Last updated: April 29, 2026
For defensive understanding only. Don’t deploy without clear authorisation. EvilGinx is the proof that “MFA stops phishing” was true in 2018, false by 2024.
How proxy phishing works
- Attacker hosts EvilGinx with a phishlet for the target service (Microsoft, Google, etc.).
- EvilGinx is a transparent reverse proxy: requests come in, get forwarded to legitimate service, responses come back.
- Victim sees legitimate login page (because it IS legitimate, just proxied).
- Victim enters credentials + MFA. Both pass through to legitimate site.
- Legitimate site issues session cookie. EvilGinx captures it.
- Attacker imports cookie → instant authenticated session, no further MFA needed.
Custom team training + practitioner advisory
Beyond the free academy — we run private workshops, vCISO advisory, and red-team exercises tailored to your stack. For Indian SMBs scaling past their first hire.