Christoffer S.<p>(sophos.com) Evilginx: How Attackers Bypass MFA Through Adversary-in-the-Middle Attacks <a href="https://news.sophos.com/en-us/2025/03/28/stealing-user-credentials-with-evilginx/" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">news.sophos.com/en-us/2025/03/</span><span class="invisible">28/stealing-user-credentials-with-evilginx/</span></a></p><p>A short descriptive article about Evilginx and how stealing credentials work, a few suggested ways of detecting etc.</p><p>Summary:<br>This article examines Evilginx, a tool that leverages the legitimate nginx web server to conduct Adversary-in-the-Middle (AitM) attacks that can bypass multifactor authentication (MFA). The tool works by proxying web traffic through malicious sites that mimic legitimate services like Microsoft 365, capturing not only usernames and passwords but also session tokens. The article demonstrates how Evilginx operates, showing how attackers can gain full access to a user's account even when protected by MFA. It provides detection methods through Azure/Microsoft 365 logs and suggests both preemptive and reactive mitigations, emphasizing the need to move toward phishing-resistant FIDO2-based authentication methods.</p><p><a href="https://swecyb.com/tags/Cybersecurity" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Cybersecurity</span></a> <a href="https://swecyb.com/tags/ThreatIntel" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>ThreatIntel</span></a> <a href="https://swecyb.com/tags/Evilginx" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Evilginx</span></a> <a href="https://swecyb.com/tags/Phishing" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Phishing</span></a> <a href="https://swecyb.com/tags/Credentials" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Credentials</span></a> <a href="https://swecyb.com/tags/MFA" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>MFA</span></a> <a href="https://swecyb.com/tags/Azure" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Azure</span></a> <a href="https://swecyb.com/tags/Sophos" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Sophos</span></a></p>