I am the evil bot capturing your MFA tokens.
Offensive security reverse-proxy phishing framework capable of bypassing MFA protections, created by @mrgretzky
Session hijacking a Microsoft 365 account! Stealing their credentials and bypassing MFA prompt with Evilginx: a reverse-proxy phishing framework! We stage a phishing domain and email pretense, and gain full access to the victim account! https://t.co/E29wB0yNXt
Black Friday and Cyber Monday deals are out! I review some of them and link to a community GitHub page for you all to get discounts on courses, tools and services!
Deals from @_RastaMouse, @_JohnHammond, @offsectraining, @evilginx, @Antisy_Training and a whole lot more.
https://t.co/gPRSiB4FoP
🚨 "Working With Evilginx On-Premises"
For projects where OPSEC is critical: keep sensitive data on your server, use cloud only for redirectors.
Architecture: Cloudflare → Caddy → Evilginx (on-prem via Tailnet)
https://t.co/ZNd8CuHKwI @evilginx@mrgretzky#Phishing#OPSEC
Black hat Asia training is completed. Two days of sharing with our students how APTs compromise AD and Entra ID. And I couldn't help but give a quick shout-out to @evilginx
Next stop is @x33fcon & I'm looking forward to it!
🚨 BLACK FRIDAY Evilginx Mastery -40% SALE 🚨
👑 40% discount (biggest yet!)
⏰ Only 24 hours
Code: BLACKFRIDAY40SALE
Link: https://t.co/XxQ1SO8N3t
Hurry! It's active only until tomorrow!
The purpose of SMS/Push/# matching MFA was to put you past most victims and thus most toolsets. There was a point you were basically immune with legacy protocols turned off in Exchange. Now that stronger methods are normalized, attackers are targeting their weaknesses. Not done.
Session hijacking a Microsoft 365 account! Stealing their credentials and bypassing MFA prompt with Evilginx: a reverse-proxy phishing framework! We stage a phishing domain and email pretense, and gain full access to the victim account! https://t.co/E29wB0yNXt
🚨 The big reveal of Evilginx Pro is finally OUT! 🚨
📔From this blog post you will learn what makes the Pro version different from the community one.
🎟️I explain how Evilpuppet secret token extraction works and showcase the core features.
Enjoy! 🪝🐟
https://t.co/kQyxOOiODI
🎬Phishing LinkedIn and bypassing MFA demo created for the upcoming Evilginx Pro post 🔥
💡Evilginx uses a background browser to capture the secret token from legitimate website and inject it back into the reverse proxy phishing session.
P.S. Enjoy that Cyberpunk tune I made 🎵