Advisory ID: ngCERT-2026-060010
Damage: Critical
Probability: High
Platform(s): Email Systems
SUMMARY
ngCERT alerts organisations to a sophisticated multi-stage phishing campaign that leverages legitimate email services and fraudulent Code of Conduct notifications to facilitate Adversary-in-the-Middle (AiTM) attacks. The campaign uses carefully crafted phishing emails to lure users to attacker-controlled proxy servers that replicate legitimate authentication pages in real time. This enables threat actors to intercept user credentials, Multi-Factor Authentication (MFA) responses, authentication cookies, and session tokens, while gaining unauthorized access to user accounts. Organisations are advised to strengthen email security, authentication controls, and user awareness to mitigate this evolving threat.
DESCRIPTION
The campaign begins with carefully crafted phishing emails disguised as legitimate corporate communications, including Code of Conduct or compliance updates, which use urgency-driven messaging to prompt immediate user action. Victims are redirected through multiple stages to highly convincing authentication pages operating as reverse proxy servers. These servers relay authentication requests while capturing usernames, passwords, Multi-Factor Authentication (MFA) responses, authentication cookies, and authenticated session tokens in real time. The use of enterprise-grade phishing templates, multi-step redirection, CAPTCHA barriers, and other evasion techniques designed to bypass both technical security controls and user awareness highlights its level of sophistication. This further demonstrates a strategic effort to maximise unauthorized access, facilitate lateral movement, compromise sensitive information, and enable Business Email Compromise (BEC) and data exfiltration. The campaign primarily targets privileged users and organisations within finance, healthcare, and technology sectors.
CONSEQUENCES
Successful exploitation of this campaign could result in:
- Unauthorized access to user accounts through the theft of credentials, authentication cookies, and MFA session tokens.
- Business Email Compromise (BEC) and financial fraud using compromised trusted accounts.
- Exposure of sensitive government and organisational information.
- Lateral movement within enterprise environments and compromise of additional systems and resources.
- Operational disruption, reputational damage, and regulatory or compliance consequences.
SOLUTION/MITIGATION
ngCERT recommends that organisations implement the following security measures:
- Deploy phishing-resistant authentication methods such as FIDO2 Security Keys or Passkeys, and enforce Multi-Factor Authentication (MFA) with risk-based access controls.
- Implement advanced email security solutions to detect and block phishing emails, malicious links, and spoofed messages.
- Continuously monitor authentication logs for suspicious sign-in activities and promptly revoke compromised sessions, reset credentials, and invalidate authentication tokens.
- Disable legacy authentication protocols, promptly apply security updates, and implement recommended security configurations.
- Conduct regular phishing awareness training and educate users to verify login URLs and report suspicious emails.
- Deploy Endpoint Detection and Response (EDR), Security Information and Event Management (SIEM), and identity threat detection solutions to identify credential theft, session hijacking, and anomalous authentication activities.
- Regularly review and test incident response plans for phishing, credential compromise, and Business Email Compromise (BEC) incidents.
HYPERLINK
- https://www.microsoft.com/en-us/security/blog/2026/05/04/breaking-the-code-multi-stage-code-of-conduct-phishing-campaign-leads-to-aitm-token-compromise/?msockid=095d8322290c6f3e3bf69509281e6e21
- https://thehackersnews.com/2026/05/microsoft-details-phishing-campaign.html
- https://msftnewsnow.com/microsoft-code-of-conduct-phishing-aitm-token-thef/
Advisory ID: NCC-CSIRT-2026-026
Summary:
NCC-CSIRT is alerting Telecommunications Service Providers to the growing use of AI-powered social engineering attacks, including deepfake voice calls, phishing emails, and impersonation scams. As these threats become more convincing, organizations are increasingly adopting awareness programmes to identify psychological manipulation tactics used by threat actors. A recent incident involving Bayer, a German multinational pharmaceutical and biotechnology company, demonstrated the effectiveness of this approach, as employees successfully detected and thwarted a deepfake voice-phishing attack targeting a senior executive.
Damage: High
Probability: High
Description:
ybercriminals are increasingly leveraging Artificial Intelligence tools to enhance the effectiveness of social engineering attacks. These technologies enable attackers to generate realistic emails, messages, audio recordings, and other forms of communication that closely resemble legitimate interactions.
Of particular concern is the growing use of deepfake technology to impersonate senior executives, government officials, regulators, and trusted business contacts. Such attacks often exploit human psychology by creating a sense of urgency, authority, fear, or trust to manipulate victims into taking actions that compromise organizational security.
Unlike traditional cyberattacks that exploit software vulnerabilities, these attacks primarily target human decision-making processes. Consequently, organizations that rely solely on technical security controls may remain vulnerable if employees are not adequately prepared to identify and respond to psychological manipulation tactics.
Threat Types:
- AI-Enabled Social Engineering
- Deepfake Voice Impersonation
- Business Email Compromise (BEC)
- Executive Impersonation Fraud
- Spear-Phishing
- Voice Phishing (Vishing)
- AI-Generated Fraudulent Communications
- Identity Deception and Manipulation
Consequences:
Successful exploitation may result in:
- Impersonate regulators, executives, or business partners
- Manipulate staff into disclosing sensitive information
- Initiate fraudulent financial transactions
- Gain unauthorized access to network management systems
- Exploit customer service channels through social engineering
- Conduct AI-generated voice or video impersonation attacks against employees
Solutions/Mitigations:
NCC-CSIRT strongly recommends the following immediate action:
- Enhance cybersecurity awareness programmes to include AI-enabled social engineering and deepfake threats.
- Train employees to recognize psychological manipulation techniques, including urgency, authority pressure, fear, and emotional appeals.
- Implement strict verification procedures for sensitive requests involving financial transactions, account changes, network modifications, or disclosure of confidential information.
- Conduct regular phishing, vishing, and executive impersonation simulation exercises.
- Promote a culture of verification and reporting of suspicious communications.
- Implement multi-factor authentication (MFA) across critical systems and administrative accounts.
- Review and strengthen incident response procedures for social engineering incidents.
- Encourage immediate reporting of suspected deepfakes, impersonation, or social engineering attempts to internal security teams and NCC-CSIRT.
References:
-
https://www.infosecurity-magazine.com/news/bayer-reinvents-security-awareness/
-
https://hawk-eye.io/2026/03/deepfake-driven-social-engineering-how-ai-voice-and-video-are-being-used-to-bypass-security-controls/
-
https://www.crowdstrike.com/en-us/cybersecurity-101/social-engineering/ai-social-engineering/
-
https://www.cyberhaven.com/infosec-essentials/ai-social-engineering
Advisory ID: NCC-CSIRT-2026-016
Summary:
The United Kingdom’s National Cyber Security Centre (NCSC), in coordination with international cybersecurity and intelligence partners, has warned of ongoing malicious cyber activities conducted by Chinese-linked threat actors using covert networks of compromised internet-connected devices to conceal cyber operations.
The attackers reportedly exploit vulnerable routers, smart devices, and internet-facing infrastructure to create stealth relay networks capable of masking malicious traffic, conducting cyber espionage, and launching cyberattacks against government agencies, critical infrastructure, and private organizations.
The infrastructure allows attackers to hide their real origin, evade attribution, and maintain long-term operational access while blending malicious traffic into legitimate internet activity. The threat poses significant risks to telecommunications providers, Internet Service Providers (ISPs), government networks, and critical national infrastructure globally, including Nigeria and the wider West African region.
Damage: Critical
Probability: High
Product(s):
- Home and Enterprise Routers
- Internet of Things (IoT) Devices
- Smart Home Appliances
- Network Edge Devices
- VPN Gateways
- Firewalls
- Consumer Premises Equipment (CPE)
- Internet-Connected Cameras and Smart Devices
Version(s):
- Devices running outdated or unsupported firmware
- Devices using default or weak administrative credentials
- Unpatched SOHO (Small Office/Home Office) routers and IoT systems
- Unsupported legacy networking equipment
Platform(s):
- Broadband Internet Infrastructure
- Residential Networks
- Enterprise Networks
- Cloud-Connected IoT Environments
- Linux-Based Embedded Systems
- Router Operating Systems
- Smart Device Ecosystems
Description:
According to international cybersecurity authorities, the threat actors are building covert operational networks by compromising internet-connected devices such as routers, smart appliances, and other edge networking systems.
The attackers exploit weak passwords, outdated firmware, exposed remote administration interfaces, and unpatched vulnerabilities to gain unauthorized access to these devices. Once compromised, the devices are incorporated into hidden proxy or relay infrastructures that route malicious traffic on behalf of the attackers.
This infrastructure enables attackers to disguise their real locations and conduct malicious activities while appearing to originate from legitimate residential or enterprise internet connections. Such techniques significantly complicate cyber attribution and detection efforts.
The compromised devices may be used to:
- Relay malicious traffic
- Conduct cyber espionage
- Support command-and-control (C2) communications
- Launch Distributed Denial-of-Service (DDoS) attacks
- Facilitate credential theft and malware distribution
The advisory indicates that the threat actors specifically target poorly secured internet-facing infrastructure and leverage globally distributed networks of compromised devices to sustain persistent cyber operations.
The threat is particularly concerning because compromised devices may continue operating normally while secretly participating in malicious activities without the knowledge of device owners.
Indicators of Compromise (IoCs):
Organizations should monitor the following indicators:
Network Indicators
- Unusual outbound traffic from routers or IoT devices
- Persistent encrypted outbound connections to unknown IP addresses
- Abnormal DNS requests or DNS tunnelling activity
- Unexpected proxy or relay traffic originating from internal networks
- Large volumes of outbound traffic from consumer premises equipment (CPE
Device Indicators
- Unauthorized configuration changes on routers or firewalls
- Unknown administrator accounts
- Unexpected device reboots or degraded performance
- Unusual open ports or remote management services
- Firmware modifications or unauthorized scheduled tasks
Operational Indicators
- Unexpected communications with foreign IP addresses
- Detection of botnet or proxy network signatures
- Devices participating in DDoS traffic patterns
Consequences:
Successful exploitation may result in:
- Unauthorized use of compromised devices as relay infrastructure for cyberattacks
- Concealment of malicious cyber operations behind legitimate residential or enterprise networks
- Data theft and cyber espionage against government and critical infrastructure organizations
- Distributed Denial-of-Service (DDoS) attacks using hijacked devices
- Reputational and attribution risks for affected Internet Service Providers
- Long-term covert access to vulnerable network environments
- Increased exposure of telecommunications infrastructure to an advanced threat actor
Threat Types:
- Advanced Persistent Threat (APT) Activity
- Cyber Espionage
- Botnet Operations
- Proxy / Relay Network Abuse
- Infrastructure Hijacking
- Covert Command-and-Control (C2) Operations
- IoT Device Exploitation
- Network Obfuscation and Evasion
Solutions/Mitigations:
NCC-CSIRT recommends the following mitigation steps:
- Monitor customer networks for unusual proxy or relay traffic patterns.
- Identify and isolate compromised routers or IoT devices.
- Enforce firmware updates and security hardening for managed devices.
- Disable unnecessary remote management interfaces.
- Deploy network anomaly detection systems to identify covert relay activity.
- Conduct threat hunting activities for covert relay or proxy traffic within enterprise and telecom networks.
- Review the security posture of all internet-facing infrastructure and edge devices.
- Monitor for signs of unauthorized access to routers, VPN devices, and firewalls.
- Collaborate with national cybersecurity authorities and ISPs to report suspicious infrastructure
- Deploy endpoint and network monitoring solutions capable of detecting botnet or proxy activity.
References:
-
https://www.ncsc.gov.uk/news/defending-against-china-nexus-covert-networks-of-compromised-devices
-
https://www.helpnetsecurity.com/2026/04/24/ncsc-china-covert-networks-advisory/
-
https://www.ncsc.gov.uk/sites/default/files/2026-04/-Defending-against-China-nexus-covert-networks-of-compromised-devices.pdf
Advisory ID: NCC-CSIRT-2026-015
Summary:
The NCC-CSIRT has observed the following cyber threats in the communications sector: increased activities involving malware strains such as Andromeda, BruteForceBot, Win.AsyncRAT, Gamut, and StealRat are being leveraged to orchestrate Distributed Denial-of-Service (DDoS) attacks. These malware families are used to compromise systems and form botnets capable of launching large-scale volumetric and application-layer attacks.
Damage: High
Probability: High
Product(s):
- Network Infrastructure
- Endpoints
- Servers
- Customer Premises Equipment (CPE)
Version(s):
All versions
Platform(s):
- Windows
- Linux
- Network Devices
- IoT Devices
Description:
Recent threat intelligence indicates the use of the following malware:
Andromeda: Modular botnet malware used for system compromise and DDoS operations.
BruteForceBot: Used for credential brute-force attacks and botnet recruitment.
Win.AsyncRAT: Remote access trojan enabling remote control and DDoS deployment.
Gamut: Known for spam and botnet activity, also leveraged for DDoS campaigns.
StealRat: Supports credential theft and remote control, aiding botnet expansion.
These malware strains enable attackers to build distributed botnets used to generate high volumes of malicious traffic, resulting in denial-of-service conditions.
Impacts:
- Service disruption and degradation of telecommunications services
- Network congestion and bandwidth exhaustion
- Loss of availability of critical systems and services
- Compromise of infected systems leading to further propagation
- Reputational damage and potential regulatory implications
Threat Types:
- Botnet Malware
- DDoS (Volumetric and Application Layer)
- Remote Access Trojan (RAT),
- Credential Attacks
Solutions/Mitigations:
NCC-CSIRT recommends the following mitigation steps:
- Deploy DDoS mitigation solutions (traffic filtering, rate limiting).
- Monitor network traffic for anomalies.
- Patch and update systems regularly.
- Implement endpoint protection (EDR/AV).
- Enforce strong authentication (MFA, password policies).
- Block command-and-control (C&C) communications.
- Leverage threat intelligence and share IOCs.
- Develop and test incident response plans.
References:
Advisory ID: ngCERT-2026-060004
Damage: Critical
Probability: High
Platform(s): All Systems Using Digital Certificates (Websites, APIs, Servers, IoT)
SUMMARY
ngCERT warns organisations about the severe risks posed by expired or mismanaged digital certificates. Expired or poorly handled TLS/SSL certificates can trigger sudden widespread service outages, expose systems to security attacks, erode user trust and cause significant financial and reputational damage. With shorter certificate lifespans and the growing number of certificates in use, ineffective management has become a major threat to business continuity and cybersecurity. Organisations using digital certificates are strongly advised to implement robust certificate management practices immediately.
DESCRIPTION
Digital certificates serve as machine credentials for authentication, confidentiality, and integrity in encrypted communications. Expired certificates can shut down websites, APIs, and entire enterprise systems. Key challenges include manual tracking of large numbers of certificates, lack of visibility, and failure to monitor expirations. Proper management involves discovery, monitoring for policy compliance and usage, timely rotation before expiry, and revocation of compromised certificates. Automation and centralised visibility are strongly recommended to manage the increasing volume of certificates in modern environments.
CONSEQUENCES
Failure to manage digital certificates properly may lead to:
- Service outages and downtime.
- Browser security warnings that damage user trust and reputation.
- Increased vulnerability to man-in-the-middle attacks and data interception.
- Operational disruptions affecting websites, APIs, internal systems, and connected devices.
- Compliance violations and potential financial losses from unplanned interruptions.
SOLUTION/MITIGATION
Organisations are strongly advised to apply these mitigations:
- Implement automated certificate discovery across all environments.
- Establish centralised visibility and inventory of all certificates.
- Monitor expiration dates with proactive alerts (30–90 days in advance).
- Automate certificate renewal and rotation before expiry.
- Enforce short certificate lifespans and regular rotation policies.
- Revoke compromised or misused certificates immediately.
- Adopt certificate management platforms to automate the lifecycle.
- Conduct regular audits and train teams on certificate best practices.
HYPERLINK
- https://www.youtube.com/watch?v=V7EgIMWOqgw
- https://cwe.mitre.org/data/definitions/298.html
- https://owasp.org/Top10/2021/A02_2021-Cryptographic_Failures/
- SECURITY ADVISORY ON REMOTE EXECUTION OF MALICIOUS CODE TARGETING WINDOWS ENDPOINTS
- ngCERT SECURITY ADVISORY ON WHATSAPP VULNERABILITIES LEVERAGING INSTAGRAM REELS TO EXECUTE MALICIOUS URL
- DEEPLOAD MALWARE TARGETING WADVISORY ON DEEPLOAD MALWARE TARGETING WINDOWS SYSTEMS THROUGH CLICKFIX SOCIAL ENGINEERINGINDOWS SYSTEMS THROUGH CLICKFIX SOCIAL ENGINEERING
- ngCERT SECURITY ADVISORY ON MICROSOFT DEFENDER ZERO-DAY (CVE-2026-33825) ENABLES SYSTEM-LEVEL PRIVILEGE ESCALATION