Threat actors have launched a sophisticated phishing campaign targeting U.S. universities by leveraging the open-source Evilginx framework. At least 18 educational institutions have been affected since April 2025, with attackers using personalized emails containing TinyURL links that redirect to dynamically generated phishing pages. These pages closely mimic student single sign-on portals and employ advanced evasion techniques, such as expiring URLs, wildcard TLS certificates, bot filtering, and JavaScript obfuscation, making detection and mitigation increasingly difficult. The campaign demonstrates the growing accessibility of advanced phishing tools, enabling even unskilled actors to bypass multi-factor authentication and compromise sensitive credentials.
Simultaneously, a new phishing kit called Spiderman has emerged on the dark web, targeting customers of major European banks and cryptocurrency platforms. This full-stack kit allows attackers to easily clone login pages for dozens of financial institutions and conduct real-time credential theft across multiple countries. With a large user community and features that facilitate immediate data exfiltration and hybrid fraud operations, Spiderman represents a significant escalation in the scale and efficiency of phishing threats facing the financial sector. Both campaigns highlight the evolving landscape of phishing, where sophisticated toolkits are lowering the barrier to entry for cybercriminals and increasing the risk to organizations worldwide.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
Researchers disclosed four advanced phishing kits—BlackForce, GhostFrame, InboxPrime AI, and Spiderman—highlighting the growing industrialization of phishing. The report emphasized AI-assisted phishing, MFA bypass, anti-analysis features, and sales through Telegram and Signal as part of a wider trend toward scalable credential theft operations.
Further reporting revealed that Spiderman is modular, supports interception of OTP and PhotoTAN codes, and provides a dashboard for real-time monitoring and export of stolen data. Researchers also observed a Signal group with roughly 750 members, indicating broad adoption among threat actors.
Varonis researchers identified the Spiderman phishing kit as a new phishing-as-a-service offering targeting major European banks and cryptocurrency platforms across at least five countries. The kit supports real-time theft of banking credentials, MFA codes, card data, and crypto wallet seed phrases while using geo-targeting and other evasion features.
Threat actors began using the open-source Evilginx framework in April 2025 to target at least 18 U.S. universities and educational entities. The campaign used personalized phishing emails with TinyURL links leading to dynamically generated fake student SSO portals.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
thehackernews.com
Open sourcebleepingcomputer.com
Open sourceblog.knowbe4.com
Open sourcehackread.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.