SECURITY·중요도 7·2026. 07. 13.·The Hacker News
Misconfigured Server Reveals Three Evilginx Phishing Operations Targeting Microsoft 365
── KO ──────────────────
잘못 구성된 서버가 Microsoft 365를 대상으로 한 피싱 공격 노출.
프랑스의 보안 회사 Lexfo가 Microsoft 365를 대상으로 하는 피싱 운영 도중, 공격자가 잘못 구성한 서버에서 전체 도구 키트를 확보했습니다. Python 웹 서버가 공용 포트에서 실행되고 있으며, 디렉토리 목록이 활성화되어 있었던 것이 원인입니다. 이 공격자는 .bash_history 파일에서 공격 명령어를 노출했습니다.
── EN ──────────────────
Misconfigured server reveals phishing operations targeting Microsoft 365.
A French security firm, Lexfo, uncovered a phishing operation targeting Microsoft 365 after discovering a misconfigured server. The attacker had left a Python web server running on a public port with directory listing enabled, exposing their complete toolkit. The command used was still present in the readable .bash_history file.