Evilginx2
Featured🎣 Phishing Analysis · Go
Evilginx2 is a man-in-the-middle attack framework used for phishing login credentials along with session cookies, which in turn allows bypassing multi-factor authentication. It acts as a reverse proxy between the victim and the real website, proxying all traffic while capturing credentials and session tokens in real time. This makes it a critical tool for demonstrating the limitations of traditional 2FA and testing organizational resilience to advanced phishing attacks.
Use Cases
- Demonstrating 2FA bypass through session hijacking
- Advanced phishing simulation for red teams
- Testing organizational resilience to credential theft
- Session cookie capture and replay
Tags
Details
- Category
- 🎣 Phishing Analysis
- Language
- Go
- Repository
- kgretzky/evilginx2
Platforms
Alternatives & Comparisons
More in Phishing Analysis
GoPhish
GoOpen-source phishing framework. Create campaigns, track results, and train users with realistic simulations.
King Phisher
PythonPhishing campaign toolkit with web cloning, credential harvesting, and campaign analytics dashboard.
URLScan.io CLI
PythonScan and analyze URLs for phishing indicators, malware, and suspicious behavior. Screenshot and DOM capture.
Modlishka
GoAutomated HTTP reverse proxy for 2FA phishing. Real-time credential and token harvesting.