Evilginx2 is an open-source adversary-in-the-middle phishing framework that operates as a reverse proxy between a victim and a legitimate authentication service. Its phishlets can relay authentication traffic in real time, capture submitted credentials, intercept MFA material, and obtain authenticated web-session cookies. Stolen cookies can be replayed to access cloud services without repeating interactive authentication, enabling account takeover and session hijacking. Evilginx2 can route relayed traffic through SOCKS5 or HTTP(S) proxies. It has been used against Microsoft 365 authentication flows and has been reported in campaigns and affiliate operations including ALPHV/BlackCat activity. Organizations in a range of sectors are exposed where attackers can socially engineer users to authenticate through attacker-controlled proxy infrastructure. Phishing-resistant authentication methods such as FIDO2/WebAuthn provide stronger resistance to this technique than phishable factors, although endpoint compromise remains a separate risk.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
8 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
BigBear 2.0 is described as a rebranded Evilginx2-based phishing-as-a-service framework. Evilginx2 phishlets operate as adversary-in-the-middle proxies that capture credential submissions and session cookies during Microsoft 365 authentication.
"...with the help of an Adversary-in-the-Middle (AitM) toolkit like EvilGinx2, could quickly provision most of the necessary infrastructure to perpetrate an attack..."
"...with the help of an Adversary-in-the-Middle (AitM) toolkit like EvilGinx2, could quickly provision most of the necessary infrastructure to perpetrate an attack..."
"...with the help of an Adversary-in-the-Middle (AitM) toolkit like EvilGinx2, could quickly provision most of the necessary infrastructure to perpetrate an attack..."
"...with the help of an Adversary-in-the-Middle (AitM) toolkit like EvilGinx2, could quickly provision most of the necessary infrastructure to perpetrate an attack..."
"...with the help of an Adversary-in-the-Middle (AitM) toolkit like EvilGinx2, could quickly provision most of the necessary infrastructure to perpetrate an attack..."
19 distinct techniques documented for this family, organized by ATT&CK tactic.
In one of the runs we’ve observed, the attacker sent emails with an HTML file attachment to multiple recipients in different organizations.
Victims are lead to credential harvesting sites run by IRON FRONTIER, who likely use the stolen credentials to gain access to sensitive email communications and documents.
“Victim enters password → proxy captures plaintext AND forwards to Microsoft.”
Sophos believes the fake ScreenConnect site proxied the inputs back to the legitimate ScreenConnect site to verify the credentials and capture the time-based one-time password (TOTP) sent from ScreenConnect to the administrator by email.
“Victim completes MFA ... session token issued by Microsoft is captured by the proxy.”
It uses an adversary-in-the-middle (AiTM) attack technique capable of bypassing multi-factor authentication.
Victims are lead to credential harvesting sites run by IRON FRONTIER, who likely use the stolen credentials to gain access to sensitive email communications and documents.
“Victim enters password → proxy captures plaintext AND forwards to Microsoft.”
The content repeatedly describes threat actors, malware, and campaigns using HTTP, HTTPS, HTTP GET/POST, cookies in headers, WebSockets/WSS, and web APIs for command and control or related communications.
78 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An adversary-in-the-middle reverse-proxy phishing framework that relays authentication traffic between a victim and the legitimate service, allowing operators to capture credentials and post-MFA session cookies for account/session hijacking. In this campaign, it underpins BigBear 2.0's Microsoft 365 targeting and cookie-capture workflow.
Named as a tool/framework in the IOC/TTP summary, but no specific operational detail is provided in the content beyond mention.
Adversary-in-the-middle phishing kit described as intercepting one-time codes and session tokens in real time.
A phishing framework used to mimic legitimate websites and support adversary-in-the-middle phishing activity by leveraging phishlets for services such as Amazon, Facebook, GitHub, Office 365, Outlook, AWS, and Google.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.