evilginx2 — Malware Profile
evilginx2 is an open-source adversary-in-the-middle (AiTM) attack framework based on the open-source nginx web server. evilginx2 can be used as a reverse proxy between victims and legitimate web services to intercept and capture credentials, authentication tokens, and session cookies.
MITRE ATT&CK techniques (14)
- T1001 Data Obfuscation
- T1016 System Network Configuration Discovery
- T1059.007 JavaScript
- T1071.001 Web Protocols
- T1090.002 External Proxy
- T1111 Multi-Factor Authentication Interception
- T1132 Data Encoding
- T1185 Browser Session Hijacking
- T1480 Execution Guardrails
- T1497.003 Time Based Checks
- T1539 Steal Web Session Cookie
- T1553.004 Install Root Certificate
- T1557 Adversary-in-the-Middle
- T1598.003 Spearphishing Link