ALMC
ALMC Security Logo - Mantenimiento Web, Programación Web Barcelona, Servidores Barcelona, Ciberseguridad Barcelona
  • English
    Español English Français Català

Quick search

Results without leaving the page.

Type to search ALMC products, services, articles and tools.

View all results
Habla a nuestro AgenteIA · respuestas al instante · 24/7
  • HomeALMC
  • ALMCAbout Us
  • ALMC SECURITY S.L.U.Contact
  • Posts
    • Posts
    • Categorías
    • Etiquetas
    • Estados
  • Soluciones
    • Desarrollo Web en Lleida — Diseño a Medida que Vende
    • Tienda Online a Medida — E-commerce que Vende de Verdad
    • Chatbot IA para Empresas — Automatiza tu Atención al Cliente
    • Automatización de Procesos para Empresas — Menos Tareas, Más Resultados
    • Desarrollo de Apps Móviles — iOS y Android a Medida
  • Services
    • Cybersecurity
      • Security Audits and Pentesting
      • Monitoring & Incident Response (SIEM)
      • System & Server Hardening
      • Compliance Consulting (GDPR, ENS, ISO 27001)
      • Cloud Security (AWS, Azure, Google Cloud)
    • Programming
      • Full Stack Web Development Laravel, Vue.js
      • Process Automation (Scripts and Bots)
      • Process Automation Scripts and Bots
      • API Integrations & Microservices
      • Code Maintenance and Optimization
    • Servers
      • Server Management & Monitoring
      • Cloud Migration (AWS, Azure, Google Cloud)
      • Performance Optimization
      • Virtualization & Containers (Docker, Kubernetes)
      • Backup & Disaster Recovery Plans
    • Website Virus Removal
    • Website Maintenance
      • WordPress Maintenance
      • PrestaShop Maintenance
      • Magento Maintenance
      • Joomla Maintenance
      • Drupal Maintenance
      • Shopify Maintenance
      • Wix Maintenance
      • Concrete5 Maintenance
      • HTML Maintenance
      • PHP Maintenance
      • JavaScript Maintenance
      • Python Maintenance
    • Website Repair
      • Hacked site cleanup
      • Fix WordPress
      • Fix PrestaShop
      • Fix Magento
      • Fix Joomla
      • Fix Drupal
      • Fix Shopify
      • Fix OpenCart
      • Fix Moodle
  • Industries
    • 3D Printing & Additive
    • Accounting
    • Advertising & Marketing
    • Aerospace & Defense
    • Agriculture
    • Architecture & Engineering
    • Arts & Culture
    • Automotive
    • Banking & Finance
    • Biomedical Research
    • Biotechnology
    • Breweries
    • Call Centers & BPO
    • Chemicals
    • Cleaning Services
    • Clinics
    • Cloud Providers
    • Construction
    • Consulting
    • Cosmetics & Beauty
    • Courier & Last Mile
    • Cybersecurity
    • Data Centers
    • Defense & Security
    • E-Commerce
    • EdTech
    • Education (K-12)
    • Electrical Equipment
    • Electronics
    • Environmental NGOs
    • Environmental Services
    • Events & Conferences
    • Facilities Management
    • Fashion & Luxury
    • FinTech
    • Fishing & Aquaculture
    • Food & Beverage Manufacturing
    • Forestry
    • Freight Transport
    • Furniture
    • Gaming
    • Government & Public Administration
    • GovTech
    • Gyms & Fitness Centers
    • Healthcare Providers
    • HealthTech
    • Higher Education
    • Home Appliances
    • Home Services
    • Hospitality
    • Hospitals
    • Human Resources
    • Insurance
    • InsurTech
    • Internet & Web Services
    • Investment & Asset Management
    • IT Services
    • Jewelry
    • Landscaping & Gardening
    • Legal Services
    • Logistics & Supply Chain
    • Machinery
    • Maritime
    • Media & Entertainment
    • Medical Devices
    • Metals
    • Mining
    • Music Industry
    • Nonprofit & NGOs
    • Oil & Gas
    • Paper & Print Media
    • Paper & Pulp
    • Pharmaceuticals
    • Photography & Video
    • Plastics
    • Postal & Courier
    • Printing
    • Private Education & Academies
    • Property Development
    • Property Management
    • PropTech
    • Public Safety & Emergency
    • Publishing
    • Rail & Public Transport
    • Real Estate
    • Real Estate Agencies
    • Religious Organizations
    • Renewable Energy
    • Research & Development
    • Research Labs
    • Restaurants & Food Service
    • Retail
    • Security Services
    • Semiconductors
    • Software Development
    • Sports & Fitness
    • Sports Clubs
    • Staffing & Recruitment
    • Telecommunications
    • Textile & Apparel
    • Tobacco
    • Toys
    • Travel & Tourism
    • Travel Agencies
    • Utilities
    • Veterinary & Animal Care
    • Warehousing
    • Waste Management
    • Water Treatment
    • Wholesale
    • Wineries & Vineyards
  • Tools
    • Network
      • What's my IP
      • WHOIS IP
      • Domain WHOIS
      • Geolocate IP
      • DNS Lookup
      • DNS Propagation
      • ASN Lookup
      • Reverse Lookup
      • Domain monitoring
    • Image Compressor
    • MCP Servers
  • Products
    • Whatsboost
      • Whatsboost PrestaShop
      • Whatsboost WordPress
      • Whatsboost Shopify
    • Ulix
      • Extension QR para navegador
    • Chatbot
      • Chatbot WhatsApp
      • Chatbot Instagram
      • Chatbot Facebook
      • Chatbot TikTok
    • VeriFactu
    • Web TV
      • Mis pantallas
      • Vincular nueva TV
      • Dispositivos vinculados
      • Releases APK
      • Pantallas por cliente
    • Control de Fichajes

5 News at ALMC
  • Inauguration of the... Web Maintenance, Web Development Barcelona, Servers Barcelona, Cybersecurity Barcelona
    Inauguration of the...It was a very busy and special day. 30 Jun 2025
  • Website Web Maintenance, Web Development Barcelona, Servers Barcelona, Cybersecurity Barcelona
    WebsiteI recover the domain I had in the past and set up... 01 Jun 2025
  • Signing of the Lease... Web Maintenance, Web Development Barcelona, Servers Barcelona, Cybersecurity Barcelona
    Signing of the Lease...After spending some time looking for premises, my... 01 Jun 2025
  • ALMC returns and com... Web Maintenance, Web Development Barcelona, Servers Barcelona, Cybersecurity Barcelona
    ALMC returns and com...We reactivate the brand with ALMC SECURITY SL (CIF... 23 Apr 2025
  • feb. 2025 Web Maintenance, Web Development Barcelona, Servers Barcelona, Cybersecurity Barcelona
    feb. 2025The decision to start entrepreneurship again was b... 01 Feb 2025

View all news

Evilginx and Device Code Phishing: Lessons from a Misconfigured Server

  1. Home
  2. Blog
  3. Categories
  4. Cybersecurity
  5. Evilginx and Device Code Phishing: Lessons fr...
  • All articles
  • Categories
  • Tags
  • Statuses

Evilginx and Device Code Phishing: Lessons from a Misconfigured Server

When a Simple Mistake Exposes a Web of PhishingIn the world of cybersecurity, sophisticated attacks often begin with the simplest of errors. Such was...

When a Simple Mistake Exposes a Web of Phishing

In the world of cybersecurity, sophisticated attacks often begin with the simplest of errors. Such was the case when a misconfigured web server—set up with a basic Python HTTP server and directory listing enabled—accidentally revealed the inner workings of three active phishing campaigns targeting Microsoft 365 users. The exposed files, including a revealing shell history, allowed researchers to reconstruct the attackers' infrastructure and tactics. This incident serves as a stark reminder that even minor oversights can have major consequences, and it offers valuable lessons for system administrators and businesses across Spain and beyond.

Fortress gate with crack and glowing keyhole symbolizing security vulnerabilities

Two Attack Vectors That Bypass Traditional Defenses

The campaigns leveraged two primary techniques that are increasingly common in the threat landscape. The first is adversary-in-the-middle (AiTM) phishing using reverse proxies like Evilginx. This method intercepts the victim's session, captures cookies, and effectively bypasses multi-factor authentication (MFA) in interactive logins. The second, more subtle approach exploits the OAuth Device Code flow—the same mechanism used by microsoft.com/devicelogin—to obtain tokens without ever presenting a fake login page. This technique is particularly dangerous because it can succeed even when users are trained to spot phishing sites.

The Longevity of Stolen Tokens

One of the most alarming findings was the lifespan of the stolen tokens. Researchers discovered cookies with expiration dates set for 2027, meaning that once an attacker gains access, they can maintain it for years if no additional controls are in place. In one campaign, over 200 confirmed victims across a dozen countries were identified, with a majority being corporate mailboxes. This highlights the importance of not only preventing initial compromise but also limiting the damage through proactive session management.

From Credential Theft to Full Control

The attackers didn't stop at stealing credentials. They deployed remote monitoring and management (RMM) tools to maintain persistent access, turning compromised mailboxes into launching pads for further attacks within the organization. This shift from credential theft to sustained control underscores the need for comprehensive incident response that goes beyond password resets.

Defending Against Reverse Proxy Phishing

To counter AiTM phishing, organizations should deploy phishing-resistant MFA methods such as FIDO2 security keys or passkeys. These technologies significantly reduce the effectiveness of cookie theft during interactive logins, as they bind authentication to the device and the user's physical presence. While no solution is foolproof, implementing these measures can dramatically lower the risk of session hijacking.

Mitigating Device Code Abuse

For the Device Code flow, the approach is different. Administrators should disable this flow in Microsoft Entra ID unless there is a genuine operational need. If exceptions are necessary, they should be minimal and tightly scoped to specific devices or applications. Additionally, robust Conditional Access policies—including location-based restrictions and Continuous Access Evaluation—can help truncate the effective lifespan of stolen tokens, limiting the window of opportunity for attackers.

Monitoring and Responding to Suspicious Activity

Proactive monitoring is essential. Organizations should audit token grants associated with the Device Code flow and watch for unusual session origins. In particular, look for refresh token grants tied to client IDs that are not typically used by your environment, and cross-reference them with suspicious IPs or ASNs. If suspicious activity is detected, the response should be immediate and thorough: revoke sessions and refresh tokens, enforce reauthentication via Conditional Access, and investigate endpoints for unauthorized RMM tools.

Building a Resilient Security Posture

This incident is a powerful illustration of how attackers chain together deception, token theft, and persistence to compromise cloud environments. For businesses in Catalonia and across Spain, the lessons are clear: invest in phishing-resistant MFA, enforce strict token policies, and maintain vigilant monitoring. Centralizing security management across your servers can also help. Solutions like Abuse Shield offer automated IP blocking, managed fail2ban, and a shared reputation feed, providing a unified defense layer that reduces the attack surface and helps you respond faster to threats. By adopting a proactive and layered security strategy, you can protect your organization from these evolving threats and ensure that a simple misconfiguration doesn't lead to a major breach.

Related

  • Hugging Face Breach: Why Data Pipelines Are the New Security Frontier
  • FakeGit: How Fake GitHub Repos Spread SmartLoader and StealC
  • Critical WordPress Flaw 'wp2shell' Exploited: Act Now to Secure Your Servers
  • Desarrollo web

Put these ideas into practice

Talk to ALMC about a solution for your business. Explore your options or contact our team.

Soluciones ALMC

Full Stack Web Development Laravel, Vue.js
Code Maintenance and Optimization
Backup & Disaster Recovery Plans
Server Management & Monitoring
System & Server Hardening
Relacionados
  • SonicWall SMA1000 Zero-Days: Urgent Patch Guidance for SysAdmins
    Cybersecurity · 54 minutes ago
  • UEFI Secure Boot Bypass: Why Old Shims Threaten Your Servers
    Cybersecurity · 54 minutes ago
  • NPM Supply Chain Attack: How a Malicious SDK Compromised Crypto Wallets
    Cybersecurity · 54 minutes ago
  • RoguePlanet: Microsoft Patches Defender Zero-Day, Update Now
    Cybersecurity · 54 minutes ago
  • GhostLock CVE-2026-43499: Patch Your Linux Servers Now
    Cybersecurity · 54 minutes ago
  • Fastjson 1.x RCE: A Practical Guide for System Administrators
    Cybersecurity · 1 hour ago
Servidores MCP Destacados
  • Chroma
    Official 🌟 Oficial
  • Hackle
    Development
  • Windows API
    Development
  • MCP Yahoo Finance
    Database
  • Tmux
    Productivity
  • DeepView MCP
    Development
  • MCP Node.js Debugger
    Development
  • What Time Is It Now
    Productivity
  • Shell MCP
    Development
Ver todos los servidores MCP
Cybersecurity · Blog Brain · 2026-09-08
Cerrar panel
Your ecosystem

SaaS applications

Open each workspace directly with your ALMC account.

My account Create account
VeriFactuVerified invoicingAbuse ShieldWeb securityWhatsBoostSales and CRMCommerceStore and POSEmail AISmart emailWebTVDigital signageTime trackingWorking-time controlPrintFlowPrint workflows
Agente Smith · ALMCAgente IA propio on-premise

Hola 👋 Soy Smith, el agente IA de ALMC. Pregúntame sobre ciberseguridad, IA, desarrollo a medida o nuestros productos SaaS.

¿Prefieres hablar con persona? Contacto humano

ALMC access centre

One account · All your services

Start wherever you want.

Create an account to centralise your services, or ask for guidance if you do not know what you need yet.

Create account Talk to ALMC

Explore by product

VeriFactuInvoicingAbuse ShieldSecurityWhatsBoostSalesCommerceStore and POSEmail AIAutomationWebTVDigital signage

Sign in to your account.

The same sign-in brings together your services, team and billing.

Enter my panelAccess your services, team and billing.
Sign in

Not a client yet? Create an account

ALMC Security Logo

Experts in cybersecurity, custom Laravel development, and server management. We deliver robust, secure, and personalized technological solutions.

Latest News

Inauguration of the first office in Lleida of ALMC SECURITY SL
Inauguration of the first office in Lleida of ALMC...
30 Jun 2025
Website
01 Jun 2025
Signing of the Lease Contract
Signing of the Lease Contract
01 Jun 2025

Main Services

  • desarrollo web lleida
  • tienda online a medida
  • chatbot ia empresa
  • automatización procesos empresa
  • desarrollo aplicaciones móviles

Suite SaaS

  • PrintFlow (copisterías)
  • WebTV (cartelería)
  • VeriFactu (facturación)
  • Fichaje horario

Contact

  • Rambla de Ferran, 37, 25007 Lleida

  • +34 614 443 757

  • info@almc.es

Follow Us

Useful links

  • About us
  • Contact
  • Reserva cita
  • Hacked website repair
  • Website maintenance
  • Website repair
  • Tools
  • What is my IP
  • Compress images
  • Site search
  • Blog

© Copyright 2026. ALMC SECURITY S.L.U.

  • Legal
      • Privacy Policy
      • Terms and Conditions of Service
      • Legal Notice and Corporate Information
      • Cookie Policy
  • Resources
    • Blog
    • Sitemap

ALMC

Legal

This site only uses first-party cookies and local browser storage, and only to make it work: keeping your session, protecting forms, remembering your language and not showing you this notice again. We use no analytics or advertising cookies, there are no third-party cookies and we do not build profiles. As strictly necessary technical cookies, they are exempt from consent under Article 22.2 of the Spanish LSSI-CE: this notice is informative and the button only stops it from appearing again. You can delete or block them from your browser, though some features may then stop working. Cookie Policy · Privacy Policy.

Chat now
Call Sales
+34 614 443 757

More ways to contact us

¿Hablamos directamente?

Reserva una cita en mi agenda — yo te llamo o nos vemos por Google Meet

  • ✓Confirmación instantánea por WhatsApp
  • ✓Disponibilidad en tiempo real
  • ✓Recordatorio 1h antes
  • ✓Cancela o cambia hora con un click
Initial consultation · 30min
📅 Ver disponibilidad y reservar