logo

Attackers have a new way to slip past your MFA

ID: 61db994e-a82c-5d39-ae64-d0135a1b3d86

STIX ID: report--61db994e-a82c-5d39-ae64-d0135a1b3d86

Feed Name: Malwarebytes Blog

Date Published: 2025-12-03

Date Updated: 2026-04-28

...
...

Researchers warn of increasing use of Evilginx, an attacker-in-the-middle phishing toolkit, to steal credentials and session cookies—allowing adversaries to bypass MFA and impersonate users, particularly affecting educational institutions. The report explains how a live-proxy phishing page relays real login flows to capture session cookies, enabling persistent access without further MFA prompts, and highlights mitigation steps including phishing-resistant MFA (passkeys/hardware keys), careful link scrutiny, password managers, real-time web/anti-malware protection, and revoking active sessions when suspicious activity is detected.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.