s2
--:--:--UTC

Searching APEX

Starting…

  1. ○ Searching Threats, IOCs & Threat Intelligence locally
  2. ○ Querying external providers
  3. ○ Asking AI Forensic Validator
  4. ○ Creating new entry from validated hit

0s elapsed

TF-MAL-elf.evilginx

📛 Threat Title

Malware family: Evilginx

Category: Evilginx First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `elf.evilginx`. Printable name: Evilginx.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain elf.evilginx VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.evilginx

IOC database

Type
domain
Value
elf.evilginx
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-elf.evilginx

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.evilginx

References (1)

Remediations (10)

  • web:abnormal.ai

    Discover how cybercriminals are using Evilginx to bypass multi-factor authentication (MFA) in attacks targeting Gmail, Outlook, Yahoo, and more.

  • web:ctrlaltdean.github.io

    Once the phishlet is active and DNS is working, visiting the phishing domain in a browser will proxy the real Microsoft login page through Evilginx—complete with working MFA prompts. The Attack - Hijacking a Microsoft 365 Session With Evilginx fully configured, it's time to walk through how an attacker would launch a phishing campaign and capture a valid Microsoft 365 session token. For ...

  • web:cyberpress.org

    Evilginx attack techniques - A new wave of phishing attacks is exploiting the open-source Evilginx framework to target student login portals.

  • web:cybersecuritynews.com

    Hackers use Evilginx phishing portals to bypass MFA, mimicking real SSO pages and stealing session cookies for cloud account takeover.

  • web:gbhackers.com

    A sophisticated threat actor has been conducting a persistent phishing campaign against United States educational institutions since April 2025, leveraging the open-source Evilginx framework to bypass multi-factor authentication (MFA). The campaign, which has targeted at least 18 universities to date, utilizes adversary-in-the-middle (AiTM) techniques to intercept login credentials and session ...

  • web:github.com

    Evilginx is a man-in-the-middle attack framework used for phishing login credentials along with session cookies, which in turn allows to bypass 2-factor authentication protection.

  • web:windowsforum.com

    Evilginx is a phishing tool that leverages the reverse proxy capabilities of the nginx web server to hijack legitimate user sessions. Attackers register a malicious domain and deploy customized "phishlets" that mimic real websites, such as Microsoft 365.

  • web:www.malwarebytes.com

    Researchers are seeing a rise in Evilginx to steal session cookies, letting them bypass the need for a multi-factor authentication (MFA) token among educational institutions.

  • web:www.microsoft.com

    Take these steps to help prevent malware infection on your computer. HackTools attack enterprises more often than individuals. Following the mitigation steps below can help prevent hack tool attacks. Keep backups so you can recover data affected by trojans and destructive attacks. Use controlled folder access to prevent unauthorized applications from modifying protected files. Harden internet ...

  • web:www.sophos.com

    Evilginx , a tool based on the legitimate (and widely used) open-source nginx web server, can be used to steal usernames, passwords, and session tokens, allowing an attacker to potentially bypass multifactor authentication (MFA).

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.