DNS Uncovers Infrastructure Used in SSO Attacks
ID: c951b01f-17ef-5a73-a7fb-572b0a291136
STIX ID: report--c951b01f-17ef-5a73-a7fb-572b0a291136
Feed Name: Infoblox Threat Intel Blog
Threat Score
This report describes an active Evilginx AITM phishing campaign (April–Nov 2025) that targeted student single sign-on (SSO) portals at 18+ U.S. universities, using short-lived, brand-mimicking subdomains and Cloudflare-protected infrastructure to proxy legitimate login flows and bypass MFA; passive DNS analysis uncovered 67 domains and multiple IPs attributed to the actor and enabled DNS-based tracking and recommended blocking of IoAs to reduce risk.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
