evilginx2

S9003

Tool.View on attack.mitre.org

About this tool

evilginx2 is an open-source adversary-in-the-middle (AiTM) attack framework based on the open-source nginx web server. evilginx2 can be used as a reverse proxy between victims and legitimate web services to intercept and capture credentials, authentication tokens, and session cookies.

Techniques used14

Procedure examples14

TechniqueProcedure example
T1001
Data Obfuscation

evilginx2 can modify the Origin and Referrer fields in HTTPS headers it relays between intended victims and legitimate websites to comply with cross-origin resource sharing (CORS) restrictions.

T1016
System Network Configuration Discovery

evilginx2 can capture information from each session with a victim including the public IP used to access the server and the user agent.

T1059.007
JavaScript

evilginx2 can inject JavaScript code into HTML content to customize phishing attacks.

T1071.001
Web Protocols

evilginx2 can proxy HTTPS connections between victims and destination websites.

T1090.002
External Proxy

evilginx2 can route traffic via SOCKS5 and HTTP(S) proxies between an intended phishing victim's machine and legitimate websites.

T1111
Multi-Factor Authentication Interception

evilginx2 can intercept authentication tokens to enable bypass of non-phishing resistant forms of MFA.

T1132
Data Encoding

evilginx2 can randomly generate and Base64 encode parameters in phishing links to defeat static detection.

T1185
Browser Session Hijacking

evilginx2 can inject custom POST arguments into requests to silently enable "Remember Me" options during authentication to stay logged in across browser sessions.

T1480
Execution Guardrails

evilginx2 can reject requests to phishing URLs if the User-Agent of the visitor doesn't match the allowlist REGEX filter for a specific lure.

T1497.003
Time Based Checks

evilginx2 has the ability to hide phishing lures for a set time to avoid scanning by sandboxes.

T1539
Steal Web Session Cookie

evilginx2 can collect information on each session with a victim including the session cookie.

T1553.004
Install Root Certificate

evilginx2 has obtained a valid SSL/TLS certificate from LetsEncrypt to provide responses to Automatic Certificate Management Environment (ACME) challenges.

T1557
Adversary-in-the-Middle

evilginx2 has the ability to act as an adversary-in-the-middle (AiTM) relay between a legitimate website and a phished user to capture all transmitted data including usernames, passwords, authentication tokens, and session cookies and tokens.

T1598.003
Spearphishing Link

evilginx2 can generate and display phishing URLs including hidden tracking pixels and can also embed URLs within iframes for browser-in-the-browser phishing.

Groups that use it0

None recorded.

Campaigns0

None recorded.

References3

  1. Breakdev Evilginx 2.1 SEP 2018 Open source
    Gretzky, K. (2018, September 10). Evilginx 2.1 - The First Post-Release Update. Retrieved January 27, 2026.
  2. Evilginx 2 July 2018 Open source
    Gretzky, K.. (2018, July 26). Evilginx 2 - Next Generation of Phishing 2FA Tokens. Retrieved October 14, 2019.
  3. Sophos Evilginx MAR 2025 Open source
    Everts, M. (2025, March 28). Stealing user credentials with evilginx. Retrieved January 27, 2026.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.