ATT&CKReferencesEvilginx 2 July 2018

Evilginx 2 July 2018

Gretzky, K.. (2018, July 26). Evilginx 2 - Next Generation of Phishing 2FA Tokens. Retrieved October 14, 2019.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples7

TechniqueUsed byProcedure example
T1001
Data Obfuscation
Toolevilginx2

evilginx2 can modify the Origin and Referrer fields in HTTPS headers it relays between intended victims and legitimate websites to comply with cross-origin resource sharing (CORS) restrictions.

T1071.001
Web Protocols
Toolevilginx2

evilginx2 can proxy HTTPS connections between victims and destination websites.

T1090.002
External Proxy
Toolevilginx2

evilginx2 can route traffic via SOCKS5 and HTTP(S) proxies between an intended phishing victim's machine and legitimate websites.

T1111
Multi-Factor Authentication Interception
Toolevilginx2

evilginx2 can intercept authentication tokens to enable bypass of non-phishing resistant forms of MFA.

T1539
Steal Web Session Cookie
Toolevilginx2

evilginx2 can collect information on each session with a victim including the session cookie.

T1553.004
Install Root Certificate
Toolevilginx2

evilginx2 has obtained a valid SSL/TLS certificate from LetsEncrypt to provide responses to Automatic Certificate Management Environment (ACME) challenges.

T1557
Adversary-in-the-Middle
Toolevilginx2

evilginx2 has the ability to act as an adversary-in-the-middle (AiTM) relay between a legitimate website and a phished user to capture all transmitted data including usernames, passwords, authentication tokens, and session cookies and tokens.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.