logo

Hackers Leverage Evilginx to Undermine MFA Security Mimicking Legitimate SSO Sites

ID: 60923271-89ad-58e4-b181-1ab79d988c90

STIX ID: report--60923271-89ad-58e4-b181-1ab79d988c90

Feed Name: cybersecurityNews.com

Threat Score
70/100

Date Published: 2025-12-02

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

The report describes active phishing campaigns leveraging the Evilginx reverse-proxy framework to present convincing fake SSO portals, capture session cookies and bypass MFA; stolen session tokens are replayed to access cloud email and collaboration services, enabling account takeover, data theft and long-term stealth access—Infoblox analysts observed campaigns targeting universities and documented the proxy-based cookie interception and header rewriting that enable these attacks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.