1200KM / tool
evilginx2 — Attack Tool
evilginx2 is an open-source adversary-in-the-middle (AiTM) attack framework based on the open-source nginx web server. evilginx2 can be used as a reverse proxy between victims and legitimate web services to intercept and capture credentials, authentication tokens, and session cookies.
Tool identity and evidence
Included because the active pinned ATT&CK object has type tool. This is an upstream classification, not an assurance of benignness or a recommendation to run it.
Aliases: evilginx2
Existing author guides
No reviewed association in this snapshot.
Primary documentation
No reviewed association in this snapshot.
Connected ecosystem references
Linked tags
Technique-specific simulations and detections
Detection links describe the associated behavior, not independently verified tool-specific signatures.
- T1001 · Data Obfuscation · Detection rules & anomalies
- T1016 · System Network Configuration Discovery · Detection rules & anomalies
- T1059.007 · JavaScript · Detection rules & anomalies
- T1071.001 · Web Protocols · Detection rules & anomalies
- T1090.002 · External Proxy · Detection rules & anomalies
- T1111 · Multi-Factor Authentication Interception · Detection rules & anomalies
- T1132 · Data Encoding · Detection rules & anomalies
- T1185 · Browser Session Hijacking · Detection rules & anomalies
- T1480 · Execution Guardrails · Detection rules & anomalies
- T1497.003 · Time Based Checks · Detection rules & anomalies
- T1539 · Steal Web Session Cookie · Detection rules & anomalies
- T1553.004 · Install Root Certificate · Detection rules & anomalies
- T1557 · Adversary-in-the-Middle · Detection rules & anomalies
- T1598.003 · Spearphishing Link · Detection rules & anomalies
Telemetry context
Derived from the explicitly linked TTPs; not proof of sensor coverage for this tool.
- Application Log Content · DC0038
- Command Execution · DC0064
- Driver Load · DC0079
- File Access · DC0055
- File Creation · DC0039
- File Metadata · DC0059
- File Modification · DC0061
- Firewall Rule Modification · DC0051
- Logon Session Creation · DC0067
- Logon Session Metadata · DC0088
- Module Load · DC0016
- Network Connection Creation · DC0082
- Network Traffic Content · DC0085
- Network Traffic Flow · DC0078
- OS API Execution · DC0021
- Process Access · DC0035
- Process Creation · DC0032
- Process Modification · DC0020
- Script Execution · DC0029
- User Account Authentication · DC0002
- User Account Metadata · DC0013
- WMI Creation · DC0008
- Windows Registry Key Creation · DC0056
- Windows Registry Key Modification · DC0063
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.