PULSE NAME
Breaking the code: Multi-stage 'code of conduct' phishing campaign leads to AiTM token compromise
WHITE AlienVault 2026-05-04 Modified: 2026-05-05
10
IOCs
LOW VOLUME
A sophisticated large-scale credential theft campaign targeted over 35,000 users across 13,000 organizations, primarily in the United States, between April 14-16, 2026. Attackers distributed fully authenticated emails from legitimate services using code of conduct-themed lures with polished HTML templates. The multi-stage attack chain included PDF attachments with embedded links, multiple CAPTCHA challenges, and intermediate staging pages designed to appear legitimate while filtering automated defenses. Recipients were directed through several layers ultimately leading to an adversary-in-the-middle phishing flow that proxied authentication sessions and captured tokens, bypassing non-phishing-resistant multifactor authentication. The campaign broadly impacted Healthcare, Financial services, Professional services, and Technology industries, using social engineering techniques that created urgency through time-bound prompts and concerning accusations.
Indicators of Compromise (10)
All CVE FileHash-SHA256 domain hostname
TYPEINDICATORDESCRIPTIONCREATED
CVE CVE-2026-31431 2026-05-04
FileHash-SHA256 11420d6d693bf8b19195e6b98fedd03b9bcbc770b6988bc64cb788bfabe1a49d 2026-05-04
FileHash-SHA256 5db1ecbbb2c90c51d81bda138d4300b90ea5eb2885cce1bd921d692214aecbc6 2026-05-04
FileHash-SHA256 b5a3346082ac566b4494e6175f1cd9873b64abe6c902db49bd4e8088876c9ead 2026-05-04
domain acceptable-use-policy-calendly.de 2026-05-04
domain cocinternal.com 2026-05-04
domain compliance-protectionoutlook.de 2026-05-04
hostname na.businesshellosign.de 2026-05-04
domain gadellinet.com 2026-05-04
domain harteprn.com 2026-05-04