One of the most dangerous phishing tools is making a comeback, causing concern among experts and organizations. Evilginx, an advanced kit used by cybercriminals in Adversary-in-the-Middle (AiTM), allows the bypassing of even multi-factor authentication (MFA) systems — one of the most basic cybersecurity measures implemented today.

This is a tool that has evolved to carry out realistic, targeted and highly effective attacks, creating headaches especially for educational institutions and organizations that rely on cloud services.
See also: GoldFactory targets Southeast Asia with over 11,000 infections
How Evilginx works and why it is so effective
At the heart of the threat is a clever but dangerous technique: active login cookie hijacking. Unlike classic phishing methods that aim to collect passwords, Evilginx focuses on “overloading” a valid user session. This way, the attacker gains access without needing either a password or MFA.
The attack begins when the victim clicks on a convincing, specially crafted link. The user is taken to a page that looks exactly like the real website — not only in appearance, but also in functionality. This happens because Evilginx acts as a reverse proxy: it mediates between the user and the authentic website, transferring the login process in real time.
As the user enters their credentials and completes MFA, the tool “catches” the session cookie that the real server creates to verify identity. From that moment on, the attacker can replicate the session in their own browser — as if they were the legitimate user.
See also: Sneeit Framework: Hackers exploit vulnerability in WordPress plugin

Why cookie theft is so devastating
Access via a stolen cookie gives the attacker complete control of the account . According to Malwarebytes ' analysis , cybercriminals can:
- Read sensitive or confidential emails
- Change security settings and recovery information
- Download personal or financial data
- Bypass security alerts, since the session appears "normal"
The most worrying thing is that the activity appears perfectly legitimate. Since the session is already considered authenticated by the system, any suspicious action may go undetected. This allows attackers to remain “invisible” for long periods of time.
A new generation of phishing attacks with “perfect disguise”
The big advantage of Evilginx is its ability to produce phishing pages that are not simple copies, but dynamic access channels to the real website. By using valid TLS certificates, the familiar security padlock in the browser still appears — rendering traditional warning signs almost useless.
See also: Aisuru botnet behind 29.7 Tbps DDoS attack
Furthermore, the phishing links used by attackers are often designed to “disappear” quickly, so that they never reach databases . This significantly weakens detection systems, which are now forced to rely primarily on behavioral analysis.
The result is an environment where attacker technology evolves faster than defenses, leaving end users more exposed than ever.

Protection and countermeasures: What organizations can do
Although AiTM attacks are particularly dangerous, there are ways to reduce the risk:
🔑 Secure your passwords with Proton Pass
Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.
- ✔ Encrypted storage of passwords & passkeys
- ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
- ✔ Free version — on all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
- Using FIDO2/WebAuthn keys instead of passwords or SMS MFA
- Implementation of adaptive authentication systems that analyze the connection context
- Actively monitor for strange changes to account settings
- Training staff and students to recognize suspicious links
Educational institutions in particular, which are facing increasing attacks, should review the cybersecurity methods they use.
The future: A battle that has just begun
Evilginx is at the forefront of a new generation of phishing tools that no longer target passwords — they target authentication mechanisms. As cyberattacks become more sophisticated, organizations are being forced to adopt more sophisticated defenses. The only thing that is certain is that the cat-and-mouse game of cybersecurity has just been taken to a new level.
