Evilginx2 is an open-source adversary-in-the-middle phishing framework that operates as a reverse proxy between a victim and a legitimate web service to capture authentication material in real time. It is widely used to bypass multifactor authentication by intercepting usernames, passwords, one-time codes, and authenticated session cookies during live login flows, enabling subsequent session hijacking and account takeover without needing to defeat the protected service directly.
The framework is commonly associated with phishing operations targeting cloud identity providers, enterprise email, social media, and other high-value web applications. Its infrastructure typically impersonates legitimate brands and relays traffic to the real service while harvesting credentials and tokens from the proxied session. Reported capabilities include routing traffic through SOCKS5 and HTTP(S) proxies to support flexible operator infrastructure and concealment.
Evilginx2 has been referenced in operations conducted by multiple threat actors, including ransomware affiliates and Russian espionage operators. ALPHV/BlackCat affiliates have used it to obtain MFA credentials, login credentials, and session cookies, while it has also been associated with targeted credential-harvesting campaigns attributed to IRON FRONTIER and with broader business email compromise and cloud account intrusion activity. It is frequently discussed alongside other AiTM frameworks such as Modlishka and EvilProxy.
Because Evilginx2 is primarily a phishing and session-capture framework rather than a conventional endpoint payload, its core behaviors center on credential theft and theft of authenticated web sessions. It is especially effective against organizations that rely on SMS, TOTP, or push-based MFA without phishing-resistant authentication controls. The framework targets web-based authentication workflows rather than a specific operating system, but it is used against services commonly accessed from Windows and other desktop environments.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
7 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
"...with the help of an Adversary-in-the-Middle (AitM) toolkit like EvilGinx2, could quickly provision most of the necessary infrastructure to perpetrate an attack..."
"...with the help of an Adversary-in-the-Middle (AitM) toolkit like EvilGinx2, could quickly provision most of the necessary infrastructure to perpetrate an attack..."
"...with the help of an Adversary-in-the-Middle (AitM) toolkit like EvilGinx2, could quickly provision most of the necessary infrastructure to perpetrate an attack..."
"...with the help of an Adversary-in-the-Middle (AitM) toolkit like EvilGinx2, could quickly provision most of the necessary infrastructure to perpetrate an attack..."
"...with the help of an Adversary-in-the-Middle (AitM) toolkit like EvilGinx2, could quickly provision most of the necessary infrastructure to perpetrate an attack..."
18 distinct techniques documented for this family, organized by ATT&CK tactic.
...steal session cookies, then logged into the console from attacker machine while the session from victim machine was also connected.
In one of the runs we’ve observed, the attacker sent emails with an HTML file attachment to multiple recipients in different organizations.
Victims are lead to credential harvesting sites run by IRON FRONTIER, who likely use the stolen credentials to gain access to sensitive email communications and documents.
Sophos believes the fake ScreenConnect site proxied the inputs back to the legitimate ScreenConnect site to verify the credentials and capture the time-based one-time password (TOTP) sent from ScreenConnect to the administrator by email.
platform admins debuted a new feature advertising its “own methodology” to bypass 2FA via the stealing of login session cookies.
The content repeatedly describes threat actors, malware, and campaigns using HTTP, HTTPS, HTTP GET/POST, cookies in headers, WebSockets/WSS, and web APIs for command and control or related communications.
55 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named as a tool/framework in the IOC/TTP summary, but no specific operational detail is provided in the content beyond mention.
Adversary-in-the-middle phishing kit described as intercepting one-time codes and session tokens in real time.
A phishing framework used to mimic legitimate websites and support adversary-in-the-middle phishing activity by leveraging phishlets for services such as Amazon, Facebook, GitHub, Office 365, Outlook, AWS, and Google.
Adversary-in-the-middle phishing framework referenced as a comparison point for handling session-based phishing flows.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.