Tuesday August 18, 2026

Advisory ID:   ngCERT-2026-060010

Damage:      Critical 

Probability:  High

Platform(s):  Email Systems

SUMMARY

ngCERT alerts organisations to a sophisticated multi-stage phishing campaign that leverages legitimate email services and fraudulent Code of Conduct notifications to facilitate Adversary-in-the-Middle (AiTM) attacks. The campaign uses carefully crafted phishing emails to lure users to attacker-controlled proxy servers that replicate legitimate authentication pages in real time. This enables threat actors to intercept user credentials, Multi-Factor Authentication (MFA) responses, authentication cookies, and session tokens, while gaining unauthorized access to user accounts. Organisations are advised to strengthen email security, authentication controls, and user awareness to mitigate this evolving threat.

DESCRIPTION

The campaign begins with carefully crafted phishing emails disguised as legitimate corporate communications, including Code of Conduct or compliance updates, which use urgency-driven messaging to prompt immediate user action. Victims are redirected through multiple stages to highly convincing authentication pages operating as reverse proxy servers. These servers relay authentication requests while capturing usernames, passwords, Multi-Factor Authentication (MFA) responses, authentication cookies, and authenticated session tokens in real time. The use of enterprise-grade phishing templates, multi-step redirection, CAPTCHA barriers, and other evasion techniques designed to bypass both technical security controls and user awareness highlights its level of sophistication. This further demonstrates a strategic effort to maximise unauthorized access, facilitate lateral movement, compromise sensitive information, and enable Business Email Compromise (BEC) and data exfiltration. The campaign primarily targets privileged users and organisations within finance, healthcare, and technology sectors.

CONSEQUENCES

Successful exploitation of this campaign could result in:

    1. Unauthorized access to user accounts through the theft of credentials, authentication cookies, and MFA session tokens.
    2. Business Email Compromise (BEC) and financial fraud using compromised trusted accounts.
    3. Exposure of sensitive government and organisational information.
    4. Lateral movement within enterprise environments and compromise of additional systems and resources.
    5. Operational disruption, reputational damage, and regulatory or compliance consequences. 

SOLUTION/MITIGATION

ngCERT recommends that organisations implement the following security measures:

    1. Deploy phishing-resistant authentication methods such as FIDO2 Security Keys or Passkeys, and enforce Multi-Factor Authentication (MFA) with risk-based access controls.
    2. Implement advanced email security solutions to detect and block phishing emails, malicious links, and spoofed messages.
    3. Continuously monitor authentication logs for suspicious sign-in activities and promptly revoke compromised sessions, reset credentials, and invalidate authentication tokens.
    4. Disable legacy authentication protocols, promptly apply security updates, and implement recommended security configurations.
    5. Conduct regular phishing awareness training and educate users to verify login URLs and report suspicious emails.
    6. Deploy Endpoint Detection and Response (EDR), Security Information and Event Management (SIEM), and identity threat detection solutions to identify credential theft, session hijacking, and anomalous authentication activities.
    7. Regularly review and test incident response plans for phishing, credential compromise, and Business Email Compromise (BEC) incidents.    

HYPERLINK