Known malicious kitcriticalphishing

RCFH AiTM toolkit — redirector & proxy root domains (Payroll Pirates / Storm-2755)

family: rcfh-aitm-storm2755

Adversary-in-the-middle credential/session theft feeding payroll-diversion BEC, overlapping the cluster Microsoft tracks as Storm-2755. Chain: voicemail-themed mail with subject '[Organization] :ATTN: Review messages. Ref id: [random]' -> redirect laundered through Google Meet linkredirect, Google Ads /ddm/clk/ click trackers and an S3 intermediary -> an 'idp.'-labelled Apache redirector 302s to the AiTM proxy -> the proxy bounces the victim once to /st_58200519/class_identifier.php to fingerprint the browser and cache a country code in an rcfh_country cookie -> the proxy relays the genuine login.microsoftonline.com flow, rewriting Microsoft's endpoints into its own path, and captures the authorization code and ID token at its callback. Post-compromise the actor signs in from residential proxies on an eight-hour cadence keeping one SessionID across ASNs, enumerates payroll/HR/finance staff over Microsoft Graph with an axios/1.18.1 user agent, and reads mail on payroll, invoices, banking and benefits.

Anchors

YARA ruleDetect_RCFH_AiTM_Fingerprint_Endpoint
SMQL queryrun
domain:*keyreniao.com OR domain:*korminel.com OR domain:*kualabemo.com OR domain:*camberwolis.com OR domain:*milocaroline.com OR domain:*monlinelogicaline.com OR domain:*logicalineonline.com OR domain:*offirmtm.com OR domain:*oficarine.com OR domain:*ofrecie.com OR domain:*ofreace.com OR domain:*ofreice.com OR domain:*ofrecre.com OR domain:*ofercarc.com OR domain:*ocrifere.com OR domain:*ocifire.com

Provenance

Added: 2026-08-10 20:57
Two anchors with opposite lifespans, deliberately. The SMQL half is the published apex list (wildcarded so it covers the idp./mslogin./msonline./msauth./office./login-microsoftonline. subdomains without spending a node on each) and it is already mostly worthless as prediction: checked 2026-08-10, every apex here except camberwolis.com has been suspended, with NS parked on Hostinger's a.share-dns.com/b.share-dns.net sinkhole and no A record. camberwolis.com is the exception and the reason this row exists rather than being left to the feed — registered at Hostinger 2026-07-01, it has since moved to Cloudflare nameservers (angelina/duke.ns.cloudflare.com) and still resolves (188.114.97.3, 188.114.96.3), and int.camberwolis.com resolves to 2.25.75.124. Worth noting that the camberwolis.com apex is NOT in misp_indicators.csv — MISP event 20948 carries only the int. host — so this row is the only thing covering it. The YARA half is the durable anchor: /st_58200519/class_identifier.php and the rcfh_country cookie survive domain rotation, and Arctic Wolf found that same path still exposed on older domains that had already abandoned the current naming scheme. Anchor matched zero scans in the corpus at creation (2026-08-10); this is a tripwire, not a backfill. 16 filter nodes.

Sightings (0)

No sightings recorded yet.