216.73.217.22

Phishing Campaigns Targeting Higher Education Institutions

· Published 24/02/2025 15:43 · Modified 24/02/2025 16:52

Export JSON

Essential information

Published
24/02/2025 15:43
Modified
24/02/2025 16:52
Tags
2025-02-24 business email compromise google forms higher education payment redirection phishing social engineering universities
Related entities
4 observables, 20 techniques (mitre), 2 others

Description

Since August 2024, there has been a significant increase in attacks targeting U.S. . Three distinct campaigns have emerged, exploiting trust within academic institutions to deceive students, faculty, and staff. One campaign used compromised educational institutions to host for . Another involved cloning university login pages and re-hosting them on attacker-controlled infrastructure. A third campaign targeted staff and students in a two-step process, first faculty credentials and then using compromised accounts to target students. These attacks aim to steal login credentials and financial information, often timed to coincide with key dates in the academic calendar. The campaigns employ various tactics to increase perceived legitimacy and perform attacks.

External references