Exposed AiTM Toolkit Lowers the Bar for MFA Bypass

A copied phishing kit is more dangerous than a single active crew. Here, a misconfigured server exposed the pieces needed to run MFA-bypass phishing end to end, including credential logs, session files, and RMM installers that can keep access alive after the phish lands. Lexfo found the directory on a Budapest VPS left with listing enabled. The exposed material tied together three operators, including codemado, with Evilginx-based Microsoft 365 phishing, a separate OAuth Device Code Flow campaign, and a seven-tool persistence kit built around RMM software and custom mailing tools. The practical risk is that password resets do not clean this up if session tokens or remote access already exist. The leak also makes the tradecraft easier to copy, so teams should expect more low-skill MFA-bypass attempts rather than a one-off crew.

Part of the PlainSec briefing for 2026-07-13

Sources