Warning: Phishing Campaign Leveraging Evilginx Targets U.S. Universities
ID: 284bb5c6-368f-5d8e-9abc-22e1bdef384e
STIX ID: report--284bb5c6-368f-5d8e-9abc-22e1bdef384e
Feed Name: KnowBe4 Blog
Researchers observed a credential-harvesting phishing campaign leveraging the Evilginx open-source framework to target at least 18 U.S. universities since April 2025. Personalized emails with TinyURL links redirected victims to dynamic, short-lived phishing URLs that proxied legitimate SSO logins in real time, enabling credential capture and MFA bypass; the attackers used advanced evasion features (wildcard TLS, fingerprinting, bot filtering, JS obfuscation, multi-domain phishlets) to reduce detection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
