Evilginx
- First seen
- 2018-01-01 00:00:00
- Malware type
- credential-stealer
- Family
- Malware family
- Last IoC activity
- 2026-07-22 00:37:27
- Profile updated
- 2026-07-07 14:24:36
Context
According to the author, Evilginx is a standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies, allowing for the bypass of 2-factor authentication.
Reports & references
- malpedia.caad.fkie.fraunhofer.de — Elf.Evilginx (report)
- osamaellahi.medium.com — The Art Of Defense Evasion Part 3 Bypass Multi Factor Authentication Mfa 26D3A87Dea0F (report)
- github.com — Evilginx2 (report)
- ironnet.com — Robin Banks Still Might Be Robbing Your Bank Part 2 (report)