Phishing campaign targets universities & EU bodies
Fri, 24th Jul 2026 (Yesterday)
Infoblox has identified a phishing campaign targeting universities, companies and multinational institutions, including agencies linked to the European Union and the United Nations.
The operation uses procurement-themed emails sent from compromised organisational accounts, making the messages appear to come from trusted sources within legitimate business workflows.
Infoblox says the attack uses adversary-in-the-middle techniques to intercept credentials and authenticated session tokens in real time after a recipient clicks a link. This allows attackers to gain access even when multi-factor authentication is enabled, because they hijack the authenticated session rather than break the authentication process itself.
The emails are designed to resemble routine work activity. They may appear as bid invitations, project files or requests for information, with false deadlines and confidentiality language used to create urgency.
Victims are then directed to fake document or login pages hosted on compromised websites. These are often dormant legitimate sites that have been repurposed, making them appear more credible than newly registered malicious domains.
Trusted channels
A central feature of the campaign is the use of previously compromised email accounts. By sending messages through genuine organisational accounts, attackers reduce the chance that recipients will question the request, particularly when it fits established procurement or administrative processes.
The approach reflects a broader shift in phishing tactics away from crude mass emails and towards attacks that mimic familiar business routines. In this case, the attackers appear to exploit trust in purchasing and document-sharing processes, where staff may expect attachments, links and requests for rapid action.
The infrastructure behind the campaign rotates across several phishing-as-a-service kits, including EvilProxy, FlowerStorm and Kali365. Researchers say the fake download pages used in the operation are nearly identical in appearance even when hosted on different compromised websites.
Those shared features may still offer clues to defenders. While a hijacked established website can look more trustworthy than a new malicious domain, repeated patterns in subdomain naming, reused infrastructure and page layout can help security teams trace and identify the activity.
Session hijack
The technical method highlighted by Infoblox centres on session theft. Instead of only collecting usernames and passwords, the attacker sits between the user and the legitimate login service, allowing authentication to complete while capturing the resulting session tokens.
Because the authenticated session is taken in real time, standard controls that rely on successful login checks may not stop the intrusion. The tactic is a growing concern for defenders because it undermines the assumption that multi-factor authentication alone will prevent account takeover.
Once inside an account, an attacker may gain access to internal communications, documents and other systems linked through single sign-on arrangements. In institutions handling procurement, policy, research or international administration, that access could expose sensitive information and provide a route to broader compromise.
The targets identified by Infoblox suggest an interest in organisations with distributed teams, formal purchasing processes and regular external communication. Universities and multinational institutions often exchange large volumes of documents and tenders, making procurement-themed lures harder to distinguish from normal business.
Detection challenge
The findings also highlight the difficulty of detecting phishing infrastructure before a user reaches a fake page. Rather than relying only on user training or login safeguards, organisations are being pushed to monitor the technical systems and domain patterns that support phishing campaigns.
DNS-based threat intelligence can help identify those patterns earlier by linking activity across domains, subdomains and hosting infrastructure associated with the operation. That kind of upstream visibility is intended to give defenders a chance to block or flag the attack before credentials and session data are captured.
Security teams have spent years urging staff to look for poor spelling, suspicious sender addresses and unusual links. This campaign, however, appears designed to evade those warning signs by using genuine accounts, credible subject matter and websites that may already carry a degree of trust.
Researchers underscored that point before describing the campaign's social engineering methods.
"These actors are using trust in organisational processes, like purchases, to convince people to hand over their credentials," said Dr. Renée Burton, Vice President of Infoblox Threat Intel.
"It's not a phishing scenario that you are usually warned about in security training," Burton said.