Evilginx is an open-source adversary-in-the-middle phishing framework built on nginx and widely used to proxy legitimate authentication flows in real time. It is commonly deployed against cloud identity providers and webmail services, especially Microsoft 365 and other single sign-on portals, to capture usernames, passwords, multi-factor authentication artifacts, and authenticated session cookies. By relaying the victim’s interaction with the real service through an attacker-controlled reverse proxy, Evilginx enables session hijacking and can allow operators to bypass conventional MFA protections that do not provide phishing resistance.
Evilginx is used extensively in spearphishing and broader phishing operations by both state-linked and financially motivated actors. Reported users include Russian espionage actors such as Star Blizzard and LAUNDRY BEAR, as well as criminal ecosystems and phishing operators associated with Scattered Spider-linked infrastructure and other AiTM campaigns. It has also appeared in modified forks and customized variants that add anti-detection features, target-specific lure themes, cookie handling changes, dashboard functions, and support for additional authentication workflows.
Operationally, Evilginx is typically paired with cloned login pages, lookalike domains, CAPTCHA or anti-bot stages, and social-engineering lures such as conference invitations, procurement workflows, document-sharing prompts, or security alerts. Once a victim authenticates through the proxied page, operators can harvest credentials and replay stolen session material to access accounts, particularly email and cloud services. In observed intrusions, this access has supported espionage, follow-on phishing, mailbox theft, and broader post-compromise activity.
Evilginx is best characterized as a phishing framework and credential-and-session interception utility rather than a traditional endpoint malware family. Its core role is enabling credential theft and session hijacking through AiTM phishing infrastructure targeting web-based authentication flows on Windows-centric enterprise environments and cloud identity ecosystems.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
9 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Star Blizzard uses the open-source framework EvilGinx in their spear-phishing activity, which allows them to harvest credentials and session cookies to successfully bypass the use of two-factor authentication.
Once a user entered their Microsoft credentials into this malicious site, LAUNDRY BEAR’s modified version of the open source adversary emulation toolkit, Evilginx, intercepted the user’s credentials.
Evilginx forks : red-queen (mail-argenta), black-queen/master (saroula01), tous deux utilisés par codemado
Evilginx forks : red-queen (mail-argenta), black-queen/master (saroula01), tous deux utilisés par codemado
Evilginx forks : red-queen (mail-argenta), black-queen/master (saroula01), tous deux utilisés par codemado
Evilginx Phishing infrastructure assessed with high confidence as very likely linked to Scattered Spider, this assessment is done by infrastructure similarities on previously attributed domains by Silent Push.
19 distinct techniques documented for this family, organized by ATT&CK tactic.
But today, attackers can pair AI-generated phishing with ‘MFA bypass kits,’ such as open-source Evilginx ... and the W3LL panel ... to deceive employees into handing over that ‘extra step’ of security.
For example, if a threat actor creates a phishing domain, goo-ink[.]online, emulating a Google domain, they can then append a URL structure, like adfs[.]llnl[.]gov ... in order to dupe a Lawrence Livermore National Lab employee into believing the link is legitimate.
By inserting themselves directly into legitimate sign-in workflows, attackers can capture session cookies, authentication tokens, and multi-factor authentication (MFA)-protected access in real time...
The phishing kits are designed to proxy “live Microsoft 365 authentication sessions to capture session cookies and OAuth tokens in real time, bypassing MFA entirely.”
Star Blizzard uses the open-source framework EvilGinx in their spear-phishing activity, which allows them to harvest credentials and session cookies.
Source: https://breakdev.org/evilginx-1-0-update-up-your-game-in-2fa-phishing/
By inserting themselves directly into legitimate sign-in workflows, attackers can capture session cookies, authentication tokens, and multi-factor authentication (MFA)-protected access in real time...
Capturing authenticated session material can provide account access even after a victim completes a conventional MFA challenge.
From the main website, you’ll see a table where you can hunt for potential Command and Control (C2) servers listed in the feed.
227 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
Other indicator types observed in public reporting.
28 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Open-source adversary-in-the-middle phishing framework used to bypass MFA by capturing credentials and session tokens via realistic fake sign-in pages.
An adversary-in-the-middle phishing framework used to proxy legitimate authentication flows and capture credentials, session cookies, authentication tokens, and MFA-protected sessions in real time.
Adversary-in-the-middle phishing framework used to capture credentials, session cookies, and OAuth/device-code authentication artifacts in the operators' phishing infrastructure.
Evilginx is an adversary-in-the-middle framework built on nginx that proxies real login pages through attacker-controlled infrastructure to capture credentials, MFA approvals, and authenticated session cookies, enabling account takeover by replaying stolen sessions.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.