Evilginx: the new generation of phishing — (too) effective and formidable
In 2023, nearly one in two French companies (49%) reported having suffered at least one "successful" cyberattack over the past 12 months, a figure that rose compared to 2022 (45%). For 60% of them, making it the technique most used by cyberattackers, this attack was phishing, whether spear phishing, smishing, or vishing. These attacks are not without consequences: theft of personal or sensitive information (banking credentials, logs), account hijacking, or financial losses.
In a context where cyberthreats are constantly evolving, hackers are developing increasingly sophisticated techniques to compromise the security of users, businesses, and organizations. Among these cyberthreats, Evilginx stands out as a highly effective and formidable tool, capable of bypassing any form of multi-factor authentication (MFA). Widely used in phishing campaigns, Evilginx has become a powerful tool, and it's easy to use with GottaPhish!
What is Evilginx?
In short, Evilginx is an advanced phishing tool, widely used in phishing campaigns to bypass MFA. It works as a man-in-the-middle (MITM) proxy, allowing attackers to intercept and manipulate the data exchanged between users and legitimate websites: login credentials, session cookies, and other sensitive information.
Evilginx is generally used in attacks known as Attacker-in-the-Middle (AiTM), an advanced form of phishing capable of defeating those well-known two-factor authentication schemes that are supposed to protect us from any unauthorized access online.
What is the difference with "classic" phishing?
"Classic" phishing attempts and those carried out with Evilginx are indeed different.
In so-called classic phishing, cybercriminals reproduce HTML templates that resemble login pages like the ones we use on Outlook, LinkedIn, our bank, etc., imitating their appearance as realistically as possible. Their goal is to trick the victim into entering their login credentials, which are then stolen and recorded by the attackers.
With Evilginx, instead of displaying simple lookalike templates, the cybercriminal sets up a phishing site that perfectly mimics a legitimate site. When a user enters their login credentials and their multi-factor authentication (MFA) code, Evilginx intercepts this information and relays it in real time to the genuine site. The user is therefore redirected to the real site without suspecting a thing, while the attacker gains access to the account at the same time without being detected.

In a sense, Evilginx is a relay between the trapped user and the genuine website, all while collecting all the data exchanged between the two parties.
Why doesn't two-factor authentication work?
An important detail to note is that Evilginx also intercepts the session tokens generated after authentication. When the victim enters their login information and has to provide their two-factor authentication code, they will indeed receive their code, but without knowing that Evilginx is still in the middle.
How does it work? With every two-factor authentication, a token is generated in the form of a cookie, and this cookie is intercepted by Evilginx and then saved. And that is what allows the attacker to bypass the usual MFA protection.
Unfortunately, at this stage, the cybercriminal has everything needed to log in to the victim's accounts, without ever being stopped by two-factor authentication.
As an example, an attacker can create a fake login page mimicking that of a bank. When the victim enters their username, password, and MFA code, the attacker (using Evilginx as a proxy) relays this information to the bank's genuine site. And once authentication succeeds, the attacker intercepts the session cookies, which they can then reuse to impersonate the victim during future logins with the bank, even after two-factor authentication has been verified.
How can you protect yourself against Evilginx?
It's true that this malicious proxy can be frightening because it is almost invisible, but there are simple ways to protect yourself against it.
1. Check the website's domain
What Evilginx will never be able to do is have the same domain name as the real website. It will always be slightly different, because attackers have to register their own domain, which is why you should always verify the legitimacy of the website's domain in the address bar.

For example, if an attacker targets LinkedIn, they might register a domain name like linkediin.com or llnkedin.com instead of the real domain name: linkedin.com.
2. Use a U2F security key
Another way to protect yourself is to use a U2F security key (Universal Second Factor), which is one of the most secure methods for two-factor authentication. It is a physical security key for MFA that provides additional security online.
It works as follows: the key communicates directly with the website, and if it detects a difference between the domain name in the address bar and the domain name of the real website, then the communication is interrupted.
3. Train and raise awareness of cyberthreats
The real danger of Evilginx is that it only takes a single tricked employee to compromise the entire company and all of its confidential data. That is why it is very important to train employees and raise their awareness of the risks of phishing to prevent any security breach within the company.
At GottaPhish, we offer exactly this kind of training for awareness purposes, because we believe that a large number of cyberattacks could be avoided if employees were better trained.
We offer both phishing tools to send personalized emails to employees, as well as short and long training courses on e-learning platforms tailored to everyone's needs.
Feel free to check out our awareness tools!
How can you try Evilginx with GottaPhish?
One of the drawbacks of using Evilginx on your own is that it is a complex tool that requires a lot of preparation time. Indeed, setting it up requires several technical steps, notably the manual configuration of phishlets (specific modules designed to faithfully imitate the targeted websites). Without these precise configurations, Evilginx cannot effectively intercept the credentials or sessions of the targeted sites, which makes it a powerful tool but one that is not very accessible to an inexperienced user.
That is why, at GottaPhish, we offer you our GottaPhish Evilginx tool: fast and automated.
Try it out by asking us for a demo!
