evilginx's profile picture. I am the evil bot capturing your MFA tokens.

Offensive security reverse-proxy phishing framework capable of bypassing MFA protections, created by @mrgretzky

Evilginx

@evilginx

I am the evil bot capturing your MFA tokens. Offensive security reverse-proxy phishing framework capable of bypassing MFA protections, created by @mrgretzky

Pinned

I approve this message! 🪝🐟

Session hijacking a Microsoft 365 account! Stealing their credentials and bypassing MFA prompt with Evilginx: a reverse-proxy phishing framework! We stage a phishing domain and email pretense, and gain full access to the victim account! youtu.be/sZ22YulJwao

_JohnHammond's tweet image. Session hijacking a Microsoft 365 account! Stealing their credentials and bypassing MFA prompt with Evilginx: a reverse-proxy phishing framework! We stage a phishing domain and email pretense, and gain full access to the victim account! youtu.be/sZ22YulJwao


The official MFA phishing anthem! 🍪💗🎵

🎵🎧 .lıllılı.ıllı.ılılıılıı.lllııılı. UwU Underground Now Playing: [I Stole Your MFA] 0:44 ———♡———1:52 ◁◁ ▐ ▌ ▷▷ Get Psyopped By New Music, Mammals



Evilginx reposted

🚨 The Black Friday sale is coming! The sale drops at midnight today! (UTC+1) It will be the biggest sale yet! 🤩

mrgretzky's tweet image. 🚨 The Black Friday sale is coming!

The sale drops at midnight today! (UTC+1)

It will be the biggest sale yet! 🤩

Black Friday is on 29th November this year. Just sayin'... 🤫


Evilginx reposted

Black hat Asia training is completed. Two days of sharing with our students how APTs compromise AD and Entra ID. And I couldn't help but give a quick shout-out to @evilginx Next stop is @x33fcon & I'm looking forward to it!

DeanOfCyber's tweet image. Black hat Asia training is completed. Two days of sharing with our students how APTs compromise AD and Entra ID. And I couldn't help but give a quick shout-out to @evilginx

Next stop is @x33fcon & I'm looking forward to it!

Evilginx reposted

Merry Christmas everyone! ❄️☃️🎄 Wish you all the best and thank you for a great year! ✨️

Our friend @mrgretzky hooked us up with 12 Evilginx Mastery courses - making it the 12 days of Evilginx Xmas:) Course details: academy.breakdev.org/evilginx-maste… Comment below for a chance to win.

vxunderground's tweet image. Our friend @mrgretzky hooked us up with 12 Evilginx Mastery courses - making it the 12 days of Evilginx Xmas:)

Course details: academy.breakdev.org/evilginx-maste…

Comment below for a chance to win.


Evilginx reposted

🚨 BLACK FRIDAY Evilginx Mastery -40% SALE 🚨 👑 40% discount (biggest yet!) ⏰ Only 24 hours Code: BLACKFRIDAY40SALE Link: academy.breakdev.org/evilginx-maste… Hurry! It's active only until tomorrow!

mrgretzky's tweet image. 🚨 BLACK FRIDAY Evilginx Mastery -40% SALE 🚨

👑 40% discount (biggest yet!)
⏰ Only 24 hours

Code: BLACKFRIDAY40SALE
Link: academy.breakdev.org/evilginx-maste…

Hurry! It's active only until tomorrow!

Evilginx reposted

🚨 Evilginx Mastery Black Friday SALE is coming... tomorrow! 🔥 It will be the BIGGEST sale so far! 🤩 ⏰ Sale will last only 24 hours.

mrgretzky's tweet image. 🚨 Evilginx Mastery Black Friday SALE is coming... tomorrow! 🔥

It will be the BIGGEST sale so far! 🤩

⏰ Sale will last only 24 hours.

Evilginx reposted

The @evilginx Mastery course is way too much fun 👀


Evilginx reposted

The purpose of SMS/Push/# matching MFA was to put you past most victims and thus most toolsets. There was a point you were basically immune with legacy protocols turned off in Exchange. Now that stronger methods are normalized, attackers are targeting their weaknesses. Not done.

Session hijacking a Microsoft 365 account! Stealing their credentials and bypassing MFA prompt with Evilginx: a reverse-proxy phishing framework! We stage a phishing domain and email pretense, and gain full access to the victim account! youtu.be/sZ22YulJwao

_JohnHammond's tweet image. Session hijacking a Microsoft 365 account! Stealing their credentials and bypassing MFA prompt with Evilginx: a reverse-proxy phishing framework! We stage a phishing domain and email pretense, and gain full access to the victim account! youtu.be/sZ22YulJwao


Evilginx reposted

Session hijacking a Microsoft 365 account! Stealing their credentials and bypassing MFA prompt with Evilginx: a reverse-proxy phishing framework! We stage a phishing domain and email pretense, and gain full access to the victim account! youtu.be/sZ22YulJwao

_JohnHammond's tweet image. Session hijacking a Microsoft 365 account! Stealing their credentials and bypassing MFA prompt with Evilginx: a reverse-proxy phishing framework! We stage a phishing domain and email pretense, and gain full access to the victim account! youtu.be/sZ22YulJwao

Evilginx reposted

🚨 The big reveal of Evilginx Pro is finally OUT! 🚨 📔From this blog post you will learn what makes the Pro version different from the community one. 🎟️I explain how Evilpuppet secret token extraction works and showcase the core features. Enjoy! 🪝🐟 breakdev.org/evilginx-pro-r…


Evilginx reposted

🎬Phishing LinkedIn and bypassing MFA demo created for the upcoming Evilginx Pro post 🔥 💡Evilginx uses a background browser to capture the secret token from legitimate website and inject it back into the reverse proxy phishing session. P.S. Enjoy that Cyberpunk tune I made 🎵


Evilginx reposted

Patch to add custom DNS records in running instance of Evilginx made by @ojensen5115 🔥 This is getting added for good in upcoming updates.

This post is unavailable.

Evilginx reposted

🚨BREAKING: Evilginx 3.2 is OUT! 🪝🐟 To celebrate the release of the new update, here is the special 10% discount code for the Evilginx Mastery course! 🎁Code: EVILGINX32 (valid until 31st Aug) 🔗Link: academy.breakdev.org/evilginx-maste… breakdev.org/evilginx-3-2/


Evilginx reposted

Finally my talk from @x33fcon is online! 🔥 I try my best to explain what websites could do to protect the users against reverse proxy phishing attacks like Evilginx.🪝🐟 There is also a bonus live demo at the end with some Evilginx Pro secret sauce! 💡 youtube.com/watch?v=C-Fh4s…

mrgretzky's tweet card. 16. How Much Is The Phish? Evolving Defences Against Evilginx Reverse...

youtube.com

YouTube

16. How Much Is The Phish? Evolving Defences Against Evilginx Reverse...


Evilginx reposted

🎁 Who is excited for Evilginx 3.2 release NEXT WEEK? 🔥 One of the new features is the ability to pause your lures for fixed time duration. Useful if you want to prevent your lure URLs from being scanned right after you send them out or if you want to lay low for a day or two.


Evilginx reposted

Override global redirect URL for each phishlet separately in the upcoming Evilginx 3.2 update 🔥 More features to come as well! Huge thanks to @0x_aalex for pitching this idea in his PR on GitHub.

mrgretzky's tweet image. Override global redirect URL for each phishlet separately in the upcoming Evilginx 3.2 update 🔥 

More features to come as well!

Huge thanks to @0x_aalex for pitching this idea in his PR on GitHub.

Evilginx reposted

Working on developing a dedicated phishing training lab with MFA support for the upcoming Evilginx Mastery course. Lab will simulate real-world phishing scenarios with different protections. Each lesson will teach how to develop a working phishlet hands-on for a given scenario.


Loading...

Something went wrong.


Something went wrong.