Skip to content

EvilGinx

Evilginx is an open-source adversary-in-the-middle phishing framework built on nginx and widely used to proxy legitimate authentication flows in real time.

Profile source: Mallory opens in a new tab

EvilGinx

Family profile

Evilginx is an open-source adversary-in-the-middle phishing framework built on nginx and widely used to proxy legitimate authentication flows in real time. It is commonly deployed against cloud identity providers and webmail services, especially Microsoft 365 and other single sign-on portals, to capture usernames, passwords, multi-factor authentication artifacts, and authenticated session cookies. By relaying the victim’s interaction with the real service through an attacker-controlled reverse proxy, Evilginx enables session hijacking and can allow operators to bypass conventional MFA protections that do not provide phishing resistance.

Evilginx is used extensively in spearphishing and broader phishing operations by both state-linked and financially motivated actors. Reported users include Russian espionage actors such as Star Blizzard and LAUNDRY BEAR, as well as criminal ecosystems and phishing operators associated with Scattered Spider-linked infrastructure and other AiTM campaigns. It has also appeared in modified forks and customized variants that add anti-detection features, target-specific lure themes, cookie handling changes, dashboard functions, and support for additional authentication workflows.

Operationally, Evilginx is typically paired with cloned login pages, lookalike domains, CAPTCHA or anti-bot stages, and social-engineering lures such as conference invitations, procurement workflows, document-sharing prompts, or security alerts. Once a victim authenticates through the proxied page, operators can harvest credentials and replay stolen session material to access accounts, particularly email and cloud services. In observed intrusions, this access has supported espionage, follow-on phishing, mailbox theft, and broader post-compromise activity.

Evilginx is best characterized as a phishing framework and credential-and-session interception utility rather than a traditional endpoint malware family. Its core role is enabling credential theft and session hijacking through AiTM phishing infrastructure targeting web-based authentication flows on Windows-centric enterprise environments and cloud identity ecosystems.

Capabilities

  • Credential Theft
  • Session Hijacking
  • Spoofing

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Aug 22, 2026
Last activity
Aug 27, 2026
Feed role
C2
Host form
7 IP / 0 hostnames

Leading locations

  • US4
  • DE1
  • FR1
  • NL1

Leading providers

  • RouterHosting LLC2
  • Akamai Connected Cloud1
  • Contabo GmbH1
  • Interserver, Inc1
  • Interserver, Inc1
  • IT WEB LTD1

Infrastructure traits

  • Hosting 7

Reported operators

Threat actors

9 named in public reporting
Star Blizzard

Star Blizzard uses the open-source framework EvilGinx in their spear-phishing activity, which allows them to harvest credentials and session cookies to successfully bypass the use of two-factor authentication.

LAUNDRY BEAR

Once a user entered their Microsoft credentials into this malicious site, LAUNDRY BEAR’s modified version of the open source adversary emulation toolkit, Evilginx, intercepted the user’s credentials.

saroula01

Evilginx forks : red-queen (mail-argenta), black-queen/master (saroula01), tous deux utilisés par codemado

mail-argenta

Evilginx forks : red-queen (mail-argenta), black-queen/master (saroula01), tous deux utilisés par codemado

codemado

Evilginx forks : red-queen (mail-argenta), black-queen/master (saroula01), tous deux utilisés par codemado

Scattered Spider

Evilginx Phishing infrastructure assessed with high confidence as very likely linked to Scattered Spider, this assessment is done by infrastructure similarities on previously attributed domains by Silent Push.

STAC4365

Those attempts leveraged phishing sites built with the evilginx open-source adversary-in-the-middle attack framework to collect credentials and session cookies and bypass multi-factor authentication (MFA).

Blue Callisto

The threat actor’s tools, techniques and procedures (TTPs) contained slight shifts during 2022, such as network provider preferences and use of phishing technologies such as Evilginx.

MCTO3030

The attackers are using the open source Evilginx framework to provision these phishing pages and to act as a reverse proxy between the victim and the real site.

MITRE ATT&CK

EvilGinx in ATT&CK

36 distinct techniques

Reporting

Research mentioning EvilGinx

Jul 26
Cyberveille

LAUNDRY BEAR cible Zimbra avec un exploit zero-day pour espionner des organisations occidentales | CyberVeille

Palo Alto Networks Unit 42 reported that a cyberespionage campaign tracked as CL-STA-1114, overlapping with activity attributed by other vendors to Void Blizzard and LAUNDRY BEAR, has been exploiting Zimbra Collaboration Suite webmail servers at government, defense, transportation, and financial organizations. The activity has affected targets across NATO member states, Ukraine, CIS countries, and Africa, with researchers saying the broader cluster has been active since at least 2024 and Zimbra-focused operations began in July 2025. The attackers used zero-click phishing emails to exploit CVE-2025-66376 in Zimbra webmail, allowing a malicious JavaScript payload to run in victims’ browsers without user interaction. Unit 42 said the malware can steal Zimbra credentials, CSRF tokens, 2FA scratch codes, system details, and up to 90 days of email and search history. Researchers also identified at least nine IP addresses and nine domains tied to command-and-control infrastructure, with servers remaining active for an average of 35.4 days, and warned that unpatched Zimbra instances are being actively targeted.

Jul 25
Cysecurity News

Russian Cyber Spies Exploited Critical Zimbra Flaw to Access Emails and 2FA Codes - CySecurity News - Latest Information Security and Hacking Incidents

Jul 24
Scworld

UK issues alert over Russian zero-click email attacks | brief | SC Media

Jul 24
Socradar

CVE-2025-66376: Russian APT Exploits Zimbra Zero-Day

Jul 24
Hackread

Russian Hackers Used a Zimbra Zero-Day to Steal Emails Without Link Clicks

Jul 24
Security Affairs

US Agencies Warn of Laundry Bear Campaign Targeting Unpatched Zimbra Servers

Jul 24
Itpro

NCSC issues alert over 'zero-click' phishing campaign hitting enterprises | IT Pro

Jul 24
Cyber Security News

Russian Hackers Exploiting Zimbra Zero-Day to Steal 90 Days of Emails

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.