Executive Summary
In early 2026, a misconfigured Python server exposed the operational stack of Egyptian threat actor codemado (MaDoO), revealing a collaborative ecosystem of Adversary-in-the-Middle (AiTM) phishing campaigns. The investigation identified three distinct actors—codemado, mail-argenta, and saroula01—operating custom Evilginx variants and abusing Microsoft's OAuth Device Code Flow to bypass Multi-Factor Authentication (MFA).
Technically, the actors utilize a combination of AI-assisted development (Claude/CyberNeurova), custom anti-bot fingerprinting gateways, and a diverse RMM arsenal (ScreenConnect, XEOX, SuperOps) for post-compromise persistence. Of particular note is the linkage to 'The Quarry' ecosystem, where codemado's 'MaDoO Blaster' tool is distributed for large-scale phishing.
This activity represents a significant threat to corporate environments, as the methods documented—specifically the long-term session cookie harvesting (up to one year) and persistent token refreshing—render traditional MFA defenses ineffective without robust Conditional Access and session controls.
Key Details
Threat Name
MaDoO Blaster
Affects
—
Adversary
codemado Other Adversaries and Aliases: mail-argenta; saroula01; RockyBelling
MITRE Techniques
Malware/Tools
Evilginx, MaDoO Blaster, red-queen, black-queen, AsyncRAT, kraken-live-panel, MaDosc, Rubeus, BadIIS
