In short: An exposed Python HTTP server instance with directory listing enabled revealed an attacker’s phishing toolkit and enabled the discovery of a total of three Evilginx campaigns targeting Microsoft 365.
An attacker operated a Microsoft 365 phishing operation with a publicly accessible Python web server that had directory listing enabled. French security researchers from Lexfo were able to expose the operator’s entire toolkit and uncover two additional operations.
The operator ran a Python web server with the command “python3 -m http.server 8080” and left it listening on a public port. The command was still readable in the system’s .bash_history. Through this configuration gap, security researchers were able to access the server’s directory listing and download the attacker’s entire toolkit.
The Lexfo security team used the captured files and configurations as an attack surface to track down further connections of the operator. This pivot strategy led to the discovery of a total of two additional phishing operations, which also targeted Microsoft 365 credentials. All three campaigns used Evilginx, an open-source phishing framework that functions as a reverse proxy and allows the attacker to intercept authentication processes.
For CISOs, this incident underscores the critical importance of secure-by-default configurations in the operating environment. A single overlooked service with public accessibility can lead to full access to attack tools and enable the discovery of linked campaigns. Organizations should systematically audit their server configurations, prevent directory listing on public ports, and regularly review or limit SSH histories to close similar security gaps.
Source: thehackernews.com · Published 13 July 2026
Lumi AI News — AI-assisted curation in accordance with Art. 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.