EvilProxy is a phishing-as-a-service adversary-in-the-middle phishing kit used to steal credentials and authenticated web sessions in real time, enabling attackers to bypass multi-factor authentication by capturing session cookies and other authentication artifacts after successful sign-in. Emerging in the early 2020s and becoming prominent by 2022–2023, it lowered the barrier to conducting reverse-proxy phishing by providing operators with a graphical interface and campaign automation features.
The kit is commonly used against enterprise identity workflows, especially Microsoft 365 and other cloud authentication portals, where it proxies victim interactions with legitimate login services, relays passwords and one-time codes, and returns valid authenticated sessions to the attacker. This makes EvilProxy particularly effective for session hijacking and account takeover even when MFA is enabled. It has also been observed in phishing chains that abuse OAuth redirection behavior to route victims from trusted identity-provider pages to attacker-controlled AiTM infrastructure.
EvilProxy is associated with phishing campaigns targeting enterprises, government and public-sector organizations, universities, multinational institutions, and sectors such as finance, healthcare, education, and energy. Delivery commonly relies on phishing links, spearphishing lures, cloud-hosted landing pages, fake document portals, CAPTCHA-gated login flows, and other attacker-in-the-middle workflows designed to evade automated analysis and increase victim trust. Operators have used trusted hosting platforms and aged or compromised websites to reduce detection.
The framework has been used by a range of financially motivated actors and phishing operators, including activity linked to Storm-1811 and abuse by Black Basta affiliates as part of broader intrusion chains. It is also part of the wider ecosystem of AiTM kits alongside Evilginx, Tycoon 2FA, Sneaky2FA, FlowerStorm, and similar platforms. EvilProxy’s role in modern identity attacks reflects the broader shift from simple credential harvesting to real-time interception of credentials and session tokens for immediate post-authentication compromise.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Storm-1811 also provides the target user with malicious links that redirect the user to an EvilProxy phishing site to input credentials. EvilProxy is an adversary-in-the-middle (AiTM) phishing kit used to capture passwords, hijack a user’s sign-in session, and skip the authentication process.
11 distinct techniques documented for this family, organized by ATT&CK tactic.
One clear trend is the abuse of cloud infrastructure. Phishing incidents on Cloudflare Pages domains nearly tripled from 460 in 2023 to more than 1,370 in 2024... Other widely trusted services, including Azure Blob Storage, Google Firebase, AWS CloudFront, and Amazon S3, have also hosted phishing assets.
The attacker then reuses these cookies to open authenticated sessions, bypassing MFA and gaining full visibility into Outlook mailboxes, SharePoint files, and broader Microsoft 365 resources.
This campaign begins with emails sent from compromised organizational accounts, a tactic used to lend credibility to the lures. The emails themselves are themed around professional workflows: requests for information (RFIs), formal bid invitations, and shared project documentation.
By inserting themselves directly into legitimate sign-in workflows, attackers can capture session cookies, authentication tokens, and multi-factor authentication (MFA)-protected access in real time...
"At this stage, the attack resembles a conventional phishing attempt... sent to phishing frameworks such as EvilProxy... designed to intercept credentials and session cookies."
Since attackers are harvesting session cookies and tokens, they inherit fully authenticated identities inside Microsoft 365 rather than simply stealing passwords.
Advanced quishing combined with AitM proxies defeats standard MFA by stealing session tokens after successful authentication.
By inserting themselves directly into legitimate sign-in workflows, attackers can capture session cookies, authentication tokens, and multi-factor authentication (MFA)-protected access in real time...
"At this stage, the attack resembles a conventional phishing attempt... sent to phishing frameworks such as EvilProxy... designed to intercept credentials and session cookies."
10 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
17 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Adversary-in-the-middle phishing kit described as intercepting one-time codes and session tokens in real time.
A phishing-as-a-service adversary-in-the-middle kit that uses reverse proxying to steal credentials and authenticated sessions across a variety of services and sectors. The content describes it as broadly used and enabling low-skill actors.
Mentioned only as another AiTM phishing kit sharing hosting infrastructure with Kratos.
A phishing platform/kit referenced as one of the established services seeing increased campaign activity following the Tycoon 2FA disruption.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.