Evilginx is an open-source adversary-in-the-middle (AiTM) phishing framework, built on nginx, that operates as a reverse proxy between a victim and a legitimate web service. It presents a live proxied authentication flow, allowing an operator to capture credentials, MFA artifacts, and authenticated web-session cookies or tokens after a victim completes sign-in. Stolen session artifacts can enable account takeover by replaying an authenticated session and may bypass conventional MFA protections. Evilginx is commonly used against cloud identity and email services, particularly Microsoft 365 and Microsoft Entra ID, and has been incorporated into targeted spear-phishing and credential-harvesting operations by state-linked and cybercriminal actors, including Star Blizzard, LAUNDRY BEAR, and ransomware affiliates. Operators commonly pair it with tailored lures, lookalike authentication pages, traffic filtering, and anti-analysis controls. Evilginx is a dual-use adversary-emulation and phishing framework rather than a self-propagating malware family.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
10 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Frameless BitB avoids iframes and supports Evilginx-based proxying of Microsoft login pages.
The group still runs password phishing with Evilginx, a tool that can also steal session cookies to get around two-factor authentication.
Once a user entered their Microsoft credentials into this malicious site, LAUNDRY BEAR’s modified version of the open source adversary emulation toolkit, Evilginx, intercepted the user’s credentials.
Evilginx forks : red-queen (mail-argenta), black-queen/master (saroula01), tous deux utilisés par codemado
Evilginx forks : red-queen (mail-argenta), black-queen/master (saroula01), tous deux utilisés par codemado
Evilginx forks : red-queen (mail-argenta), black-queen/master (saroula01), tous deux utilisés par codemado
19 distinct techniques documented for this family, organized by ATT&CK tactic.
But today, attackers can pair AI-generated phishing with ‘MFA bypass kits,’ such as open-source Evilginx ... and the W3LL panel ... to deceive employees into handing over that ‘extra step’ of security.
For example, if a threat actor creates a phishing domain, goo-ink[.]online, emulating a Google domain, they can then append a URL structure, like adfs[.]llnl[.]gov ... in order to dupe a Lawrence Livermore National Lab employee into believing the link is legitimate.
The page the target lands on is the genuine Microsoft /common/oauth2/v2.0/authorize response, relayed in real time, into which the proxy injects two malicious scripts.
A custom module... automatically accepted “Keep me signed in” and submitted validated one-time codes.
This allowed supported password and MFA steps to complete while the attacker captured the resulting session cookies... The goal was a usable cloud session, not simply a stolen password.
The attack combined adversary-in-the-middle, or AitM, phishing with a modified Frameless BitB toolkit... the proxy relayed the genuine Microsoft sign-in process while adding malicious scripts.
The attack combined adversary-in-the-middle, or AitM, phishing with a modified Frameless BitB toolkit... the proxy relayed the genuine Microsoft sign-in process while adding malicious scripts.
The page the target lands on is the genuine Microsoft /common/oauth2/v2.0/authorize response, relayed in real time, into which the proxy injects two malicious scripts.
Capturing authenticated session material can provide account access even after a victim completes a conventional MFA challenge.
229 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
Other indicator types observed in public reporting.
30 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A reverse-proxy phishing framework used here to relay legitimate Microsoft sign-in activity and facilitate theft of authenticated session cookies.
A phishing framework used to capture passwords and session cookies, potentially bypassing two-factor authentication protections.
Open-source adversary-in-the-middle phishing framework used to bypass MFA by capturing credentials and session tokens via realistic fake sign-in pages.
An adversary-in-the-middle phishing framework used to proxy legitimate authentication flows and capture credentials, session cookies, authentication tokens, and MFA-protected sessions in real time.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.