
Three-Layer Evasion Stack Targets Education Networks via Per-Victim Phishing URLs
A spearphishing campaign against the education and research sector is routing victims through a DGA-tagged C2 domain that fingerprints browser environments before firing its redirect. The infrastructure stacks fast-flux DNS, a CNAME hop through an unanalysed secondary domain, and freshly provisioned IPs that register near-zero detections across 91 scanning engines.
Thirteen individualised phishing URLs, each carrying a distinct base64-encoded payload that fingerprints the victim's browser before deciding whether to proceed — that is the opening move of a campaign CTX Team has been tracking against the education and research sector, built on infrastructure that layers domain-generation algorithm tagging, fast-flux DNS across eight A-records at 60-second TTLs, and a CNAME redirect through a secondary unanalysed domain, all backed by freshly provisioned…
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read