Evilginx Tool (Still) Bypasses MFA
ID: 5e7e2eae-b8e1-5291-81fd-0c31a9034f3d
STIX ID: report--5e7e2eae-b8e1-5291-81fd-0c31a9034f3d
Feed Name: Dark Reading
Sophos researchers warn that Evilginx, an adversary‑in‑the‑middle (AitM) proxy built on a malicious NGINX variant, is being used to phish Microsoft users, capture credentials and session cookies, and bypass token or push‑based MFA; captured cookies let attackers sign into legitimate portals to access mailboxes, reset MFA, change passwords and persist access. The report notes in‑the‑wild activity (including an MSP-targeted incident), a rise in similar AitM tools, and recommends moving to phishing‑resistant authentication such as FIDO2/passkeys combined with conditional access.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
