An EvilProxy Phishing campaign was recently uncovered, targeting Microsoft 365 accounts of key executives in US. This campaign abuses open redirects from Indeed.com for job postings.
See also: EvilProxy: Allows all hackers to use advanced phishing tactics

The threat actor uses the EvilProxy phishing service to collect cookies during its operation. These cookies can be used to bypass multi-factor authentication (MFA) mechanisms. Menlo Security researchers report that the phishing campaign targets executives and high-ranking employees from various industries, including electronics manufacturing, banking and finance, real estate, insurance, and property management.
Redirects are legitimate URLs that automatically direct visitors to another location on the internet, usually a third-party website. Vulnerabilities in website code, known as open redirects, allow redirects to be created to arbitrary locations. Malicious actors take advantage of this opportunity to direct users to phishing pages.
Since the link comes from a trusted source, it can bypass email security measures or be promoted in search results without arousing suspicion.
In the campaign discovered by Menlo Security, threat actors exploit an open redirect to indeed.com, the American job posting website. Targets receive emails with a link to indeed.com that appears to be legitimate. Once accessed ,the URL will direct you to a phishing website that acts as a reverse proxy for the Microsoft login page.
EvilProxy is a phishing service that operates as a platform, using reverse proxy servers. Its main function is to facilitate communication and transmission of user information between the target and the authentic online service. In this case, we are referring to Microsoft.
See also: Apple not updating an email app with ChatGPT technology due to security concerns

When the user accesses their account through this phishing server, which mimics the authentic login page, the threat actor can capture authentication cookies. Since users have already completed the required MFA (multi-factor authentication) steps during login, the obtained cookies give cybercriminals full access to the victim’s account.
Menlo has recovered several artifacts from the attack that make EvilProxy's performance more secure, including:
- Nginx server hosting
- Specific URI paths that were previously associated with the service
- Proxy authentication requirement
- Presence of status code 444 in server response
- Presence of IDS signatures designed to recognize EvliProxy uri content
- Using the FingerprintJS library to capture fingerprints in the browser
- Using specific POST requests containing emails in encrypted form64
In August 2023, Proofpoint warned of another campaign called EvilProxy. During this attack, approximately 120,000 phishing emails were distributed to hundreds of organizations targeting their employees' Microsoft 365 accounts.
See also: WhatsApp's new native Mac app is now in open beta
Unfortunately, the use of a reverse proxy for phishing is increasing, and their combined use with open redirects improves the success of a campaign. Phishing attacks using EvilProxy are extremely dangerous, as they can cause serious financial damage and violation of the privacy of victims. It is important to be careful and not open suspicious links or enter sensitive information on untrusted websites.
