{"id":12633,"date":"2025-12-01T06:55:09","date_gmt":"2025-12-01T14:55:09","guid":{"rendered":"https:\/\/blogs.infoblox.com\/?p=12633"},"modified":"2025-12-01T05:44:27","modified_gmt":"2025-12-01T13:44:27","slug":"dns-uncovers-infrastructure-used-in-sso-attacks","status":"publish","type":"post","link":"https:\/\/www.infoblox.com\/blog\/threat-intelligence\/dns-uncovers-infrastructure-used-in-sso-attacks\/","title":{"rendered":"DNS Uncovers Infrastructure Used in SSO Attacks"},"content":{"rendered":"<p>We recently received a tip from a customer that their institution was under recurring attacks that targeted their student single sign-on (SSO) portal. The threat actor leveraged <a href=\"https:\/\/github.com\/kgretzky\/evilginx2\" target=\"_blank\"><strong>Evilginx<\/strong><\/a> (likely version 3.0), an open source, advanced phishing adversary-in-the-middle (AITM, aka MITM) framework designed to steal login credentials and session cookies. Evilginx is widely used by cybercriminals to undermine multi-factor authentication (MFA) security, and this actor has used it to target at least 18 universities and educational institutions across the United States since April 2025. The campaigns were delivered through email and the phishing domains used subdomains that mimicked the legitimate SSO sites. Figure 1 shows a timeline of attack volumes, based on DNS, against the schools.<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/blogs.infoblox.com\/wp-content\/uploads\/dns-uncovers-infrastructure-used-in-sso-attacks-image1.png\" alt=\"Figure 1\" \/><\/p>\n<p class=\"image-caption\">Figure 1. A timeline of SSO phishing attacks against higher educational institutions by the actor between April 12-Nov 16, 2025. Each color represents a different university.<\/p>\n<p>Evilginx employs multiple evasion techniques, making it difficult to detect and analyze using common methods. For example, the software resists security scanners. Additionally, the actor running the university campaigns configured their toolkit to use short-lived phishing URLs and hide its servers behind Cloudflare proxies. Combined with Evilginx\u2019s reverse-proxy characteristics, these tactics challenge traditional detection methods such as URL analysis and front-end code inspection (HTML, CSS, JavaScript). Nevertheless, the campaigns had consistent DNS patterns that allowed us to craft a signature for effective, continuous tracking using initial web server fingerprinting and extensive DNS-based analysis.<\/p>\n<p>We uncovered nearly 70 domains related to these attacks and created tracking mechanisms to identify future activity. This work demonstrates that DNS can uncover malicious infrastructure that is otherwise very hard to detect, and the results can be used to pre-emptively protect organizations from compromise, including data breaches. It also highlights the benefit of collaboration: by sharing their story, our customer has helped protect many others.<\/p>\n<h3>Campaigns<\/h3>\n<p>In the campaigns we analyzed, students were targeted via personalized emails that contained TinyURL links. These short links redirected to phishing URLs dynamically generated from Evilginx phishlets\u2014configuration files that define how the proxy interacts between the victim\u2019s device and the legitimate site. Each phishing URL used a subdomain that impersonated the target brand and a URI with eight random alphabetic characters (case-insensitive).<\/p>\n<p>The URLs expired within 24 hours, a tactic to limit exposure and evade detection. When victims accessed the phishing URL, Evilginx proxied the legitimate login flows in real time, making traffic appear normal and bypassing MFA. Figure 2 shows a simplified view of the actor\u2019s campaign that targeted students enrolled at the University of San Diego, one of many universities that received these emails.<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/blogs.infoblox.com\/wp-content\/uploads\/dns-uncovers-infrastructure-used-in-sso-attacks-image2.png\" alt=\"Figure 2\" \/><\/p>\n<p class=\"image-caption\">Figure 2. The threat actor used Evilginx to target University of San Diego students.<\/p>\n<h3>DNS Unveils Targets<\/h3>\n<p>Although the Evilginx proxy phishing URLs expired quickly, traces of their activities remain in passive DNS. When cybercriminals configure subdomains for phishlets, they typically use names that closely mimic legitimate login pages to appear authentic. This particular actor uses subdomain labels that match the legitimate service domain. For example, in <a href=\"https:\/\/urlscan.io\/result\/019a3727-739a-765f-b998-2ca9c0933028\/\" target=\"_blank\"><strong>one attack<\/strong><\/a> the phishing subdomain shibbolethmainrit[.]fiuy[.]weddingsarahetemmanuel[.]com impersonated a Rochester Institute of Technology SSO login page, which is hosted at shibboleth.main.ad.rit.edu. Both domains share the prefix &#8220;shibboleth,&#8221; which refers to an open-source identity management and authentication service.<\/p>\n<p>By analyzing these labels, we determined that the actor has targeted at least 18 different U.S. universities. Figure 3 highlights the most targeted institutions based on the volume of DNS queries to their phishing sites. The top five targeted institutions are the University of California Santa Cruz, University of California Santa Barbara, University of San Diego, Virginia Commonwealth University, and the University of Michigan.<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/blogs.infoblox.com\/wp-content\/uploads\/dns-uncovers-infrastructure-used-in-sso-attacks-image3.png\" alt=\"Figure 3\" \/><\/p>\n<p class=\"image-caption\">Figure 3. Universities targeted by the Evilginx actor<\/p>\n<p>While the actor is currently using Cloudflare to hide their hosting location, they previously used dedicated servers in GoDaddy and NameCheap. In their infrastructure conversion, they reused some domains, allowing us to unravel a much larger set of campaigns and analyze the attack timeline. In total, we found 67 domains owned by the actor. The first domain observed was catering-amato[.]com.<\/p>\n<p>The first known phishing attack using this infrastructure occurred on April 12, 2025, against the University of San Diego. Attack volumes remained relatively low until mid-2025, when activity increased significantly. Additional targets were added over time; the University of Maryland, Baltimore County on November 16, 2025. See Figure 1. <\/p>\n<h3>DNS as a Detection Weapon<\/h3>\n<p>The low detection rates across the cybersecurity community highlight how effective Evilginx\u2019s evasion techniques have become. Recent versions, such as Evilginx Pro, add features that make detection even harder. These include default use of wildcard TLS certificates, bot filtering through advanced fingerprinting like JA4, decoy web pages, improved integration with DNS providers (e.g., Cloudflare, DigitalOcean), multi-domain support for phishlets, and JavaScript obfuscation. As Evilginx continues to mature, identifying its phishing URLs will only become more challenging. Traditional detection methods and manual hunting can\u2019t keep pace at scale. Fortunately, threat actors who leverage tools like Evilginx usually still utilize domain names for their operations and often leave fingerprints, allowing us a means to be a little devilish and foil their plans.<\/p>\n<h3>IoAs<\/h3>\n<p>The table below provides IoAs (indicators of activity) used by this Evilginx threat actor. We strongly recommend that organizations block the domains in this list for better protection over DNS. For more indicators, visit the Infoblox Threat Intel Github repo: <a href=\"https:\/\/github.com\/infobloxopen\/threat-intelligence\/tree\/main\" target=\"_blank\"><strong>https:\/\/github.com\/infobloxopen\/threat-intelligence\/tree\/main<\/strong><\/a>.<\/p>\n<table>\n<thead>\n<tr>\n<th>Indicator<\/th>\n<th>Type<\/th>\n<th>Note<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>132[.]148[.]73[.]92<\/td>\n<td>IPv4<\/td>\n<td>Dedicated IP address hosting Evilginx phishing proxy domains<\/td>\n<\/tr>\n<tr>\n<td>132[.]148[.]74[.]178<\/td>\n<td>IPv4<\/td>\n<td>Dedicated IP address hosting Evilginx phishing proxy domains<\/td>\n<\/tr>\n<tr>\n<td>160[.]153[.]176[.]197<\/td>\n<td>IPv4<\/td>\n<td>Dedicated IP address hosting Evilginx phishing proxy domains<\/td>\n<\/tr>\n<tr>\n<td>160[.]153[.]178[.]199<\/td>\n<td>IPv4<\/td>\n<td>Dedicated IP address hosting Evilginx phishing proxy domains<\/td>\n<\/tr>\n<tr>\n<td>162[.]0[.]214[.]254<\/td>\n<td>IPv4<\/td>\n<td>Dedicated IP address hosting Evilginx phishing proxy domains<\/td>\n<\/tr>\n<tr>\n<td>162[.]0[.]228[.]151<\/td>\n<td>IPv4<\/td>\n<td>Dedicated IP address hosting Evilginx phishing proxy domains<\/td>\n<\/tr>\n<tr>\n<td>192[.]169[.]177[.]165<\/td>\n<td>IPv4<\/td>\n<td>Dedicated IP address hosting Evilginx phishing proxy domains<\/td>\n<\/tr>\n<tr>\n<td>199[.]192[.]23[.]40<\/td>\n<td>IPv4<\/td>\n<td>Dedicated IP address hosting Evilginx phishing proxy domains<\/td>\n<\/tr>\n<tr>\n<td>203[.]161[.]60[.]59<\/td>\n<td>IPv4<\/td>\n<td>Dedicated IP address hosting Evilginx phishing proxy domains<\/td>\n<\/tr>\n<tr>\n<td>208[.]109[.]244[.]86<\/td>\n<td>IPv4<\/td>\n<td>Dedicated IP address hosting Evilginx phishing proxy domains<\/td>\n<\/tr>\n<tr>\n<td>208[.]109[.]39[.]196<\/td>\n<td>IPv4<\/td>\n<td>Dedicated IP address hosting Evilginx phishing proxy domains<\/td>\n<\/tr>\n<tr>\n<td>64[.]202[.]186[.]223<\/td>\n<td>IPv4<\/td>\n<td>Dedicated IP address hosting Evilginx phishing proxy domains<\/td>\n<\/tr>\n<tr>\n<td>66[.]29[.]133[.]135<\/td>\n<td>IPv4<\/td>\n<td>Dedicated IP address hosting Evilginx phishing proxy domains<\/td>\n<\/tr>\n<tr>\n<td>72[.]167[.]224[.]193<\/td>\n<td>IPv4<\/td>\n<td>Dedicated IP address hosting Evilginx phishing proxy domains<\/td>\n<\/tr>\n<tr>\n<td>72[.]167[.]52[.]130<\/td>\n<td>IPv4<\/td>\n<td>Dedicated IP address hosting Evilginx phishing proxy domains<\/td>\n<\/tr>\n<tr>\n<td>acmsquared[.]com<\/td>\n<td>domain<\/td>\n<td>Domain used by Evilginx phishing proxy URL<\/td>\n<\/tr>\n<tr>\n<td>ads2ads[.]com<\/td>\n<td>domain<\/td>\n<td>Domain used by Evilginx phishing proxy URL<\/td>\n<\/tr>\n<tr>\n<td>aghomesandproperties[.]com<\/td>\n<td>domain<\/td>\n<td>Domain used by Evilginx phishing proxy URL<\/td>\n<\/tr>\n<tr>\n<td>allwebdirectories[.]com<\/td>\n<td>domain<\/td>\n<td>Domain used by Evilginx phishing proxy URL<\/td>\n<\/tr>\n<tr>\n<td>amj-international[.]com<\/td>\n<td>domain<\/td>\n<td>Domain used by Evilginx phishing proxy URL<\/td>\n<\/tr>\n<tr>\n<td>apartamentosmalaga[.]com<\/td>\n<td>domain<\/td>\n<td>Domain used by Evilginx phishing proxy URL<\/td>\n<\/tr>\n<tr>\n<td>armingaud[.]com<\/td>\n<td>domain<\/td>\n<td>Domain used by Evilginx phishing proxy URL<\/td>\n<\/tr>\n<tr>\n<td>bazmepaigham[.]com<\/td>\n<td>domain<\/td>\n<td>Domain used by Evilginx phishing proxy URL<\/td>\n<\/tr>\n<tr>\n<td>bedrijvenregister[.]com<\/td>\n<td>domain<\/td>\n<td>Domain used by Evilginx phishing proxy URL<\/td>\n<\/tr>\n<tr>\n<td>bestshayari[.]com<\/td>\n<td>domain<\/td>\n<td>Domain used by Evilginx phishing proxy URL<\/td>\n<\/tr>\n<tr>\n<td>brillianceboundielts[.]com<\/td>\n<td>domain<\/td>\n<td>Domain used by Evilginx phishing proxy URL<\/td>\n<\/tr>\n<tr>\n<td>brownak[.]com<\/td>\n<td>domain<\/td>\n<td>Domain used by Evilginx phishing proxy URL<\/td>\n<\/tr>\n<tr>\n<td>buildonhope[.]com<\/td>\n<td>domain<\/td>\n<td>Domain used by Evilginx phishing proxy URL<\/td>\n<\/tr>\n<tr>\n<td>cappadociavisittours[.]com<\/td>\n<td>domain<\/td>\n<td>Domain used by Evilginx phishing proxy URL<\/td>\n<\/tr>\n<tr>\n<td>catering-amato[.]com<\/td>\n<td>domain<\/td>\n<td>Domain used by Evilginx phishing proxy URL<\/td>\n<\/tr>\n<tr>\n<td>cccsok[.]com<\/td>\n<td>domain<\/td>\n<td>Domain used by Evilginx phishing proxy URL<\/td>\n<\/tr>\n<tr>\n<td>citywideprayer[.]com<\/td>\n<td>domain<\/td>\n<td>Domain used by Evilginx phishing proxy URL<\/td>\n<\/tr>\n<tr>\n<td>controlunlimited[.]com<\/td>\n<td>domain<\/td>\n<td>Domain used by Evilginx phishing proxy URL<\/td>\n<\/tr>\n<tr>\n<td>coralridgehour[.]com<\/td>\n<td>domain<\/td>\n<td>Domain used by Evilginx phishing proxy URL<\/td>\n<\/tr>\n<tr>\n<td>dartsinireland[.]com<\/td>\n<td>domain<\/td>\n<td>Domain used by Evilginx phishing proxy URL<\/td>\n<\/tr>\n<tr>\n<td>data-logistics[.]com<\/td>\n<td>domain<\/td>\n<td>Domain used by Evilginx phishing proxy URL<\/td>\n<\/tr>\n<tr>\n<td>dhoughton[.]com<\/td>\n<td>domain<\/td>\n<td>Domain used by Evilginx phishing proxy URL<\/td>\n<\/tr>\n<tr>\n<td>dogcuty[.]com<\/td>\n<td>domain<\/td>\n<td>Domain used by Evilginx phishing proxy URL<\/td>\n<\/tr>\n<tr>\n<td>e-briefe[.]com<\/td>\n<td>domain<\/td>\n<td>Domain used by Evilginx phishing proxy URL<\/td>\n<\/tr>\n<tr>\n<td>eggcoo[.]com<\/td>\n<td>domain<\/td>\n<td>Domain used by Evilginx phishing proxy URL<\/td>\n<\/tr>\n<tr>\n<td>eheringe-trauringe[.]com<\/td>\n<td>domain<\/td>\n<td>Domain used by Evilginx phishing proxy URL<\/td>\n<\/tr>\n<tr>\n<td>ehsantrust[.]com<\/td>\n<td>domain<\/td>\n<td>Domain used by Evilginx phishing proxy URL<\/td>\n<\/tr>\n<tr>\n<td>esdetodo[.]com<\/td>\n<td>domain<\/td>\n<td>Domain used by Evilginx phishing proxy URL<\/td>\n<\/tr>\n<tr>\n<td>fluffybascha[.]com<\/td>\n<td>domain<\/td>\n<td>Domain used by Evilginx phishing proxy URL<\/td>\n<\/tr>\n<tr>\n<td>forty-something[.]com<\/td>\n<td>domain<\/td>\n<td>Domain used by Evilginx phishing proxy URL<\/td>\n<\/tr>\n<tr>\n<td>freaksandfriends[.]com<\/td>\n<td>domain<\/td>\n<td>Domain used by Evilginx phishing proxy URL<\/td>\n<\/tr>\n<tr>\n<td>geegletee[.]com<\/td>\n<td>domain<\/td>\n<td>Domain used by Evilginx phishing proxy URL<\/td>\n<\/tr>\n<tr>\n<td>georgiayr[.]com<\/td>\n<td>domain<\/td>\n<td>Domain used by Evilginx phishing proxy URL<\/td>\n<\/tr>\n<tr>\n<td>goraba[.]com<\/td>\n<td>domain<\/td>\n<td>Domain used by Evilginx phishing proxy URL<\/td>\n<\/tr>\n<tr>\n<td>hafikoman[.]com<\/td>\n<td>domain<\/td>\n<td>Domain used by Evilginx phishing proxy URL<\/td>\n<\/tr>\n<tr>\n<td>heisseliebe[.]com<\/td>\n<td>domain<\/td>\n<td>Domain used by Evilginx phishing proxy URL<\/td>\n<\/tr>\n<tr>\n<td>hurenkontakte[.]com<\/td>\n<td>domain<\/td>\n<td>Domain used by Evilginx phishing proxy URL<\/td>\n<\/tr>\n<tr>\n<td>ideallivingsolutions[.]com<\/td>\n<td>domain<\/td>\n<td>Domain used by Evilginx phishing proxy URL<\/td>\n<\/tr>\n<tr>\n<td>igreensoft[.]com<\/td>\n<td>domain<\/td>\n<td>Domain used by Evilginx phishing proxy URL<\/td>\n<\/tr>\n<tr>\n<td>ilchirone[.]com<\/td>\n<td>domain<\/td>\n<td>Domain used by Evilginx phishing proxy URL<\/td>\n<\/tr>\n<tr>\n<td>impexinc[.]com<\/td>\n<td>domain<\/td>\n<td>Domain used by Evilginx phishing proxy URL<\/td>\n<\/tr>\n<tr>\n<td>inkdchronicles[.]com<\/td>\n<td>domain<\/td>\n<td>Domain used by Evilginx phishing proxy URL<\/td>\n<\/tr>\n<tr>\n<td>intellipex[.]com<\/td>\n<td>domain<\/td>\n<td>Domain used by Evilginx phishing proxy URL<\/td>\n<\/tr>\n<tr>\n<td>intercuba[.]com<\/td>\n<td>domain<\/td>\n<td>Domain used by Evilginx phishing proxy URL<\/td>\n<\/tr>\n<tr>\n<td>ispamembers[.]com<\/td>\n<td>domain<\/td>\n<td>Domain used by Evilginx phishing proxy URL<\/td>\n<\/tr>\n<tr>\n<td>jimmylange[.]com<\/td>\n<td>domain<\/td>\n<td>Domain used by Evilginx phishing proxy URL<\/td>\n<\/tr>\n<tr>\n<td>joshuasdodds[.]com<\/td>\n<td>domain<\/td>\n<td>Domain used by Evilginx phishing proxy URL<\/td>\n<\/tr>\n<tr>\n<td>kbdav[.]com<\/td>\n<td>domain<\/td>\n<td>Domain used by Evilginx phishing proxy URL<\/td>\n<\/tr>\n<tr>\n<td>l2storm[.]com<\/td>\n<td>domain<\/td>\n<td>Domain used by Evilginx phishing proxy URL<\/td>\n<\/tr>\n<tr>\n<td>littlenuggetsco[.]com<\/td>\n<td>domain<\/td>\n<td>Domain used by Evilginx phishing proxy URL<\/td>\n<\/tr>\n<tr>\n<td>lost-signal[.]com<\/td>\n<td>domain<\/td>\n<td>Domain used by Evilginx phishing proxy URL<\/td>\n<\/tr>\n<tr>\n<td>lpdeco[.]com<\/td>\n<td>domain<\/td>\n<td>Domain used by Evilginx phishing proxy URL<\/td>\n<\/tr>\n<tr>\n<td>monnalissaboutique[.]com<\/td>\n<td>domain<\/td>\n<td>Domain used by Evilginx phishing proxy URL<\/td>\n<\/tr>\n<tr>\n<td>mpoterbaru2024[.]com<\/td>\n<td>domain<\/td>\n<td>Domain used by Evilginx phishing proxy URL<\/td>\n<\/tr>\n<tr>\n<td>mykidsfashion[.]com<\/td>\n<td>domain<\/td>\n<td>Domain used by Evilginx phishing proxy URL<\/td>\n<\/tr>\n<tr>\n<td>northstarcouncil[.]com<\/td>\n<td>domain<\/td>\n<td>Domain used by Evilginx phishing proxy URL<\/td>\n<\/tr>\n<tr>\n<td>qrcodespoweredbygs1[.]com<\/td>\n<td>domain<\/td>\n<td>Domain used by Evilginx phishing proxy URL<\/td>\n<\/tr>\n<tr>\n<td>schnaitsee[.]com<\/td>\n<td>domain<\/td>\n<td>Domain used by Evilginx phishing proxy URL<\/td>\n<\/tr>\n<tr>\n<td>sercanaydin[.]com<\/td>\n<td>domain<\/td>\n<td>Domain used by Evilginx phishing proxy URL<\/td>\n<\/tr>\n<tr>\n<td>srpskazemlja[.]com<\/td>\n<td>domain<\/td>\n<td>Domain used by Evilginx phishing proxy URL<\/td>\n<\/tr>\n<tr>\n<td>thelovecity[.]com<\/td>\n<td>domain<\/td>\n<td>Domain used by Evilginx phishing proxy URL<\/td>\n<\/tr>\n<tr>\n<td>thermalresistivity[.]com<\/td>\n<td>domain<\/td>\n<td>Domain used by Evilginx phishing proxy URL<\/td>\n<\/tr>\n<tr>\n<td>transusasia[.]com<\/td>\n<td>domain<\/td>\n<td>Domain used by Evilginx phishing proxy URL<\/td>\n<\/tr>\n<tr>\n<td>tubeunderwater[.]com<\/td>\n<td>domain<\/td>\n<td>Domain used by Evilginx phishing proxy URL<\/td>\n<\/tr>\n<tr>\n<td>weddingsarahetemmanuel[.]com<\/td>\n<td>domain<\/td>\n<td>Domain used by Evilginx phishing proxy URL<\/td>\n<\/tr>\n<tr>\n<td>winbet299mas[.]com<\/td>\n<td>domain<\/td>\n<td>Domain used by Evilginx phishing proxy URL<\/td>\n<\/tr>\n<tr>\n<td>yoopuipui[.]com<\/td>\n<td>domain<\/td>\n<td>Domain used by Evilginx phishing proxy URL<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<style>\n.savy-seahorse-table {font-size:14px;word-break: keep-all;}.savy-seahorse-table td:last-child, .savy-seahorse-table th:last-child {padding-right:10px;}.\/*code-format {\tfont-family: 'Courier New';}*\/.image-caption {    font-size: 12px;margin-top:auto;}.list-spacing li{margin-bottom:20px}.img-container, .img-container-3-col {display: flex;}.img-container img {    width: 40%;    margin-bottom: 10px;    height: max-content !important;}.img-container-3-col img {width: 30%;margin-bottom: 10px;}@media (max-width: 767px) {.img-container, .img-container-3-col {display: block;}.img-container img, .img-container-3-col img {width: 100%;}.grid-container {    grid-template-columns: 1fr!important;  }}@media (min-width: 767px) {.img-50{width:50%;}}.grid-container {  display: grid;  grid-template-columns: repeat(2, 1fr);  gap: 40px;  max-width: 800px;  margin: 0 auto;  align-items: stretch;}.grid-item {   display: flex;  flex-direction: column;  justify-content: flex-start;}.grid-item img {  width: 100%;  height: auto;}.image-caption {font-size: 12px;}.iti-blog-table,\n.iti-blog-table * {\n    font-size: 15px !important;\n}<\/style>\n<p><script>\njQuery('.single h1').html('<span class=\"gradient\">DNS Uncovers Infrastructure<\/span> Used in SSO Attacks');\n<\/script><\/p>\n","protected":false},"excerpt":{"rendered":"<p>We recently received a tip from a customer that their institution was under recurring attacks that targeted their student single sign-on (SSO) portal. The threat actor leveraged Evilginx (likely version 3.0), an open source, advanced phishing adversary-in-the-middle (AITM, aka MITM) framework designed to steal login credentials and session cookies. Evilginx is widely used by cybercriminals [&hellip;]<\/p>\n","protected":false},"author":397,"featured_media":12634,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"inline_featured_image":false,"_genesis_hide_title":false,"_genesis_hide_breadcrumbs":false,"_genesis_hide_singular_image":false,"_genesis_hide_footer_widgets":false,"_genesis_custom_body_class":"","_genesis_custom_post_class":"","_genesis_layout":"","footnotes":""},"categories":[254],"tags":[1466,1467,1468,1469,30,1470,1471,1472,1473,1474],"class_list":{"0":"post-12633","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-threat-intelligence","8":"tag-evilginx-phishing","9":"tag-evilginx-aitm-phishing","10":"tag-sso-attack","11":"tag-mfa-attack","12":"tag-dns","13":"tag-evilginx-attack-detection","14":"tag-dns-based-phishing-detection","15":"tag-evilginx-evasion-techniques","16":"tag-evilginx-reverse-proxy-phishing","17":"tag-evilginx-pro-features","18":"entry"},"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v27.3 (Yoast SEO v27.3) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>DNS Uncovers Infrastructure Used in SSO Attacks<\/title>\n<meta name=\"description\" content=\"Learn how DNS was used to uncover Evilginx AITM infrastructure attacking U.S. university single sign-on (SSO) portals to phish student login credentials.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.infoblox.com\/blog\/threat-intelligence\/dns-uncovers-infrastructure-used-in-sso-attacks\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"DNS Uncovers Infrastructure Used in SSO Attacks\" \/>\n<meta property=\"og:description\" content=\"Learn how DNS was used to uncover Evilginx AITM infrastructure attacking U.S. university single sign-on (SSO) portals to phish student login credentials.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.infoblox.com\/blog\/threat-intelligence\/dns-uncovers-infrastructure-used-in-sso-attacks\/\" \/>\n<meta property=\"og:site_name\" content=\"Infoblox Blog\" \/>\n<meta property=\"article:published_time\" content=\"2025-12-01T14:55:09+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/blog-sso-phishing-attacks-univerities-thumbnail.jpeg\" \/>\n\t<meta property=\"og:image:width\" content=\"612\" \/>\n\t<meta property=\"og:image:height\" content=\"408\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Infoblox Threat Intel\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:title\" content=\"DNS Uncovers Infrastructure Used in SSO Attacks\" \/>\n<meta name=\"twitter:description\" content=\"Learn how DNS was used to uncover Evilginx AITM infrastructure attacking U.S. university single sign-on (SSO) portals to phish student login credentials.\" \/>\n<meta name=\"twitter:image\" content=\"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/blog-sso-phishing-attacks-univerities-thumbnail.jpeg\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Infoblox Threat Intel\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"8 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/threat-intelligence\\\/dns-uncovers-infrastructure-used-in-sso-attacks\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/threat-intelligence\\\/dns-uncovers-infrastructure-used-in-sso-attacks\\\/\"},\"author\":{\"name\":\"Infoblox Threat Intel\",\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/#\\\/schema\\\/person\\\/b6aed8965e3298a0817c16d32c0a67ae\"},\"headline\":\"DNS Uncovers Infrastructure Used in SSO Attacks\",\"datePublished\":\"2025-12-01T14:55:09+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/threat-intelligence\\\/dns-uncovers-infrastructure-used-in-sso-attacks\\\/\"},\"wordCount\":1698,\"publisher\":{\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/threat-intelligence\\\/dns-uncovers-infrastructure-used-in-sso-attacks\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/wp-content\\\/uploads\\\/blog-sso-phishing-attacks-univerities-thumbnail.jpeg\",\"keywords\":[\"Evilginx phishing\",\"Evilginx AITM phishing\",\"SSO attack\",\"MFA attack\",\"DNS\",\"Evilginx attack detection\",\"DNS-based phishing detection\",\"Evilginx evasion techniques\",\"Evilginx reverse proxy phishing\",\"Evilginx Pro features\"],\"articleSection\":[\"Infoblox Threat Intel\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/threat-intelligence\\\/dns-uncovers-infrastructure-used-in-sso-attacks\\\/\",\"url\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/threat-intelligence\\\/dns-uncovers-infrastructure-used-in-sso-attacks\\\/\",\"name\":\"DNS Uncovers Infrastructure Used in SSO Attacks\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/threat-intelligence\\\/dns-uncovers-infrastructure-used-in-sso-attacks\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/threat-intelligence\\\/dns-uncovers-infrastructure-used-in-sso-attacks\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/wp-content\\\/uploads\\\/blog-sso-phishing-attacks-univerities-thumbnail.jpeg\",\"datePublished\":\"2025-12-01T14:55:09+00:00\",\"description\":\"Learn how DNS was used to uncover Evilginx AITM infrastructure attacking U.S. university single sign-on (SSO) portals to phish student login credentials.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/threat-intelligence\\\/dns-uncovers-infrastructure-used-in-sso-attacks\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/threat-intelligence\\\/dns-uncovers-infrastructure-used-in-sso-attacks\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/threat-intelligence\\\/dns-uncovers-infrastructure-used-in-sso-attacks\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/wp-content\\\/uploads\\\/blog-sso-phishing-attacks-univerities-thumbnail.jpeg\",\"contentUrl\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/wp-content\\\/uploads\\\/blog-sso-phishing-attacks-univerities-thumbnail.jpeg\",\"width\":612,\"height\":408},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/threat-intelligence\\\/dns-uncovers-infrastructure-used-in-sso-attacks\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Infoblox Threat Intel\",\"item\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/category\\\/threat-intelligence\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"DNS Uncovers Infrastructure Used in SSO Attacks\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/\",\"name\":\"infoblox.com\\\/blog\\\/\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/#organization\",\"name\":\"Infoblox\",\"url\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/wp-content\\\/uploads\\\/infoblox-logo-2.svg\",\"contentUrl\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/wp-content\\\/uploads\\\/infoblox-logo-2.svg\",\"width\":137,\"height\":30,\"caption\":\"Infoblox\"},\"image\":{\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/#\\\/schema\\\/person\\\/b6aed8965e3298a0817c16d32c0a67ae\",\"name\":\"Infoblox Threat Intel\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/blogs.infoblox.com\\\/wp-content\\\/uploads\\\/avatar_user_397_1714162589-96x96.png\",\"url\":\"https:\\\/\\\/blogs.infoblox.com\\\/wp-content\\\/uploads\\\/avatar_user_397_1714162589-96x96.png\",\"contentUrl\":\"https:\\\/\\\/blogs.infoblox.com\\\/wp-content\\\/uploads\\\/avatar_user_397_1714162589-96x96.png\",\"caption\":\"Infoblox Threat Intel\"},\"description\":\"Infoblox Threat Intel is the leading creator of original DNS threat intelligence, distinguishing itself in a sea of aggregators. What sets us apart? Two things: mad DNS skills and unparalleled visibility. DNS is notoriously tricky to interpret and hunt from, but our deep understanding and unique access to the internet's inner workings allow us to track down threat actors that others can't see. We're proactive, not just defensive, using our insights to disrupt cybercrime where it begins. We also believe in sharing knowledge to support the broader security community by publishing detailed research and releasing indicators on GitHub. In addition, our intel is seamlessly integrated into our Infoblox Protective DNS solutions, so customers automatically get its benefits, along with ridiculously low false positive rates.\",\"url\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/author\\\/infoblox-threat-intel\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"DNS Uncovers Infrastructure Used in SSO Attacks","description":"Learn how DNS was used to uncover Evilginx AITM infrastructure attacking U.S. university single sign-on (SSO) portals to phish student login credentials.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.infoblox.com\/blog\/threat-intelligence\/dns-uncovers-infrastructure-used-in-sso-attacks\/","og_locale":"en_US","og_type":"article","og_title":"DNS Uncovers Infrastructure Used in SSO Attacks","og_description":"Learn how DNS was used to uncover Evilginx AITM infrastructure attacking U.S. university single sign-on (SSO) portals to phish student login credentials.","og_url":"https:\/\/www.infoblox.com\/blog\/threat-intelligence\/dns-uncovers-infrastructure-used-in-sso-attacks\/","og_site_name":"Infoblox Blog","article_published_time":"2025-12-01T14:55:09+00:00","og_image":[{"width":612,"height":408,"url":"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/blog-sso-phishing-attacks-univerities-thumbnail.jpeg","type":"image\/jpeg"}],"author":"Infoblox Threat Intel","twitter_card":"summary_large_image","twitter_title":"DNS Uncovers Infrastructure Used in SSO Attacks","twitter_description":"Learn how DNS was used to uncover Evilginx AITM infrastructure attacking U.S. university single sign-on (SSO) portals to phish student login credentials.","twitter_image":"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/blog-sso-phishing-attacks-univerities-thumbnail.jpeg","twitter_misc":{"Written by":"Infoblox Threat Intel","Est. reading time":"8 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.infoblox.com\/blog\/threat-intelligence\/dns-uncovers-infrastructure-used-in-sso-attacks\/#article","isPartOf":{"@id":"https:\/\/www.infoblox.com\/blog\/threat-intelligence\/dns-uncovers-infrastructure-used-in-sso-attacks\/"},"author":{"name":"Infoblox Threat Intel","@id":"https:\/\/www.infoblox.com\/blog\/#\/schema\/person\/b6aed8965e3298a0817c16d32c0a67ae"},"headline":"DNS Uncovers Infrastructure Used in SSO Attacks","datePublished":"2025-12-01T14:55:09+00:00","mainEntityOfPage":{"@id":"https:\/\/www.infoblox.com\/blog\/threat-intelligence\/dns-uncovers-infrastructure-used-in-sso-attacks\/"},"wordCount":1698,"publisher":{"@id":"https:\/\/www.infoblox.com\/blog\/#organization"},"image":{"@id":"https:\/\/www.infoblox.com\/blog\/threat-intelligence\/dns-uncovers-infrastructure-used-in-sso-attacks\/#primaryimage"},"thumbnailUrl":"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/blog-sso-phishing-attacks-univerities-thumbnail.jpeg","keywords":["Evilginx phishing","Evilginx AITM phishing","SSO attack","MFA attack","DNS","Evilginx attack detection","DNS-based phishing detection","Evilginx evasion techniques","Evilginx reverse proxy phishing","Evilginx Pro features"],"articleSection":["Infoblox Threat Intel"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.infoblox.com\/blog\/threat-intelligence\/dns-uncovers-infrastructure-used-in-sso-attacks\/","url":"https:\/\/www.infoblox.com\/blog\/threat-intelligence\/dns-uncovers-infrastructure-used-in-sso-attacks\/","name":"DNS Uncovers Infrastructure Used in SSO Attacks","isPartOf":{"@id":"https:\/\/www.infoblox.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.infoblox.com\/blog\/threat-intelligence\/dns-uncovers-infrastructure-used-in-sso-attacks\/#primaryimage"},"image":{"@id":"https:\/\/www.infoblox.com\/blog\/threat-intelligence\/dns-uncovers-infrastructure-used-in-sso-attacks\/#primaryimage"},"thumbnailUrl":"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/blog-sso-phishing-attacks-univerities-thumbnail.jpeg","datePublished":"2025-12-01T14:55:09+00:00","description":"Learn how DNS was used to uncover Evilginx AITM infrastructure attacking U.S. university single sign-on (SSO) portals to phish student login credentials.","breadcrumb":{"@id":"https:\/\/www.infoblox.com\/blog\/threat-intelligence\/dns-uncovers-infrastructure-used-in-sso-attacks\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.infoblox.com\/blog\/threat-intelligence\/dns-uncovers-infrastructure-used-in-sso-attacks\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.infoblox.com\/blog\/threat-intelligence\/dns-uncovers-infrastructure-used-in-sso-attacks\/#primaryimage","url":"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/blog-sso-phishing-attacks-univerities-thumbnail.jpeg","contentUrl":"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/blog-sso-phishing-attacks-univerities-thumbnail.jpeg","width":612,"height":408},{"@type":"BreadcrumbList","@id":"https:\/\/www.infoblox.com\/blog\/threat-intelligence\/dns-uncovers-infrastructure-used-in-sso-attacks\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.infoblox.com\/blog\/"},{"@type":"ListItem","position":2,"name":"Infoblox Threat Intel","item":"https:\/\/www.infoblox.com\/blog\/category\/threat-intelligence\/"},{"@type":"ListItem","position":3,"name":"DNS Uncovers Infrastructure Used in SSO Attacks"}]},{"@type":"WebSite","@id":"https:\/\/www.infoblox.com\/blog\/#website","url":"https:\/\/www.infoblox.com\/blog\/","name":"infoblox.com\/blog\/","description":"","publisher":{"@id":"https:\/\/www.infoblox.com\/blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.infoblox.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.infoblox.com\/blog\/#organization","name":"Infoblox","url":"https:\/\/www.infoblox.com\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.infoblox.com\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/infoblox-logo-2.svg","contentUrl":"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/infoblox-logo-2.svg","width":137,"height":30,"caption":"Infoblox"},"image":{"@id":"https:\/\/www.infoblox.com\/blog\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/www.infoblox.com\/blog\/#\/schema\/person\/b6aed8965e3298a0817c16d32c0a67ae","name":"Infoblox Threat Intel","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/blogs.infoblox.com\/wp-content\/uploads\/avatar_user_397_1714162589-96x96.png","url":"https:\/\/blogs.infoblox.com\/wp-content\/uploads\/avatar_user_397_1714162589-96x96.png","contentUrl":"https:\/\/blogs.infoblox.com\/wp-content\/uploads\/avatar_user_397_1714162589-96x96.png","caption":"Infoblox Threat Intel"},"description":"Infoblox Threat Intel is the leading creator of original DNS threat intelligence, distinguishing itself in a sea of aggregators. What sets us apart? Two things: mad DNS skills and unparalleled visibility. DNS is notoriously tricky to interpret and hunt from, but our deep understanding and unique access to the internet's inner workings allow us to track down threat actors that others can't see. We're proactive, not just defensive, using our insights to disrupt cybercrime where it begins. We also believe in sharing knowledge to support the broader security community by publishing detailed research and releasing indicators on GitHub. In addition, our intel is seamlessly integrated into our Infoblox Protective DNS solutions, so customers automatically get its benefits, along with ridiculously low false positive rates.","url":"https:\/\/www.infoblox.com\/blog\/author\/infoblox-threat-intel\/"}]}},"_links":{"self":[{"href":"https:\/\/www.infoblox.com\/blog\/wp-json\/wp\/v2\/posts\/12633","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.infoblox.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.infoblox.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.infoblox.com\/blog\/wp-json\/wp\/v2\/users\/397"}],"replies":[{"embeddable":true,"href":"https:\/\/www.infoblox.com\/blog\/wp-json\/wp\/v2\/comments?post=12633"}],"version-history":[{"count":5,"href":"https:\/\/www.infoblox.com\/blog\/wp-json\/wp\/v2\/posts\/12633\/revisions"}],"predecessor-version":[{"id":12637,"href":"https:\/\/www.infoblox.com\/blog\/wp-json\/wp\/v2\/posts\/12633\/revisions\/12637"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.infoblox.com\/blog\/wp-json\/wp\/v2\/media\/12634"}],"wp:attachment":[{"href":"https:\/\/www.infoblox.com\/blog\/wp-json\/wp\/v2\/media?parent=12633"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.infoblox.com\/blog\/wp-json\/wp\/v2\/categories?post=12633"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.infoblox.com\/blog\/wp-json\/wp\/v2\/tags?post=12633"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}