Evilginx AiTM Attack Steals Microsoft Credentials, MFA, and Sessions
Key Takeaways Highly sophisticated phishing campaigns are actively targeting Microsoft users, leveraging the Evilginx adversary-in-the-middle (AiTM) framework. These attacks bypass multi-factor...
Key Takeaways
- Highly sophisticated phishing campaigns are actively targeting Microsoft users, leveraging the Evilginx adversary-in-the-middle (AiTM) framework.
- These attacks bypass multi-factor authentication (MFA) to steal credentials, MFA tokens, and authenticated session cookies.
- Even users employing MFA are vulnerable, as Evilginx intercepts the entire login process, including MFA approval.
- Stolen session cookies allow attackers to bypass future MFA prompts, gaining persistent access without needing passwords.
- Phishing-resistant MFA (FIDO2/passkeys) and Microsoft Entra ID Conditional Access with Token Protection are critical for mitigation.
The Rise of AiTM Attacks Against Microsoft Users
Microsoft users are currently under siege from advanced phishing attacks that utilize the Evilginx adversary-in-the-middle (AiTM) framework. These campaigns are particularly dangerous because they circumvent multi-factor authentication, capturing not only usernames and passwords but also MFA tokens and active session cookies.
Table Of Content
Security experts have extensively documented how Evilginx operates as an intermediary, silently capturing the full Microsoft login sequence. This includes the initial credential exchange, subsequent MFA approvals, and the resulting authenticated session cookies.
The severity of this threat lies in its ability to compromise accounts even when users have enabled multi-factor authentication, a security measure widely considered robust. Many individuals incorrectly assume that MFA provides complete protection, an assumption now being challenged by these sophisticated AiTM techniques.
How Evilginx Works
Evilginx positions itself strategically between a user and the legitimate Microsoft login portal. It acts as a transparent proxy, mirroring the authentic login page in real-time without raising suspicion. During this process, all data exchanged—from initial credentials to MFA responses—is routed through the attacker’s server before reaching Microsoft.
The core of the attack involves Evilginx leveraging the widely used Nginx web server to proxy traffic. When a victim clicks a malicious link, they are presented with what appears to be an exact duplicate of Microsoft’s login interface. Unbeknownst to the user, every input and interaction is harvested by the attacker’s server.
Upon successful authentication, including the approval of an MFA prompt, the attacker gains immediate access to the user’s username, password, and, critically, the live session cookie. This session cookie is the primary objective, as it signifies to Microsoft’s servers that a valid authentication has already occurred. An attacker can then import this cookie into their own browser, effectively hijacking the session and gaining full access to the account without needing to re-enter credentials or trigger another MFA challenge. This capability fundamentally differentiates AiTM attacks from traditional phishing, which typically only captures static credentials.
Real-World Impact: A NetSPI Case Study
Analysts at NetSPI provided a compelling illustration of this attack in a real-world engagement targeting a corporate executive team. As detailed in a report shared with Cyber Security News (CSN), NetSPI researchers created a convincing lookalike domain and configured an Evilginx server to intercept the client’s live Microsoft login flow. The phishing attempt was embedded within a carefully crafted social engineering narrative, designed to make detection extremely difficult for the targets.
The effectiveness of this method was dramatically demonstrated when a targeted executive, believing they were addressing an urgent company matter, inadvertently forwarded the malicious link to two external contracting firms. This single action threatened to expand a localized attack into a multi-company breach. NetSPI immediately terminated the session to prevent further compromise, underscoring the rapid and far-reaching potential of such attacks.
What You Should Do
- Implement Phishing-Resistant MFA: Prioritize the deployment of FIDO2 hardware keys or passkeys. These methods employ domain binding, preventing the interception of authentication sessions by proxy-based attacks like Evilginx.
- Enable Token Protection in Microsoft Entra ID Conditional Access: Configure Conditional Access policies to bind session tokens to the device from which they were initially issued. This renders stolen session cookies useless if an attacker attempts to replay them from a different machine.
- Monitor Sign-in Logs: Actively monitor Microsoft Entra ID sign-in logs for suspicious activity, particularly for session tokens being used from new or unusual IP addresses or geographical locations that do not match the original issuance point.
- Enhance User Awareness Training: Conduct regular and robust security awareness training for all employees, emphasizing the dangers of sophisticated phishing, social engineering tactics, and the importance of verifying URLs before entering credentials. Educate users about the specific risks of AiTM attacks and how they differ from traditional phishing.
- Establish Clear Communication Policies: Develop and enforce strict internal policies regarding how employees, especially executives, should handle unsolicited external communications that request login to internal systems or direct them to external links. Implement a “verify before you click” culture.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.