{"id":179,"date":"2025-11-16T20:10:00","date_gmt":"2025-11-16T20:10:00","guid":{"rendered":"http:\/\/localhost\/?p=26"},"modified":"2025-11-16T20:10:00","modified_gmt":"2025-11-16T20:10:00","slug":"cyber-alert-active-phishing-campaign-impersonating-denison-accounts","status":"publish","type":"post","link":"https:\/\/securityblog.denison.edu\/index.php\/2025\/11\/16\/cyber-alert-active-phishing-campaign-impersonating-denison-accounts\/","title":{"rendered":"Active phishing campaign impersonating Denison accounts"},"content":{"rendered":"<p>Denison&#8217;s cybersecurity intelligence has observed an aggressive phishing campaign that has been targeting Denison over the past several weeks. This campaign has included multiple messages sent by different means, but all messages attempt to get a user to click on a link and input account credentials, such as usernames and passwords.<\/p>\n<p>In this campaign, we have noticed impersonation of Denison accounts, including the Service Desk. This campaign includes a link or button that goes to a malicious webpage. We have observed the following domains.<\/p>\n<ul>\n<li>vdgmentorias[.]com<\/li>\n<li>du[.]vdgmentorias[.]com<\/li>\n<\/ul>\n<p>You can see the domain by hovering over the link with your mouse on a computer and looking in the bottom-left corner. The domain should match denison.edu.<\/p>\n<p>Denison will never ask for your password by email, by Google Form, or by calling. If you receive such a message, please forward it to our reporting mailbox at <a href=\"mailto:isitsafe@denison.edu\">isitsafe@denison.edu<\/a>. If you have accidentally interacted with a message or think you might&#8217;ve sent credentials, immediately contact the Service Desk.<\/p>\n\n\n<p class=\"wp-block-paragraph\"><em>Edit (Feb 17, 2026): We now attribute this phishing campaign to a threat actor we track as <\/em>MIDNIGHTSTONEFISH.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Denison&#8217;s cybersecurity intelligence has observed an aggressive phishing campaign that has been targeting Denison over the past several weeks. This campaign has included multiple messages sent by different means, but all messages attempt to get a user to click on a link and input account credentials, such as usernames and passwords. In this campaign, we have noticed impersonation of Denison accounts, including the Service Desk. This campaign includes a link&#8230;<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-179","post","type-post","status-publish","format-standard","hentry","category-uncategorized"],"_links":{"self":[{"href":"https:\/\/securityblog.denison.edu\/index.php\/wp-json\/wp\/v2\/posts\/179","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/securityblog.denison.edu\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/securityblog.denison.edu\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/securityblog.denison.edu\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/securityblog.denison.edu\/index.php\/wp-json\/wp\/v2\/comments?post=179"}],"version-history":[{"count":0,"href":"https:\/\/securityblog.denison.edu\/index.php\/wp-json\/wp\/v2\/posts\/179\/revisions"}],"wp:attachment":[{"href":"https:\/\/securityblog.denison.edu\/index.php\/wp-json\/wp\/v2\/media?parent=179"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/securityblog.denison.edu\/index.php\/wp-json\/wp\/v2\/categories?post=179"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/securityblog.denison.edu\/index.php\/wp-json\/wp\/v2\/tags?post=179"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}