Evilginx is an open-source adversary-in-the-middle (AiTM) phishing and adversary-emulation framework used for authorized security testing and abused for account compromise. It operates as a reverse proxy between a victim’s browser and a legitimate authentication service, relaying the genuine sign-in process while intercepting usernames, passwords, authentication artifacts, and authenticated session cookies. Unlike endpoint information-stealing malware, it captures authentication data through attacker-controlled web infrastructure.
Operators direct victims to impersonated sign-in sites using phishing or spearphishing links, lookalike domains, and social-engineering lures such as shared documents, event invitations, or account-security notices. Evilginx can relay supported multifactor-authentication interactions while capturing the resulting authenticated session. Attackers can then replay stolen session cookies to access accounts without repeating the victim’s password and MFA steps, subject to session validity and service-side protections. This circumvents some MFA protections through session theft rather than breaking the underlying authentication mechanism.
Evilginx has been used against Microsoft 365, Microsoft Entra ID, and other web authentication services, including university single-sign-on portals and ScreenConnect administration portals. Documented users include Star Blizzard, LAUNDRY BEAR, Scattered Spider, and the Qilin ransomware affiliate STAC4365. Its use spans espionage-oriented targeting of academia, government, defense, and think tanks, as well as financially motivated intrusions into enterprises and managed service providers. Customized forks extend its phishing workflows and session-capture functionality. Subsequent email theft, remote-management deployment, extortion, and ransomware activity are actions performed by operators or additional tooling, not inherent Evilginx capabilities.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
10 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The group's preferred initial access vectors continue to involve highly sophisticated social engineering, often combined with phishing campaigns utilizing typosquatted domains ... and tools like Evilginx to intercept credentials and session cookies.
Frameless BitB avoids iframes and supports Evilginx-based proxying of Microsoft login pages.
The group still runs password phishing with Evilginx, a tool that can also steal session cookies to get around two-factor authentication.
Once a user entered their Microsoft credentials into this malicious site, LAUNDRY BEAR’s modified version of the open source adversary emulation toolkit, Evilginx, intercepted the user’s credentials.
Evilginx forks : red-queen (mail-argenta), black-queen/master (saroula01), tous deux utilisés par codemado
Evilginx forks : red-queen (mail-argenta), black-queen/master (saroula01), tous deux utilisés par codemado
17 distinct techniques documented for this family, organized by ATT&CK tactic.
The victim is redirected to an attacker-in-the-middle (AitM) credential phishing page that steals the victim's cloud account login information.
A custom module... automatically accepted “Keep me signed in” and submitted validated one-time codes.
[The kit includes] an Evilginx phishlet to intercept usernames, passwords, and session cookies for Microsoft 365.
The phishing chain ... redirects the victim to an attacker-in-the-middle (AitM) credential phishing page. It is built on open source Frameless BitB ... [and] an Evilginx phishlet to intercept usernames, passwords, and session cookies for Microsoft 365.
The attack combined adversary-in-the-middle, or AitM, phishing with a modified Frameless BitB toolkit... the proxy relayed the genuine Microsoft sign-in process while adding malicious scripts.
The victim is redirected to an attacker-in-the-middle (AitM) credential phishing page that steals the victim's cloud account login information.
Frameless BitB ... contains a Browser-in-the-Browser (BitB) overlay [and] an Evilginx phishlet to intercept usernames, passwords, and session cookies for Microsoft 365.
229 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
Other indicator types observed in public reporting.
31 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A reverse-proxy phishing framework used here to relay legitimate Microsoft sign-in activity and facilitate theft of authenticated session cookies.
A phishing framework used to capture passwords and session cookies, potentially bypassing two-factor authentication protections.
Open-source adversary-in-the-middle phishing framework used to bypass MFA by capturing credentials and session tokens via realistic fake sign-in pages.
An adversary-in-the-middle phishing framework used to proxy legitimate authentication flows and capture credentials, session cookies, authentication tokens, and MFA-protected sessions in real time.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.