logo

Hackers Using Evilginx to Steal Session Cookies and Bypass Multi-Factor Authentication Tokens

ID: 8659b20e-83d6-563a-b90c-c2a348911df0

STIX ID: report--8659b20e-83d6-563a-b90c-c2a348911df0

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2025-12-04

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

The report outlines how the Evilginx AiTM phishing toolkit operates as a transparent proxy that relays real site content to capture credentials and, critically, session cookies; by replaying stolen cookies attackers can bypass MFA and take over accounts, with a noted surge in campaigns targeting educational institutions and researcher findings showing unrestricted access and covert data exfiltration.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.