Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
phishing-campaign-intelligenceeducation-sector-threatfinancial-sector-threatcredential-access-method

Phishing Campaigns Using Advanced Kits Targeting Universities and Banks

Updated 3mo agoFirst seen Dec 10, 20254 sources

Threat actors have launched a sophisticated phishing campaign targeting U.S. universities by leveraging the open-source Evilginx framework. At least 18 educational institutions have been affected since April 2025, with attackers using personalized emails containing TinyURL links that redirect to dynamically generated phishing pages. These pages closely mimic student single sign-on portals and employ advanced evasion techniques, such as expiring URLs, wildcard TLS certificates, bot filtering, and JavaScript obfuscation, making detection and mitigation increasingly difficult. The campaign demonstrates the growing accessibility of advanced phishing tools, enabling even unskilled actors to bypass multi-factor authentication and compromise sensitive credentials.

Simultaneously, a new phishing kit called Spiderman has emerged on the dark web, targeting customers of major European banks and cryptocurrency platforms. This full-stack kit allows attackers to easily clone login pages for dozens of financial institutions and conduct real-time credential theft across multiple countries. With a large user community and features that facilitate immediate data exfiltration and hybrid fraud operations, Spiderman represents a significant escalation in the scale and efficiency of phishing threats facing the financial sector. Both campaigns highlight the evolving landscape of phishing, where sophisticated toolkits are lowering the barrier to entry for cybercriminals and increasing the risk to organizations worldwide.

Share:
Phishing Campaigns Using Advanced Kits Targeting Universities and Banks
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

4 events from the most recent confirmed update back to the earliest known activity.

4 EVENTS
Dec 12, 20256mo ago

Researchers identify broader wave of advanced phishing kits

Researchers disclosed four advanced phishing kits—BlackForce, GhostFrame, InboxPrime AI, and Spiderman—highlighting the growing industrialization of phishing. The report emphasized AI-assisted phishing, MFA bypass, anti-analysis features, and sales through Telegram and Signal as part of a wider trend toward scalable credential theft operations.

Dec 10, 20257mo ago

Researchers detail Spiderman's scale and operator ecosystem

Further reporting revealed that Spiderman is modular, supports interception of OTP and PhotoTAN codes, and provides a dashboard for real-time monitoring and export of stolen data. Researchers also observed a Signal group with roughly 750 members, indicating broad adoption among threat actors.

Dec 9, 20257mo ago

Researchers report Spiderman phishing kit targeting European banks

Varonis researchers identified the Spiderman phishing kit as a new phishing-as-a-service offering targeting major European banks and cryptocurrency platforms across at least five countries. The kit supports real-time theft of banking credentials, MFA codes, card data, and crypto wallet seed phrases while using geo-targeting and other evasion features.

Apr 1, 20251y ago

Evilginx phishing campaign begins targeting U.S. universities

Threat actors began using the open-source Evilginx framework in April 2025 to target at least 18 U.S. universities and educational entities. The campaign used personalized phishing emails with TinyURL links leading to dynamically generated fake student SSO portals.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

25 LINKEDOpen in app
Malware
1 linked
Organizations
24 linked
VaronisBarracuda NetworksZscalerAny.RunAbnormal AIINGCommerzbankCaixaBankDeutsche BankDigitaloceanCloudflareKnowbe4PayPalInfobloxHackread.comMetamaskEvilginxLedgerO2BlauKlarnaVolksbankComdirectExodus Movement
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Phishing Campaigns Using Advanced Kits Targeting Universities and Banks | Mallory