Attackers have a new way to slip past your MFA
ID: 61db994e-a82c-5d39-ae64-d0135a1b3d86
STIX ID: report--61db994e-a82c-5d39-ae64-d0135a1b3d86
Feed Name: Malwarebytes Blog
Researchers warn of increasing use of Evilginx, an attacker-in-the-middle phishing toolkit, to steal credentials and session cookies—allowing adversaries to bypass MFA and impersonate users, particularly affecting educational institutions. The report explains how a live-proxy phishing page relays real login flows to capture session cookies, enabling persistent access without further MFA prompts, and highlights mitigation steps including phishing-resistant MFA (passkeys/hardware keys), careful link scrutiny, password managers, real-time web/anti-malware protection, and revoking active sessions when suspicious activity is detected.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
