evilginx2

MITRE ATT&CK: S9003 View on attack.mitre.org

Aliases: evilginx2

First seen
2018-05-01 00:00:00
Malware type
credential-stealer
Family
Malware family
Operating systems
iaas, identity-provider, office-suite, saas
Profile updated
2026-07-07 15:32:26

Targeted industries: financial-services government-and-public-sector technology-and-telecommunications

Context

evilginx2 is an open-source adversary-in-the-middle (AiTM) attack framework based on the open-source nginx web server. evilginx2 can be used as a reverse proxy between victims and legitimate web services to intercept and capture credentials, authentication tokens, and session cookies.

Detection coverage

  • 87 Sigma rules

Malware & tools used

  • JavaScript (attack-pattern)
  • Time Based Checks (attack-pattern)
  • Execution Guardrails (attack-pattern)
  • Steal Web Session Cookie (attack-pattern)
  • Web Protocols (attack-pattern)
  • Adversary-in-the-Middle (attack-pattern)
  • Browser Session Hijacking (attack-pattern)
  • Multi-Factor Authentication Interception (attack-pattern)
  • Data Encoding (attack-pattern)
  • Install Root Certificate (attack-pattern)
  • External Proxy (attack-pattern)
  • System Network Configuration Discovery (attack-pattern)
  • Spearphishing Link (attack-pattern)
  • Data Obfuscation (attack-pattern)

Reports & references

  • MITRE ATT&CK — S9003 (report)
  • breakdev.org — Evilginx 2 1 The First Post Release Update (report)
  • breakdev.org — Evilginx 2 Next Generation Of Phishing 2Fa Tokens (report)
  • sophos.com — Stealing User Credentials With Evilginx (report)

External references