Skip to content

CodeStorm Phishing Campaign Targets M365 Tenants With Token Reuse and Replay Attacks

Gbhackers Mayura Kathir June 23, 2026

A multi-organization phishing campaign attributed to the CodeStorm family is actively targeting Microsoft 365 tenants with a tenant-aware AiTM (adversary-in-the-middle) phishing kit that combines rotating frontends and backend replay behavior under a stable controller path, /google.php. The human recipient rarely scrolls to that dummy conversation, but automated secure email gateways frequently do; the added “conversation […]

Extracted Entities

Attack Types (1)

MITRE ATT&CK (1)

Platforms (1)