PULSE NAME
DNS Uncovers Infrastructure Used in SSO Attacks
WHITE AlienVault 2025-12-03 Modified: 2026-01-01
67
IOCs
HIGH VOLUME
The threat actor leveraged Evilginx (likely version 3.0), an open source, advanced phishing adversary-in-the-middle (AITM, aka MITM) framework designed to steal login credentials and session cookies. Evilginx is widely used by cybercriminals to undermine multi-factor authentication (MFA) security, and this actor has used it to target at least 18 universities and educational institutions across the United States since April 2025. The campaigns were delivered through email and the phishing domains used subdomains that mimicked the legitimate SSO sites.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
MALWARE FAMILIES
Evilginx
Indicators of Compromise (67)
All domain
TYPEINDICATORDESCRIPTIONCREATED
domain acmsquared.com 2025-12-03
domain ads2ads.com 2025-12-03
domain aghomesandproperties.com 2025-12-03
domain allwebdirectories.com 2025-12-03
domain amj-international.com 2025-12-03
domain apartamentosmalaga.com 2025-12-03
domain armingaud.com 2025-12-03
domain bazmepaigham.com 2025-12-03
domain bedrijvenregister.com 2025-12-03
domain bestshayari.com 2025-12-03
domain brillianceboundielts.com 2025-12-03
domain brownak.com 2025-12-03
domain buildonhope.com 2025-12-03
domain cappadociavisittours.com 2025-12-03
domain catering-amato.com 2025-12-03
domain cccsok.com 2025-12-03
domain citywideprayer.com 2025-12-03
domain controlunlimited.com 2025-12-03
domain coralridgehour.com 2025-12-03
domain dartsinireland.com 2025-12-03
domain data-logistics.com 2025-12-03
domain dhoughton.com 2025-12-03
domain dogcuty.com 2025-12-03
domain e-briefe.com 2025-12-03
domain eggcoo.com 2025-12-03
domain eheringe-trauringe.com 2025-12-03
domain ehsantrust.com 2025-12-03
domain esdetodo.com 2025-12-03
domain fluffybascha.com 2025-12-03
domain forty-something.com 2025-12-03
domain freaksandfriends.com 2025-12-03
domain geegletee.com 2025-12-03
domain georgiayr.com 2025-12-03
domain goraba.com 2025-12-03
domain hafikoman.com 2025-12-03
domain heisseliebe.com 2025-12-03
domain hurenkontakte.com 2025-12-03
domain ideallivingsolutions.com 2025-12-03
domain igreensoft.com 2025-12-03
domain ilchirone.com 2025-12-03
domain impexinc.com 2025-12-03
domain inkdchronicles.com 2025-12-03
domain intellipex.com 2025-12-03
domain intercuba.com 2025-12-03
domain ispamembers.com 2025-12-03
domain jimmylange.com 2025-12-03
domain joshuasdodds.com 2025-12-03
domain kbdav.com 2025-12-03
domain l2storm.com 2025-12-03
domain littlenuggetsco.com 2025-12-03
domain lost-signal.com 2025-12-03
domain lpdeco.com 2025-12-03
domain monnalissaboutique.com 2025-12-03
domain mpoterbaru2024.com 2025-12-03
domain mykidsfashion.com 2025-12-03
domain northstarcouncil.com 2025-12-03
domain qrcodespoweredbygs1.com 2025-12-03
domain schnaitsee.com 2025-12-03
domain sercanaydin.com 2025-12-03
domain srpskazemlja.com 2025-12-03
domain thelovecity.com 2025-12-03
domain thermalresistivity.com 2025-12-03
domain transusasia.com 2025-12-03
domain tubeunderwater.com 2025-12-03
domain weddingsarahetemmanuel.com 2025-12-03
domain winbet299mas.com 2025-12-03
domain yoopuipui.com 2025-12-03