Module 14 · EvilGinx — Modern Phishing

Manish Garg
Manish Garg Associate of (ISC)² · RingSafe
Apr 27, 2026
1 min read
Read as

Last updated: April 29, 2026

100% Free

No signup. No paywall. No catch. One of our 10 most-requested practitioner modules — published in full so anyone can learn for free. We earn through consulting, not by gating knowledge.

See all 10 free modules →

For defensive understanding only. Don’t deploy without clear authorisation. EvilGinx is the proof that “MFA stops phishing” was true in 2018, false by 2024.

For defensive understanding only. Don’t deploy without clear authorisation. EvilGinx is the proof that “MFA stops phishing” was true in 2018, false by 2024.

How proxy phishing works

  1. Attacker hosts EvilGinx with a phishlet for the target service (Microsoft, Google, etc.).
  2. EvilGinx is a transparent reverse proxy: requests come in, get forwarded to legitimate service, responses come back.
  3. Victim sees legitimate login page (because it IS legitimate, just proxied).
  4. Victim enters credentials + MFA. Both pass through to legitimate site.
  5. Legitimate site issues session cookie. EvilGinx captures it.
  6. Attacker imports cookie → instant authenticated session, no further MFA needed.
Want this for your team?

Custom team training + practitioner advisory

Beyond the free academy — we run private workshops, vCISO advisory, and red-team exercises tailored to your stack. For Indian SMBs scaling past their first hire.

Book team training call Replies in 4 working hrs · India-only · Senior consultants