Recommendations on mitigation of man-in-the-middle phishing attacks (evilginx2/Modlishka)
ID: c7f7d9d0-3401-5e13-846e-4263a7870bfc
STIX ID: report--c7f7d9d0-3401-5e13-846e-4263a7870bfc
Feed Name: CERT Polska
Threat Score
CERT Polska documents a rise in MitM proxy phishing (tools: Modlishka, Evilginx2) that transparently proxies real-site traffic to harvest logins, 2FA codes and session cookies — often using valid TLS certificates — and recommends mitigations (U2F/WebAuthn, modified e-mail 2FA, JS-based MITM detection, and trap subpages) while noting these defenses can be bypassed with sufficient attacker effort.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
