EvilProxy is a commercial adversary-in-the-middle phishing-as-a-service platform active since at least May 2022. It is marketed in criminal forums as a turnkey reverse-proxy phishing service designed to target major cloud identity providers and online services, including Microsoft 365, Google Workspace, Dropbox, and GitHub. The platform enables operators and customers to relay legitimate authentication traffic in real time, capture credentials and authenticated session artifacts, and bypass the practical protections of standard multi-factor authentication through session hijacking rather than cryptographic defeat of MFA. EvilProxy has been associated with large-scale phishing campaigns against organizations globally, including campaigns targeting C-level executives and managers at more than 100 organizations. Activity attributed by Okta to threat actor cluster O-TA-041 has been linked to EvilProxy campaigns active since at least March 2025. Microsoft has also referenced a developing cluster associated with EvilProxy as Storm-0835. Operationally, EvilProxy is characterized by reverse-proxy AiTM phishing workflows that sit between the victim and the legitimate service, forwarding authentication exchanges and intercepting session cookies after successful sign-in. This gives attackers authenticated access to victim accounts without needing to break MFA directly. Reporting also indicates EvilProxy operators have incorporated device-code phishing into their operations, reflecting adaptation beyond classic credential relay toward broader token- and session-focused account takeover techniques. EvilProxy is best understood as part of the broader financially motivated phishing-service ecosystem alongside platforms such as Tycoon 2FA, Mamba 2FA, and Sneaky 2FA. It provides initial access and post-authentication account takeover capability that can support downstream fraud, business email compromise, and other criminal intrusion activity.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
1 distinct technique observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Commercial reverse-proxy AiTM phishing platform used to hijack Microsoft 365 and other cloud identity sessions by proxying real login pages, relaying MFA, and harvesting session cookies in transit.
Operating a commercial reverse-proxy phishing-as-a-service platform that proxies real login pages in real time, relays credentials and MFA challenges, and steals authenticated session cookies for account hijacking at scale.
Using device code phishing as part of standard operations to compromise Microsoft 365 accounts through the OAuth device authorization flow.
An established phishing platform that increased campaign activity after Tycoon 2FA was disrupted.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.