logo

Recommendations on mitigation of man-in-the-middle phishing attacks (evilginx2/Modlishka)

ID: c7f7d9d0-3401-5e13-846e-4263a7870bfc

STIX ID: report--c7f7d9d0-3401-5e13-846e-4263a7870bfc

Feed Name: CERT Polska

Threat Score
70/100

Date Published: 2019-01-31

Date Updated: 2026-04-19

Author: Michał Leszczyński

...
...

CERT Polska documents a rise in MitM proxy phishing (tools: Modlishka, Evilginx2) that transparently proxies real-site traffic to harvest logins, 2FA codes and session cookies — often using valid TLS certificates — and recommends mitigations (U2F/WebAuthn, modified e-mail 2FA, JS-based MITM detection, and trap subpages) while noting these defenses can be bypassed with sufficient attacker effort.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.