TI Mindmap HUB
Threat Intelligence Report

DNS Uncovers Infrastructure Used in SSO Attacks

๐Ÿ“… December 2, 2025 ๐Ÿ“ฐ blogs.infoblox.com ๐Ÿ” 0 CVE(s) referenced

A sophisticated threat actor has used the Evilginx adversary-in-the-middle phishing framework to bypass multi-factor authentication and compromise student SSO portals at at least 18 U.S. universities, evading traditional security measures but leaving detectable DNS fingerprints that enable ongoing tracking and protection.

vendor

Sign in to access the full report including:
detailed analysis, IOCs, MITRE ATT&CK mapping, and STIX bundle.

๐Ÿ” Sign In to Read Full Report

You'll need to accept our Terms of Service to access the platform.

๐Ÿ“Š Visual Mindmap
๐ŸŽฏ IOC Extraction
โš”๏ธ MITRE ATT&CK TTPs
๐Ÿ“ฆ STIX 2.1 Bundle