| Technique | Procedure example |
|---|---|
| T1001 Data Obfuscation |
evilginx2 can modify the Origin and Referrer fields in HTTPS headers it relays between intended victims and legitimate websites to comply with cross-origin resource sharing (CORS) restrictions. |
| T1016 System Network Configuration Discovery |
evilginx2 can capture information from each session with a victim including the public IP used to access the server and the user agent. |
| T1059.007 JavaScript |
evilginx2 can inject JavaScript code into HTML content to customize phishing attacks. |
| T1071.001 Web Protocols |
evilginx2 can proxy HTTPS connections between victims and destination websites. |
| T1090.002 External Proxy |
evilginx2 can route traffic via SOCKS5 and HTTP(S) proxies between an intended phishing victim's machine and legitimate websites. |
| T1111 Multi-Factor Authentication Interception |
evilginx2 can intercept authentication tokens to enable bypass of non-phishing resistant forms of MFA. |
| T1132 Data Encoding |
evilginx2 can randomly generate and Base64 encode parameters in phishing links to defeat static detection. |
| T1185 Browser Session Hijacking |
evilginx2 can inject custom POST arguments into requests to silently enable "Remember Me" options during authentication to stay logged in across browser sessions. |
| T1480 Execution Guardrails |
evilginx2 can reject requests to phishing URLs if the User-Agent of the visitor doesn't match the allowlist REGEX filter for a specific lure. |
| T1497.003 Time Based Checks |
evilginx2 has the ability to hide phishing lures for a set time to avoid scanning by sandboxes. |
| T1539 Steal Web Session Cookie |
evilginx2 can collect information on each session with a victim including the session cookie. |
| T1553.004 Install Root Certificate |
evilginx2 has obtained a valid SSL/TLS certificate from LetsEncrypt to provide responses to Automatic Certificate Management Environment (ACME) challenges. |
| T1557 Adversary-in-the-Middle |
evilginx2 has the ability to act as an adversary-in-the-middle (AiTM) relay between a legitimate website and a phished user to capture all transmitted data including usernames, passwords, authentication tokens, and session cookies and tokens. |
| T1598.003 Spearphishing Link |
evilginx2 can generate and display phishing URLs including hidden tracking pixels and can also embed URLs within iframes for browser-in-the-browser phishing. |
None recorded.
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.