← Back to Pulse Feed
PULSE DETAIL
PULSE NAME
Breaking the code: Multi-stage 'code of conduct' phishing campaign leads to AiTM token compromise
A sophisticated large-scale credential theft campaign targeted over 35,000 users across 13,000 organizations, primarily in the United States, between April 14-16, 2026. Attackers distributed fully authenticated emails from legitimate services using code of conduct-themed lures with polished HTML templates. The multi-stage attack chain included PDF attachments with embedded links, multiple CAPTCHA challenges, and intermediate staging pages designed to appear legitimate while filtering automated defenses. Recipients were directed through several layers ultimately leading to an adversary-in-the-middle phishing flow that proxied authentication sessions and captured tokens, bypassing non-phishing-resistant multifactor authentication. The campaign broadly impacted Healthcare, Financial services, Professional services, and Technology industries, using social engineering techniques that created urgency through time-bound prompts and concerning accusations.
MITRE ATT&CK & Malware Families
Indicators of Compromise (10)
| TYPE | INDICATOR | DESCRIPTION | CREATED | |
|---|---|---|---|---|
| CVE | CVE-2026-31431 | — | 2026-05-04 | |
| FileHash-SHA256 | 11420d6d693bf8b19195e6b98fedd03b9bcbc770b6988bc64cb788bfabe1a49d | — | 2026-05-04 | |
| FileHash-SHA256 | 5db1ecbbb2c90c51d81bda138d4300b90ea5eb2885cce1bd921d692214aecbc6 | — | 2026-05-04 | |
| FileHash-SHA256 | b5a3346082ac566b4494e6175f1cd9873b64abe6c902db49bd4e8088876c9ead | — | 2026-05-04 | |
| domain | acceptable-use-policy-calendly.de | — | 2026-05-04 | |
| domain | cocinternal.com | — | 2026-05-04 | |
| domain | compliance-protectionoutlook.de | — | 2026-05-04 | |
| hostname | na.businesshellosign.de | — | 2026-05-04 | |
| domain | gadellinet.com | — | 2026-05-04 | |
| domain | harteprn.com | — | 2026-05-04 |