I am the evil bot capturing your MFA tokens.
Offensive security reverse-proxy phishing framework capable of bypassing MFA protections, created by @mrgretzkygithub.com/kgretzky/evilg…Joined May 2018
🚨 "Working With Evilginx On-Premises"
For projects where OPSEC is critical: keep sensitive data on your server, use cloud only for redirectors.
Architecture: Cloudflare → Caddy → Evilginx (on-prem via Tailnet)
dan1t0.com/2025/09/24/Wor…@evilginx@mrgretzky#Phishing#OPSEC
Black hat Asia training is completed. Two days of sharing with our students how APTs compromise AD and Entra ID. And I couldn't help but give a quick shout-out to @evilginx
Next stop is @x33fcon & I'm looking forward to it!
Our friend @mrgretzky hooked us up with 12 Evilginx Mastery courses - making it the 12 days of Evilginx Xmas:)
Course details: academy.breakdev.org/evilginx-maste…
Comment below for a chance to win.
🚨 BLACK FRIDAY Evilginx Mastery -40% SALE 🚨
👑 40% discount (biggest yet!)
⏰ Only 24 hours
Code: BLACKFRIDAY40SALE
Link: academy.breakdev.org/evilginx-maste…
Hurry! It's active only until tomorrow!
The purpose of SMS/Push/# matching MFA was to put you past most victims and thus most toolsets. There was a point you were basically immune with legacy protocols turned off in Exchange. Now that stronger methods are normalized, attackers are targeting their weaknesses. Not done.
Session hijacking a Microsoft 365 account! Stealing their credentials and bypassing MFA prompt with Evilginx: a reverse-proxy phishing framework! We stage a phishing domain and email pretense, and gain full access to the victim account! youtu.be/sZ22YulJwao
Session hijacking a Microsoft 365 account! Stealing their credentials and bypassing MFA prompt with Evilginx: a reverse-proxy phishing framework! We stage a phishing domain and email pretense, and gain full access to the victim account! youtu.be/sZ22YulJwao
🚨 The big reveal of Evilginx Pro is finally OUT! 🚨
📔From this blog post you will learn what makes the Pro version different from the community one.
🎟️I explain how Evilpuppet secret token extraction works and showcase the core features.
Enjoy! 🪝🐟
breakdev.org/evilginx-pro-r…
🎬Phishing LinkedIn and bypassing MFA demo created for the upcoming Evilginx Pro post 🔥
💡Evilginx uses a background browser to capture the secret token from legitimate website and inject it back into the reverse proxy phishing session.
P.S. Enjoy that Cyberpunk tune I made 🎵
300 Followers 247 Following“The quieter you become, the more you are able to hear”
“Only those who will risk going too far, can possibly find out how one can go”
20 Followers 61 FollowingI am into cryptocurrency, follow me if you wanna make money with cryptocurrency meme coin is life saver, let make money together