INTEL_REPORT
Microsoft Security Blog · published 5/4/2026, 3:00:00 PM · TLP amber
Summary
Ingested excerpt (first ~500 chars of normalized text).
Breaking the code: Multi-stage ‘code of conduct’ phishing campaign leads to AiTM token compromise Microsoft Defender Research observed a large-scale credential theft campaign that exemplifies this trend, using code of conduct-themed lures, a multi-step attack chain, and legitimate email services to distribute fully authenticated messages from attacker-controlled domains. The post Breaking the code: Multi-stage ‘code of conduct’ phishing campaign leads to AiTM token compromis…
https://www.microsoft.com/en-us/security/blog/2026/05/04/breaking-the-code-multi-stage-code-of-conduct-phishing-campaign-leads-to-aitm-token-compromise
sha256:3c9a37c2ad792292ebeaf489b11d1c62e208a9b5174a0c9e51e8e74dfef39afc
What we pulled out
Deterministic extractor (IOC + allowlisted tokens + ATT&CK IDs present in DB).
Indicators
Linked with report → mentions → indicator. Values open the indicator workspace.
Malware families
Allowlist token matches only.
Threat actors mentioned
Allowlist mentions — not a formal attribution verdict.
ATT&CK techniques
MITRE IDs referenced in text and present in local technique table.
CONTINUE INVESTIGATION
High-signal pivots without leaving the thread you started in search.
Browse the report corpus.
Neighborhood from the first linked indicator.
| harteprn.com |
| Open → |
| domain | na.businesshellosign.de | Open → |
| sha256 | 5db1ecbbb2c90c51d81bda138d4300b90ea5eb2885cce1bd921d692214aecbc6 | Open → |
| sha256 | b5a3346082ac566b4494e6175f1cd9873b64abe6c902db49bd4e8088876c9ead | Open → |
| sha256 | 11420d6d693bf8b19195e6b98fedd03b9bcbc770b6988bc64cb788bfabe1a49d | Open → |