Last seven days
- First activity
- Aug 22, 2026
- Last activity
- Aug 27, 2026
- Feed role
- C2
- Host form
- 7 IP / 0 hostnames
Evilginx is an open-source adversary-in-the-middle phishing framework built on nginx and widely used to proxy legitimate authentication flows in real time.
Profile source: Mallory opens in a new tabEvilGinx
Evilginx is an open-source adversary-in-the-middle phishing framework built on nginx and widely used to proxy legitimate authentication flows in real time. It is commonly deployed against cloud identity providers and webmail services, especially Microsoft 365 and other single sign-on portals, to capture usernames, passwords, multi-factor authentication artifacts, and authenticated session cookies. By relaying the victim’s interaction with the real service through an attacker-controlled reverse proxy, Evilginx enables session hijacking and can allow operators to bypass conventional MFA protections that do not provide phishing resistance.
Evilginx is used extensively in spearphishing and broader phishing operations by both state-linked and financially motivated actors. Reported users include Russian espionage actors such as Star Blizzard and LAUNDRY BEAR, as well as criminal ecosystems and phishing operators associated with Scattered Spider-linked infrastructure and other AiTM campaigns. It has also appeared in modified forks and customized variants that add anti-detection features, target-specific lure themes, cookie handling changes, dashboard functions, and support for additional authentication workflows.
Operationally, Evilginx is typically paired with cloned login pages, lookalike domains, CAPTCHA or anti-bot stages, and social-engineering lures such as conference invitations, procurement workflows, document-sharing prompts, or security alerts. Once a victim authenticates through the proxied page, operators can harvest credentials and replay stolen session material to access accounts, particularly email and cloud services. In observed intrusions, this access has supported espionage, follow-on phishing, mailbox theft, and broader post-compromise activity.
Evilginx is best characterized as a phishing framework and credential-and-session interception utility rather than a traditional endpoint malware family. Its core role is enabling credential theft and session hijacking through AiTM phishing infrastructure targeting web-based authentication flows on Windows-centric enterprise environments and cloud identity ecosystems.
C2 tracking
Derp observations, rolling seven-day window
Reported operators
Star Blizzard uses the open-source framework EvilGinx in their spear-phishing activity, which allows them to harvest credentials and session cookies to successfully bypass the use of two-factor authentication.
Once a user entered their Microsoft credentials into this malicious site, LAUNDRY BEAR’s modified version of the open source adversary emulation toolkit, Evilginx, intercepted the user’s credentials.
Evilginx forks : red-queen (mail-argenta), black-queen/master (saroula01), tous deux utilisés par codemado
Evilginx forks : red-queen (mail-argenta), black-queen/master (saroula01), tous deux utilisés par codemado
Evilginx forks : red-queen (mail-argenta), black-queen/master (saroula01), tous deux utilisés par codemado
Evilginx Phishing infrastructure assessed with high confidence as very likely linked to Scattered Spider, this assessment is done by infrastructure similarities on previously attributed domains by Silent Push.
Those attempts leveraged phishing sites built with the evilginx open-source adversary-in-the-middle attack framework to collect credentials and session cookies and bypass multi-factor authentication (MFA).
The threat actor’s tools, techniques and procedures (TTPs) contained slight shifts during 2022, such as network provider preferences and use of phishing technologies such as Evilginx.
The attackers are using the open source Evilginx framework to provision these phishing pages and to act as a reverse proxy between the victim and the real site.
MITRE ATT&CK
Reporting
Palo Alto Networks Unit 42 reported that a cyberespionage campaign tracked as CL-STA-1114, overlapping with activity attributed by other vendors to Void Blizzard and LAUNDRY BEAR, has been exploiting Zimbra Collaboration Suite webmail servers at government, defense, transportation, and financial organizations. The activity has affected targets across NATO member states, Ukraine, CIS countries, and Africa, with researchers saying the broader cluster has been active since at least 2024 and Zimbra-focused operations began in July 2025. The attackers used zero-click phishing emails to exploit CVE-2025-66376 in Zimbra webmail, allowing a malicious JavaScript payload to run in victims’ browsers without user interaction. Unit 42 said the malware can steal Zimbra credentials, CSRF tokens, 2FA scratch codes, system details, and up to 90 days of email and search history. Researchers also identified at least nine IP addresses and nine domains tied to command-and-control infrastructure, with servers remaining active for an average of 35.4 days, and warned that unpatched Zimbra instances are being actively targeted.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.