logo

Warning: Phishing Campaign Leveraging Evilginx Targets U.S. Universities

ID: 284bb5c6-368f-5d8e-9abc-22e1bdef384e

STIX ID: report--284bb5c6-368f-5d8e-9abc-22e1bdef384e

Feed Name: KnowBe4 Blog

Threat Score
70/100

Date Published: 2025-12-09

Date Updated: 2026-04-28

Author: KnowBe4 Team

...
...

Researchers observed a credential-harvesting phishing campaign leveraging the Evilginx open-source framework to target at least 18 U.S. universities since April 2025. Personalized emails with TinyURL links redirected victims to dynamic, short-lived phishing URLs that proxied legitimate SSO logins in real time, enabling credential capture and MFA bypass; the attackers used advanced evasion features (wildcard TLS, fingerprinting, bot filtering, JS obfuscation, multi-domain phishlets) to reduce detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.