ATT&CKReferencesSophos Evilginx MAR 2025

Sophos Evilginx MAR 2025

Everts, M. (2025, March 28). Stealing user credentials with evilginx. Retrieved January 27, 2026.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples5

TechniqueUsed byProcedure example
T1016
System Network Configuration Discovery
Toolevilginx2

evilginx2 can capture information from each session with a victim including the public IP used to access the server and the user agent.

T1090.002
External Proxy
Toolevilginx2

evilginx2 can route traffic via SOCKS5 and HTTP(S) proxies between an intended phishing victim's machine and legitimate websites.

T1539
Steal Web Session Cookie
Toolevilginx2

evilginx2 can collect information on each session with a victim including the session cookie.

T1557
Adversary-in-the-Middle
Toolevilginx2

evilginx2 has the ability to act as an adversary-in-the-middle (AiTM) relay between a legitimate website and a phished user to capture all transmitted data including usernames, passwords, authentication tokens, and session cookies and tokens.

T1598.003
Spearphishing Link
Toolevilginx2

evilginx2 can generate and display phishing URLs including hidden tracking pixels and can also embed URLs within iframes for browser-in-the-browser phishing.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.