DNS Uncovers Infrastructure Used in SSO Attacks
ID: 64e829d2-acd8-5b95-a6a8-f88339535b5a
STIX ID: report--64e829d2-acd8-5b95-a6a8-f88339535b5a
Feed Name: Infoblox Threat Intel Blog
Threat Score
This report documents an ongoing Evilginx-based phishing campaign that targeted at least 18 U.S. universities' student SSO portals between April and November 2025. The actor used TinyURL lures, short-lived impersonating subdomains, and Cloudflare-proxied infrastructure to capture credentials and session cookies (bypassing MFA); the analysis uncovered 67 associated domains, multiple hosting IPs, and DNS fingerprints that enable detection and blocking.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
