The Wolf Left His Den Unlocked and We Just... Walked In
Oh good. Another ticket. Another Monday. Another reason to question every life choice that led me to this chair.
But wait. This one is actually almost funny.
A threat actor, presumably a very busy and very stupid one, was running not one, not two, but THREE separate fake grain operations targeting Microsoft 365 credentials. Evilginx, the whole setup, reverse proxies, stolen session tokens, the works. Real professional stuff.
And then he ran python3 -m http.server 8080 and left it pointing at his entire toolkit like a gift basket.
Directory listing. On. Public port. Wide open. His .bash_history sitting there like a confession note taped to the front door of his own den.
The French firm Lexfo just... walked in. Read the history file. Pivoted through his infrastructure. Found two MORE hooking operations running in parallel. Three campaigns, fully exposed, because this particular wolf couldn't be bothered to learn basic operational security before deciding to become a career criminal.
I've seen the Lambs in this organization do smarter things, and last week one of them replied-all to a phishing simulation asking if the gift card was real.
Here's the actual threat, since apparently I have to explain it: Evilginx sits between the Lamb and the legitimate Microsoft login page, intercepts the whole session, and walks away with valid authentication cookies. Multi-factor authentication doesn't save you here. The session is already authenticated. The tick is already under the wool. Your Electric Fence didn't even see it coming.
The good news is this specific wolf tripped over his own hooves. The bad news is there are plenty more who didn't leave the lights on.
The Shepherds will read this story and say "see, the hackers are dumb, we're fine." Please do not let them do that.
Remediation
Look, I'm tired, so I'll keep this short:
Phishing-resistant MFA like FIDO2/passkeys. Conditional Access policies that actually check for compliant devices. Session token lifetime limits so a stolen cookie expires before someone does anything useful with it. And maybe, MAYBE, train the Flock to recognize that Microsoft does not send login pages hosted on totally-real-microsoft.login-secure-verify[.]ru.
Also, if YOU are running any kind of server, check what ports you have exposed. Right now. I'll wait.
No I won't, I have fourteen other tickets.
Still can't believe the wolf dipped himself.
Original Report: https://thehackernews.com/2026/07/misconfigured-server-reveals-three.html