IOC Radar
TLP:WHITE13 IOCs

Breaking the code: Multi-stage ‘code of conduct’ phishing campaign leads to AiTM token compromise

MT
Microsoft Threat Intelligence
Published May 4, 2026Original Report

Diamond Model

SOCIAL AXISTECHNOLOGY AXISADVERSARYunknownINFRASTRUCTUREharteprn.comcocinternal.comcompliance-protection…CAPABILITYunknownVICTIMunknown
Adversary
Infrastructure(5)
Capability
Victim

5W+H Threat Analysis

Analysis unavailable

Indicators of Compromise

Indicators of Compromise13

TypeIndicatorConfidenceScoreFirst Seen
Email[email protected]
emailindicatorintel-blog
High
58
Jun 2, 26
Domainharteprn.com
indicatorintel-blognetwork
High
58
Jun 2, 26
Email[email protected]
emailindicatorintel-blog
High
58
Jun 2, 26
Domaincocinternal.com
indicatorintel-blognetwork
High
58
Jun 2, 26
Domaincompliance-protectionoutlook.de
aptespionageintel-blog
High
58
Jun 2, 26
SHA2565db1ecbbb2c90c51d81bda138d4300b90ea5eb2885cce1bd921d692214aecbc6
file-hashintel-blogphishing
Medium
53
Jun 2, 26
Email[email protected]
emailindicatorintel-blog
High
58
Jun 2, 26
Domainacceptable-use-policy-calendly.de
aptespionageintel-blog
High
58
Jun 2, 26
SHA256b5a3346082ac566b4494e6175f1cd9873b64abe6c902db49bd4e8088876c9ead
file-hashindicatorintel-blog
Medium
53
Jun 2, 26
Email[email protected]
emailindicatorintel-blog
High
58
Jun 2, 26
Domaingadellinet.com
indicatorintel-blognetwork
High
58
Jun 2, 26
SHA25611420d6d693bf8b19195e6b98fedd03b9bcbc770b6988bc64cb788bfabe1a49d
file-hashindicatorintel-blog
Medium
53
Jun 2, 26
Email[email protected]
emailindicatorintel-blog
High
58
Jun 2, 26

IOC Relationship Graph

IOC Relationship Graph13 total IOCs
EmailDomainSHA256
Email5Domain5SHA2563REPORTBreaking the code: Multi-s
scroll to zoom · drag to pan · click IOC to open