Evilginx2 is an open-source adversary-in-the-middle phishing framework used to steal login credentials and authenticated session cookies. It operates as a reverse proxy between a victim’s browser and a legitimate website, relaying authentication traffic through attacker-controlled infrastructure. Service-specific configurations called phishlets support impersonation of authentication flows, including Microsoft 365 and other online services. Evilginx2 also supports routing traffic through SOCKS5 and HTTP(S) proxies.
By intercepting credentials, one-time authentication codes, and session cookies during authentication, Evilginx2 enables account takeover even when victims complete susceptible forms of multifactor authentication. Captured session cookies can be replayed to access services without repeating authentication. This does not constitute a general bypass of phishing-resistant FIDO2/WebAuthn authentication, whose cryptographic assertions are bound to the legitimate origin.
Evilginx2 has been used by ALPHV/BlackCat affiliates and is associated with Qilin campaigns and the Russian espionage group Star Blizzard, also known as COLDRIVER and SEABORGIUM. Its credential and session theft capabilities support initial access to enterprise cloud accounts. Evilginx2 also serves as the foundation for derivative phishing-as-a-service platforms such as BigBear 2.0; capabilities added by those platforms are distinct from the underlying framework.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
8 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
BigBear 2.0 is described as a rebranded Evilginx2-based phishing-as-a-service framework. Evilginx2 phishlets operate as adversary-in-the-middle proxies that capture credential submissions and session cookies during Microsoft 365 authentication.
"...with the help of an Adversary-in-the-Middle (AitM) toolkit like EvilGinx2, could quickly provision most of the necessary infrastructure to perpetrate an attack..."
"...with the help of an Adversary-in-the-Middle (AitM) toolkit like EvilGinx2, could quickly provision most of the necessary infrastructure to perpetrate an attack..."
"...with the help of an Adversary-in-the-Middle (AitM) toolkit like EvilGinx2, could quickly provision most of the necessary infrastructure to perpetrate an attack..."
"...with the help of an Adversary-in-the-Middle (AitM) toolkit like EvilGinx2, could quickly provision most of the necessary infrastructure to perpetrate an attack..."
"...with the help of an Adversary-in-the-Middle (AitM) toolkit like EvilGinx2, could quickly provision most of the necessary infrastructure to perpetrate an attack..."
16 distinct techniques documented for this family, organized by ATT&CK tactic.
“The operation exfiltrated 5,137 credential records, including ... 1,032 plaintext passwords...”
“The operation exfiltrated ... 4,148 session cookies” and used “automated cookie replay.”
“The operation exfiltrated 5,137 credential records, including ... 1,032 plaintext passwords...”
108 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An adversary-in-the-middle reverse-proxy phishing framework that relays authentication traffic between a victim and the legitimate service, allowing operators to capture credentials and post-MFA session cookies for account/session hijacking. In this campaign, it underpins BigBear 2.0's Microsoft 365 targeting and cookie-capture workflow.
Named as a tool/framework in the IOC/TTP summary, but no specific operational detail is provided in the content beyond mention.
Adversary-in-the-middle phishing kit described as intercepting one-time codes and session tokens in real time.
A phishing framework used to mimic legitimate websites and support adversary-in-the-middle phishing activity by leveraging phishlets for services such as Amazon, Facebook, GitHub, Office 365, Outlook, AWS, and Google.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.