Evilginx is an open-source adversary-in-the-middle reverse-proxy framework originally developed for authorized security testing and phishing-awareness exercises. It is widely recognized in defensive and threat-intelligence reporting because attackers adapt and modify it to proxy legitimate authentication flows, capture submitted credentials, and steal authenticated session cookies or tokens that can be replayed to bypass multi-factor authentication protections based on session establishment rather than phishing-resistant authenticators. Evilginx is not itself a phishing-as-a-service operator or a distinct intrusion set; it is a toolset that can be used by multiple unrelated threat actors and criminal operations. Operationally, Evilginx is associated with credential theft and session hijacking through reverse-proxy phishing. It reproduces legitimate sign-in experiences by relaying traffic between victims and real services, allowing attackers to intercept authentication material after successful login. Reporting also notes that modified credential-harvesting panels in broader criminal ecosystems may be derived from Evilginx, underscoring its influence on later phishing frameworks and commercialized kits. Evilginx has been linked in observed phishing patterns to theft of session tokens intended to defeat conventional MFA deployments. Because Evilginx is a framework rather than a single actor, there is no high-confidence basis to assign it a specific country of origin, stable victim geography, or a single motivation in threat-actor terms. Its primary relevance is as an enabling platform for phishing, credential interception, and session-token theft used across diverse campaigns.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Open-source reverse-proxy framework frequently repurposed by attackers for phishing that intercepts credentials, tokens, and session cookies to bypass conventional MFA protections.
Evilginx is associated with adversary-in-the-middle (AiTM) phishing campaigns that steal session tokens to bypass multi-factor authentication, often targeting organizations in manufacturing, industrial automation, and healthcare.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.