Gretzky, K.. (2018, July 26). Evilginx 2 - Next Generation of Phishing 2FA Tokens. Retrieved October 14, 2019.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1001 Data Obfuscation |
Toolevilginx2 | evilginx2 can modify the Origin and Referrer fields in HTTPS headers it relays between intended victims and legitimate websites to comply with cross-origin resource sharing (CORS) restrictions. |
| T1071.001 Web Protocols |
Toolevilginx2 | evilginx2 can proxy HTTPS connections between victims and destination websites. |
| T1090.002 External Proxy |
Toolevilginx2 | evilginx2 can route traffic via SOCKS5 and HTTP(S) proxies between an intended phishing victim's machine and legitimate websites. |
| T1111 Multi-Factor Authentication Interception |
Toolevilginx2 | evilginx2 can intercept authentication tokens to enable bypass of non-phishing resistant forms of MFA. |
| T1539 Steal Web Session Cookie |
Toolevilginx2 | evilginx2 can collect information on each session with a victim including the session cookie. |
| T1553.004 Install Root Certificate |
Toolevilginx2 | evilginx2 has obtained a valid SSL/TLS certificate from LetsEncrypt to provide responses to Automatic Certificate Management Environment (ACME) challenges. |
| T1557 Adversary-in-the-Middle |
Toolevilginx2 | evilginx2 has the ability to act as an adversary-in-the-middle (AiTM) relay between a legitimate website and a phished user to capture all transmitted data including usernames, passwords, authentication tokens, and session cookies and tokens. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.