EvilProxy is a phishing-as-a-service adversary-in-the-middle phishing kit used to steal credentials and hijack authenticated web sessions, particularly against cloud identity and enterprise login portals. Emerging in 2022, it is marketed in underground communities as a subscription service and has been associated with the alternate name Moloch. The platform lowers the barrier to conducting real-time reverse-proxy phishing by providing operators with deployment tooling, campaign customization, and management interfaces.
EvilProxy operates by relaying traffic between victims and legitimate authentication services, allowing attackers to capture usernames, passwords, one-time codes, and especially session cookies or tokens that can be reused to bypass multifactor authentication. Reported implementations also include cookie-injection and other session-hijacking techniques. The kit has been used in campaigns impersonating major technology and business platforms, with repeated reporting around Microsoft 365, Microsoft Entra ID, Google services, GitHub, npm, and PyPI, creating particular risk for enterprise account takeover and software supply-chain compromise.
Observed delivery commonly involves phishing links embedded in email lures, fake document-sharing workflows, OAuth redirect abuse, and cloud-hosted phishing pages. Campaigns using EvilProxy have employed trusted platforms and aged or compromised websites to improve credibility, as well as CAPTCHA gates and anti-bot filtering to hinder analysis. The service has also been described as supporting operator-side customization and automated campaign setup through a graphical interface.
EvilProxy has been used by multiple financially motivated actors and phishing operators rather than a single exclusive group. Public reporting links it to campaigns involving Storm-1811 and to activity associated with Black Basta operations, while broader enterprise phishing activity has shown EvilProxy used alongside other AiTM kits such as Evilginx, Tycoon 2FA, Sneaky2FA, FlowerStorm, and Kali365. It has been observed targeting enterprises, government and public-sector organizations, universities, multinational institutions, Fortune 500 companies, and software developers.
The malware’s significance lies in its effectiveness against organizations that rely on MFA but do not enforce phishing-resistant authentication end to end. By capturing valid authenticated sessions in real time, EvilProxy enables account takeover without needing to defeat the underlying identity provider directly.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Storm-1811 also provides the target user with malicious links that redirect the user to an EvilProxy phishing site to input credentials. EvilProxy is an adversary-in-the-middle (AiTM) phishing kit used to capture passwords, hijack a user’s sign-in session, and skip the authentication process.
18 distinct techniques documented for this family, organized by ATT&CK tactic.
One clear trend is the abuse of cloud infrastructure. Phishing incidents on Cloudflare Pages domains nearly tripled from 460 in 2023 to more than 1,370 in 2024... Other widely trusted services, including Azure Blob Storage, Google Firebase, AWS CloudFront, and Amazon S3, have also hosted phishing assets.
Resecurity has acquired videos released by EvilProxy actors demonstrating how it can be used to steal the victim’s session and successfully go through Microsoft 2FA and Google e-mail services to gain access to the target account.
MITRE ATT&CK Mapping Technique ID Technique Applies To T1078.004 Valid Accounts: Cloud Accounts All three (post-compromise)
Besides PyPi, the functionality of EvilProxy also supports GitHub and npmjs ... enabling supply chain attacks via advanced phishing campaigns.
Resecurity has acquired videos released by EvilProxy actors demonstrating how it can be used to steal the victim’s session and successfully go through Microsoft 2FA and Google e-mail services to gain access to the target account.
The bad actors register similar (by spelling) domains with the intention of masking them under legitimate online-services.
Resecurity has acquired videos released by EvilProxy actors demonstrating how it can be used to steal the victim’s session and successfully go through Microsoft 2FA and Google e-mail services to gain access to the target account.
MITRE ATT&CK Mapping Technique ID Technique Applies To T1078.004 Valid Accounts: Cloud Accounts All three (post-compromise)
By inserting themselves directly into legitimate sign-in workflows, attackers can capture session cookies, authentication tokens, and multi-factor authentication (MFA)-protected access in real time...
This allows the operator to capture passwords, MFA responses, and authenticated session cookies, potentially enabling account takeover even after the victim completes a conventional MFA challenge.
This way they can harvest valid session cookies and bypass the need to authenticate with usernames, passwords and/or 2FA tokens.
Advanced quishing combined with AitM proxies defeats standard MFA by stealing session tokens after successful authentication.
they aggregate data about known VPN services, Proxies, TOR exit nodes and other hosts which may be used for IP reputation analysis (of potential victims).
By inserting themselves directly into legitimate sign-in workflows, attackers can capture session cookies, authentication tokens, and multi-factor authentication (MFA)-protected access in real time...
34 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
Other indicator types observed in public reporting.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An adversary-in-the-middle phishing kit used in AI-branded credential theft lures.
Adversary-in-the-middle phishing kit described as intercepting one-time codes and session tokens in real time.
A phishing-as-a-service adversary-in-the-middle kit that uses reverse proxying to steal credentials and authenticated sessions across a variety of services and sectors. The content describes it as broadly used and enabling low-skill actors.
Mentioned only as another AiTM phishing kit sharing hosting infrastructure with Kratos.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.