Evilginx2 is an open-source adversary-in-the-middle phishing framework that operates as a reverse proxy between a victim and a legitimate web service to capture authentication material in real time. It is widely used to bypass multifactor authentication by intercepting usernames, passwords, one-time codes, and authenticated web session cookies during live login flows, enabling subsequent account takeover through replay of valid sessions.
The framework is associated with AiTM phishing operations rather than traditional malware deployment on endpoints. It can relay traffic between victims and legitimate sites and supports routing through SOCKS5 and HTTP(S) proxies, which helps operators manage phishing infrastructure and obscure traffic paths. Its tradecraft is particularly effective against services that rely on bearer-style web sessions, because stolen session tokens can remain usable even after password changes unless sessions are explicitly revoked.
Evilginx2 has been observed in credential theft campaigns and business email compromise activity, including operations attributed to ransomware affiliates and Russian espionage actors. Reported users include ALPHV/BlackCat affiliates for theft of MFA credentials, login credentials, and session cookies, and it has also been associated with Russian state-linked phishing activity tracked under names including COLDRIVER and Star Blizzard. It is commonly discussed alongside other reverse-proxy phishing kits such as Modlishka and EvilProxy.
The framework primarily targets web-based authentication workflows used by cloud and enterprise services, especially identity providers and email platforms. Its role in intrusions is typically initial access and session hijacking through phishing rather than persistence or destructive action on the host itself.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
7 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
"...with the help of an Adversary-in-the-Middle (AitM) toolkit like EvilGinx2, could quickly provision most of the necessary infrastructure to perpetrate an attack..."
"...with the help of an Adversary-in-the-Middle (AitM) toolkit like EvilGinx2, could quickly provision most of the necessary infrastructure to perpetrate an attack..."
"...with the help of an Adversary-in-the-Middle (AitM) toolkit like EvilGinx2, could quickly provision most of the necessary infrastructure to perpetrate an attack..."
"...with the help of an Adversary-in-the-Middle (AitM) toolkit like EvilGinx2, could quickly provision most of the necessary infrastructure to perpetrate an attack..."
"...with the help of an Adversary-in-the-Middle (AitM) toolkit like EvilGinx2, could quickly provision most of the necessary infrastructure to perpetrate an attack..."
14 distinct techniques documented for this family, organized by ATT&CK tactic.
...steal session cookies, then logged into the console from attacker machine while the session from victim machine was also connected.
Victims are lead to credential harvesting sites run by IRON FRONTIER, who likely use the stolen credentials to gain access to sensitive email communications and documents.
Sophos believes the fake ScreenConnect site proxied the inputs back to the legitimate ScreenConnect site to verify the credentials and capture the time-based one-time password (TOTP) sent from ScreenConnect to the administrator by email.
The content repeatedly describes threat actors, malware, and campaigns using HTTP, HTTPS, HTTP GET/POST, cookies in headers, WebSockets/WSS, and web APIs for command and control or related communications.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named as a tool/framework in the IOC/TTP summary, but no specific operational detail is provided in the content beyond mention.
Adversary-in-the-middle phishing kit described as intercepting one-time codes and session tokens in real time.
Adversary-in-the-middle phishing framework referenced as a comparison point for handling session-based phishing flows.
Reverse-proxy framework for AiTM attacks that transparently relays authentication, captures session tokens in real time, and enables immediate session replay after MFA is completed by the victim.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.