Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Mindgard Raises $30M to Secure AI Systems Against Emerging Threats
August 12, 2026
City-Forum Hackers Exploit Salesforce, ServiceNow Critical Vulnerabilities
August 12, 2026
Palo Alto Networks Patches 11 Vulnerabilities in PAN-OS, GlobalProtect, Prisma Access
August 12, 2026
Home/Threats/Evilginx AiTM Attack Steals Microsoft Credentials, MFA, and Sessions
Threats

Evilginx AiTM Attack Steals Microsoft Credentials, MFA, and Sessions

Key Takeaways Highly sophisticated phishing campaigns are actively targeting Microsoft users, leveraging the Evilginx adversary-in-the-middle (AiTM) framework. These attacks bypass multi-factor...

Emy Elsamnoudy
Emy Elsamnoudy
June 18, 2026 3 Min Read
52 0

Key Takeaways

  • Highly sophisticated phishing campaigns are actively targeting Microsoft users, leveraging the Evilginx adversary-in-the-middle (AiTM) framework.
  • These attacks bypass multi-factor authentication (MFA) to steal credentials, MFA tokens, and authenticated session cookies.
  • Even users employing MFA are vulnerable, as Evilginx intercepts the entire login process, including MFA approval.
  • Stolen session cookies allow attackers to bypass future MFA prompts, gaining persistent access without needing passwords.
  • Phishing-resistant MFA (FIDO2/passkeys) and Microsoft Entra ID Conditional Access with Token Protection are critical for mitigation.

The Rise of AiTM Attacks Against Microsoft Users

Microsoft users are currently under siege from advanced phishing attacks that utilize the Evilginx adversary-in-the-middle (AiTM) framework. These campaigns are particularly dangerous because they circumvent multi-factor authentication, capturing not only usernames and passwords but also MFA tokens and active session cookies.

Table Of Content

  • Key Takeaways
  • The Rise of AiTM Attacks Against Microsoft Users
  • How Evilginx Works
  • Real-World Impact: A NetSPI Case Study
  • What You Should Do

Security experts have extensively documented how Evilginx operates as an intermediary, silently capturing the full Microsoft login sequence. This includes the initial credential exchange, subsequent MFA approvals, and the resulting authenticated session cookies.

The severity of this threat lies in its ability to compromise accounts even when users have enabled multi-factor authentication, a security measure widely considered robust. Many individuals incorrectly assume that MFA provides complete protection, an assumption now being challenged by these sophisticated AiTM techniques.

How Evilginx Works

Evilginx positions itself strategically between a user and the legitimate Microsoft login portal. It acts as a transparent proxy, mirroring the authentic login page in real-time without raising suspicion. During this process, all data exchanged—from initial credentials to MFA responses—is routed through the attacker’s server before reaching Microsoft.

The core of the attack involves Evilginx leveraging the widely used Nginx web server to proxy traffic. When a victim clicks a malicious link, they are presented with what appears to be an exact duplicate of Microsoft’s login interface. Unbeknownst to the user, every input and interaction is harvested by the attacker’s server.

Upon successful authentication, including the approval of an MFA prompt, the attacker gains immediate access to the user’s username, password, and, critically, the live session cookie. This session cookie is the primary objective, as it signifies to Microsoft’s servers that a valid authentication has already occurred. An attacker can then import this cookie into their own browser, effectively hijacking the session and gaining full access to the account without needing to re-enter credentials or trigger another MFA challenge. This capability fundamentally differentiates AiTM attacks from traditional phishing, which typically only captures static credentials.

Real-World Impact: A NetSPI Case Study

Analysts at NetSPI provided a compelling illustration of this attack in a real-world engagement targeting a corporate executive team. As detailed in a report shared with Cyber Security News (CSN), NetSPI researchers created a convincing lookalike domain and configured an Evilginx server to intercept the client’s live Microsoft login flow. The phishing attempt was embedded within a carefully crafted social engineering narrative, designed to make detection extremely difficult for the targets.

The effectiveness of this method was dramatically demonstrated when a targeted executive, believing they were addressing an urgent company matter, inadvertently forwarded the malicious link to two external contracting firms. This single action threatened to expand a localized attack into a multi-company breach. NetSPI immediately terminated the session to prevent further compromise, underscoring the rapid and far-reaching potential of such attacks.

What You Should Do

  • Implement Phishing-Resistant MFA: Prioritize the deployment of FIDO2 hardware keys or passkeys. These methods employ domain binding, preventing the interception of authentication sessions by proxy-based attacks like Evilginx.
  • Enable Token Protection in Microsoft Entra ID Conditional Access: Configure Conditional Access policies to bind session tokens to the device from which they were initially issued. This renders stolen session cookies useless if an attacker attempts to replay them from a different machine.
  • Monitor Sign-in Logs: Actively monitor Microsoft Entra ID sign-in logs for suspicious activity, particularly for session tokens being used from new or unusual IP addresses or geographical locations that do not match the original issuance point.
  • Enhance User Awareness Training: Conduct regular and robust security awareness training for all employees, emphasizing the dangers of sophisticated phishing, social engineering tactics, and the importance of verifying URLs before entering credentials. Educate users about the specific risks of AiTM attacks and how they differ from traditional phishing.
  • Establish Clear Communication Policies: Develop and enforce strict internal policies regarding how employees, especially executives, should handle unsolicited external communications that request login to internal systems or direct them to external links. Implement a “verify before you click” culture.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackBreachphishingSecurityThreat

Share Article

Emy Elsamnoudy

Emy Elsamnoudy

Emy is a cybersecurity analyst and reporter specializing in threat hunting, defense strategies, and industry trends. With expertise in proactive security measures, Emily covers the tools and techniques organizations use to detect and prevent cyber attacks. She is a regular speaker at security conferences and has contributed to industry reports on threat intelligence and security operations. Emily's reporting focuses on helping organizations improve their security posture through practical, actionable insights.

Previous Post

Critical Flaw in PowerShell Commands Lets Attackers Deliver SmartRAT

Next Post

F5 Patches Critical NGINX Vulnerability CVE-2023-50438

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Google Chrome 115 Patches Five High-Severity Use-After-Free Flaws
August 12, 2026
Eclipse Ransomware Launches RaaS, Targets Windows, Linux, ESXi
August 12, 2026
WhatsApp launches new scam alert feature to combat social engineering
August 12, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Emy Elsamnoudy
Emy Elsamnoudy
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us