codemado is a cybercriminal phishing operator attributed with high confidence to Egypt and active in underground and hacking-forum communities since at least 2018. The actor is associated with the aliases MaDoO, MaDosc, and MADO, and has been linked to Microsoft 365-focused adversary-in-the-middle phishing operations built on Evilginx. These operations were designed to bypass multi-factor authentication by stealing authenticated sessions and targeting primarily corporate accounts. codemado operated a full phishing stack that included anti-bot filtering, phishing lure rotation, SMTP validation, and post-compromise tooling. The actor used multiple remote monitoring and management tools to maintain persistence after account compromise and appears to have paired credential and session theft with broader post-exploitation access mechanisms. Reporting also links codemado to custom bulk-mailing tooling known as MaDoO Blaster, a commercial spam and phishing utility supporting large-scale email delivery and lure generation. MaDoO Blaster has been associated with the broader Quarry phishing-as-a-service ecosystem in a supplier or client capacity rather than as proof of formal membership or command authority. The actor’s observed tradecraft includes initial access through phishing, session hijacking against Microsoft 365, credential theft, persistence through remote management tooling, and defense evasion through anti-bot controls and infrastructure concealment. Exposed operational artifacts also tied codemado to a broader ecosystem of phishing operators using public Evilginx forks and AI-assisted tooling development. High-confidence victim evidence includes corporate targets in France and North America, with the actor’s activity centered on enterprise cloud identity and email access rather than ransomware or destructive operations. The dominant motivation is financial gain.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
18 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
5 malware families attributed to this actor across reporting.
62 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Operates an Evilginx adversary-in-the-middle phishing platform targeting Microsoft 365 and is linked as a supplier/client to a broader phishing-as-a-service ecosystem.
Cybercriminal phishing operator running an adversary-in-the-middle M365 phishing platform on picis.net, using Evilginx infrastructure, RMM tooling, loaders, and bulk phishing capabilities via MaDoO Blaster.
Operated an Evilginx-based AiTM phishing platform targeting corporate Microsoft 365 accounts, with exposed phishing configurations, credential logs, RMM tools for persistence, and a custom bulk-mailer called MaDoO Blaster.
Operating a Microsoft 365 adversary-in-the-middle phishing campaign using a custom Evilginx fork to capture credentials and session tokens from primarily corporate mailboxes, while monetizing access with a bulk mailer.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.