ATT&CKReferencesBreakdev Evilginx 3.2 AUG 2023

Breakdev Evilginx 3.2 AUG 2023

Gretzky, K. (2023, August 24). Evilginx 3.2 - Swimming With The Phishes. Retrieved January 27, 2026.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples2

TechniqueUsed byProcedure example
T1497.003
Time Based Checks
Toolevilginx2

evilginx2 has the ability to hide phishing lures for a set time to avoid scanning by sandboxes.

T1557
Adversary-in-the-Middle
Toolevilginx2

evilginx2 has the ability to act as an adversary-in-the-middle (AiTM) relay between a legitimate website and a phished user to capture all transmitted data including usernames, passwords, authentication tokens, and session cookies and tokens.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.