logo

State-of-the-art phishing: MFA bypass

ID: 3451f168-62b5-5cd4-bb09-ee12c4f4282f

STIX ID: report--3451f168-62b5-5cd4-bb09-ee12c4f4282f

Feed Name: Cisco Talos

Threat Score
70/100

Date Published: 2025-05-01

Date Updated: 2026-04-27

Author: Jaeson Schultz

...
...

Cisco Talos details how cybercriminals are conducting MFA bypasses using adversary‑in‑the‑middle reverse proxies and turnkey Phishing‑as‑a‑Service kits (Tycoon 2FA, Evilproxy/Evilginx), outlines common indicators (e.g., Evilginx default URL patterns, LetsEncrypt/TLS certificate metadata, anomalous session reuse), and recommends stronger defenses such as WebAuthn, MFA log auditing, and network/security controls to detect and prevent these campaigns.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.