Hackers Leverage Evilginx to Undermine MFA Security Mimicking Legitimate SSO Sites
ID: 60923271-89ad-58e4-b181-1ab79d988c90
STIX ID: report--60923271-89ad-58e4-b181-1ab79d988c90
Feed Name: cybersecurityNews.com
The report describes active phishing campaigns leveraging the Evilginx reverse-proxy framework to present convincing fake SSO portals, capture session cookies and bypass MFA; stolen session tokens are replayed to access cloud email and collaboration services, enabling account takeover, data theft and long-term stealth access—Infoblox analysts observed campaigns targeting universities and documented the proxy-based cookie interception and header rewriting that enable these attacks.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
