PULSE NAME
Multi-Stage AiTM Attack Uses Code Of Conduct Phishing Emails
WHITE AlienVault 2026-05-06 Modified: 2026-05-07
3
IOCs
LOW VOLUME
A sophisticated credential theft campaign targeting over 35,000 users across 13,000 organizations was observed between April 14-16, 2026. The operation primarily impacted the United States, particularly healthcare and financial services sectors. Attackers used code of conduct themed phishing emails masquerading as internal compliance communications, sent through legitimate email delivery services from attacker-controlled domains. Victims received polished HTML emails with PDF attachments containing fake disciplinary logs and CAPTCHA gates to evade automated analysis. The multi-stage attack chain ultimately directed users to counterfeit Microsoft authentication pages operating as adversary-in-the-middle infrastructure, enabling real-time interception of credentials and session tokens while bypassing multi-factor authentication defenses.
Indicators of Compromise (3)
All domain
TYPEINDICATORDESCRIPTIONCREATED
domain acceptable-use-policy-calendly.de 2026-05-06
domain cocinternal.com 2026-05-06
domain compliance-protectionoutlook.de 2026-05-06