Evilginx is an open-source adversary-in-the-middle phishing framework built to proxy legitimate authentication flows in real time and capture credentials, multifactor authentication artifacts, and authenticated web session cookies. It is widely used to bypass conventional MFA by relaying a victim’s login to the real service, then stealing the resulting session material so the attacker can replay an authenticated session without needing to re-enter the victim’s second factor. The framework is commonly deployed against cloud identity and webmail platforms, especially Microsoft 365 and other single sign-on environments, and has also been used against cryptocurrency and consumer web services.
Evilginx is not a traditional endpoint malware family; it is a phishing framework and reverse-proxy attack platform. Its core function is credential theft and session hijacking rather than payload execution on victim hosts. Operators typically customize it with target-specific phishlets, lure pages, anti-bot filtering, cloaking, and infrastructure obfuscation. Documented variants and forks have added features such as URL rewriting, JavaScript-based victim prefill, modified cookie handling, web dashboards, and integrations for broader phishing operations.
The framework has been used by a wide range of actors, from commodity cybercriminals and phishing-as-a-service operators to ransomware affiliates and state-linked espionage groups. Reported users include Scattered Spider and Star Blizzard, and Evilginx-based infrastructure has appeared in campaigns targeting enterprises, managed service providers, universities, government-related targets, defense, professional services, and other corporate environments. Delivery is most often through phishing and spearphishing links, including lookalike login portals, cloud-hosted lure documents, shortened links, and other social-engineering pretexts.
Because Evilginx captures authenticated session cookies in addition to usernames and passwords, it enables account takeover even when standard MFA is enabled. In observed operations, attackers have used it to access victim email and cloud accounts, steal data, maintain access through stolen sessions or refreshed tokens, and support follow-on intrusion activity. Its widespread adoption reflects the low barrier to entry for AiTM phishing and the growing effectiveness of session theft against organizations that rely on non-phishing-resistant authentication methods.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
9 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Evilginx forks : red-queen (mail-argenta), black-queen/master (saroula01), tous deux utilisés par codemado
Evilginx forks : red-queen (mail-argenta), black-queen/master (saroula01), tous deux utilisés par codemado
Evilginx forks : red-queen (mail-argenta), black-queen/master (saroula01), tous deux utilisés par codemado
Evilginx Phishing infrastructure assessed with high confidence as very likely linked to Scattered Spider, this assessment is done by infrastructure similarities on previously attributed domains by Silent Push.
Those attempts leveraged phishing sites built with the evilginx open-source adversary-in-the-middle attack framework to collect credentials and session cookies and bypass multi-factor authentication (MFA).
The setup used the open-source Evilginx kit to intercept usernames, passwords, and session cookies as users attempted to "register" for the bogus summit.
19 distinct techniques documented for this family, organized by ATT&CK tactic.
Credential harvesting panel – A modified phishing framework for username and password collection, possibly derived from Evilginx...
MitM для развития атаки: DNS spoofing, перехват cookies, инъекция вредоносного кода в HTTP-ответы, перехват MFA-токенов (T1111) через Evilginx-прокси.
saroula01 est l’auteur du fork black-queen d’Evilginx, spécialisé dans l’abus du Device Code Flow OAuth ... 97 tokens OAuth actifs avec autoRefresh: true
mail-argenta / bot_7183501714 : 15 victimes confirmées, sessions O365, Google, Kraken, Bybit, iCloud, eHarmony ; cookie ESTSAUTHPERSISTENT valide jusqu’en juin 2027
All of them abused forks of the Evilginx framework to bypass multi-factor authentication on Microsoft 365 accounts.
Credential harvesting panel – A modified phishing framework for username and password collection, possibly derived from Evilginx...
182 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
Other indicator types observed in public reporting.
23 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Adversary-in-the-middle phishing framework used to capture credentials, session cookies, and OAuth/device-code authentication artifacts in the operators' phishing infrastructure.
Evilginx is an adversary-in-the-middle framework built on nginx that proxies real login pages through attacker-controlled infrastructure to capture credentials, MFA approvals, and authenticated session cookies, enabling account takeover by replaying stolen sessions.
A phishing framework referenced as a possible basis for the credential harvesting panel used in the operation for collecting usernames and passwords.
Adversary-in-the-middle phishing framework used to proxy Microsoft 365 and other login flows, capture session cookies and OAuth tokens, and bypass MFA. The article discusses multiple customized forks including red-queen and black-queen.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.