Exposure of Three AiTM Phishing Operators
Score: 9/10

Exposure of Three AiTM Phishing Operators

Egyptian threat actor codemado and associates leverage custom Evilginx forks and Device Code Flow abuse to target Microsoft 365 and cryptocurrency users.

Executive Summary

In early 2026, a misconfigured Python server exposed the operational stack of Egyptian threat actor codemado (MaDoO), revealing a collaborative ecosystem of Adversary-in-the-Middle (AiTM) phishing campaigns. The investigation identified three distinct actors—codemado, mail-argenta, and saroula01—operating custom Evilginx variants and abusing Microsoft's OAuth Device Code Flow to bypass Multi-Factor Authentication (MFA).

Technically, the actors utilize a combination of AI-assisted development (Claude/CyberNeurova), custom anti-bot fingerprinting gateways, and a diverse RMM arsenal (ScreenConnect, XEOX, SuperOps) for post-compromise persistence. Of particular note is the linkage to 'The Quarry' ecosystem, where codemado's 'MaDoO Blaster' tool is distributed for large-scale phishing.

This activity represents a significant threat to corporate environments, as the methods documented—specifically the long-term session cookie harvesting (up to one year) and persistent token refreshing—render traditional MFA defenses ineffective without robust Conditional Access and session controls.

Key Details

Threat Name

MaDoO Blaster

Affects

—

Adversary

codemado Other Adversaries and Aliases: mail-argenta; saroula01; RockyBelling

Malware/Tools

Evilginx, MaDoO Blaster, red-queen, black-queen, AsyncRAT, kraken-live-panel, MaDosc, Rubeus, BadIIS

Report Score

9out of 10
Quality Score
Excellent
IOC Quality10
TTP Details9
Detection Guidance7
Enterprise Relevance10
Clarity & Structure10
Technical Depth9

Sources