logo

DNS Uncovers Infrastructure Used in SSO Attacks

ID: 64e829d2-acd8-5b95-a6a8-f88339535b5a

STIX ID: report--64e829d2-acd8-5b95-a6a8-f88339535b5a

Feed Name: Infoblox Threat Intel Blog

Threat Score
78/100

Date Published: 2025-12-01

Date Updated: 2026-04-28

Author: Infoblox Threat Intel

...
...

This report documents an ongoing Evilginx-based phishing campaign that targeted at least 18 U.S. universities' student SSO portals between April and November 2025. The actor used TinyURL lures, short-lived impersonating subdomains, and Cloudflare-proxied infrastructure to capture credentials and session cookies (bypassing MFA); the analysis uncovered 67 associated domains, multiple hosting IPs, and DNS fingerprints that enable detection and blocking.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.