logo

'LockBit of phishing' EvilProxy used in more than a million attacks every month

ID: 8fedd80c-737c-57c9-bf49-5304d04298be

STIX ID: report--8fedd80c-737c-57c9-bf49-5304d04298be

Feed Name: The Register (Security)

Threat Score
75/100

Date Published: 2024-07-30

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

The report details active, large-scale phishing campaigns powered by the EvilProxy PhaaS reverse-proxy that dynamically proxies real login pages to harvest credentials, session cookies and MFA tokens while using Cloudflare and multi-stage redirects to evade automated detection; Proofpoint and Menlo observations show widespread use, high-volume detections, and adoption by known actors TA4903 and TA577 targeting high-value executives and organizations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.