evilginx2
MITRE ATT&CK: S9003 View on attack.mitre.org
Aliases: evilginx2
- First seen
- 2018-05-01 00:00:00
- Malware type
- credential-stealer
- Family
- Malware family
- Operating systems
- iaas, identity-provider, office-suite, saas
- Profile updated
- 2026-07-07 15:32:26
Targeted industries: financial-services government-and-public-sector technology-and-telecommunications
Context
evilginx2 is an open-source adversary-in-the-middle (AiTM) attack framework based on the open-source nginx web server. evilginx2 can be used as a reverse proxy between victims and legitimate web services to intercept and capture credentials, authentication tokens, and session cookies.
Detection coverage
- 87 Sigma rules
Malware & tools used
- JavaScript (attack-pattern)
- Time Based Checks (attack-pattern)
- Execution Guardrails (attack-pattern)
- Steal Web Session Cookie (attack-pattern)
- Web Protocols (attack-pattern)
- Adversary-in-the-Middle (attack-pattern)
- Browser Session Hijacking (attack-pattern)
- Multi-Factor Authentication Interception (attack-pattern)
- Data Encoding (attack-pattern)
- Install Root Certificate (attack-pattern)
- External Proxy (attack-pattern)
- System Network Configuration Discovery (attack-pattern)
- Spearphishing Link (attack-pattern)
- Data Obfuscation (attack-pattern)
Reports & references
- MITRE ATT&CK — S9003 (report)
- breakdev.org — Evilginx 2 1 The First Post Release Update (report)
- breakdev.org — Evilginx 2 Next Generation Of Phishing 2Fa Tokens (report)
- sophos.com — Stealing User Credentials With Evilginx (report)