ATT&CKReferencesBreakdev Evilginx 2.4 SEP 2020

Breakdev Evilginx 2.4 SEP 2020

Gretzky, K. (2020, September 14). Evilginx 2.4 - Gone Phishing. Retrieved January 27, 2026.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples4

TechniqueUsed byProcedure example
T1071.001
Web Protocols
Toolevilginx2

evilginx2 can proxy HTTPS connections between victims and destination websites.

T1090.002
External Proxy
Toolevilginx2

evilginx2 can route traffic via SOCKS5 and HTTP(S) proxies between an intended phishing victim's machine and legitimate websites.

T1132
Data Encoding
Toolevilginx2

evilginx2 can randomly generate and Base64 encode parameters in phishing links to defeat static detection.

T1480
Execution Guardrails
Toolevilginx2

evilginx2 can reject requests to phishing URLs if the User-Agent of the visitor doesn't match the allowlist REGEX filter for a specific lure.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.