New Phishing Kits Use Open-Source Tools to Bypass MFA

KnowBe4 Team | Jul 31, 2026

Researchers at Lexfo are tracking three sophisticated phishing kits that were built using open-source components, primarily based on the publicly available adversary-in-the-middle (AiTM) attack framework “Evilginx.” The phishing kits are designed to proxy “live Microsoft 365 authentication sessions to capture session cookies and OAuth tokens in real time, bypassing MFA entirely.”

The kits also use AI to generate personalized phishing lures with a variety of different delivery methods.

“[T]he tool supports a broad lure-generation capability: HTML email templates with per-recipient personalisation (victim domain, company name, randomised strings), dynamically generated PDF, DOCX, PPTX, ZIP, and EML attachments, AI-generated voicemail .wav lures, QR code embedding, and calendar meeting invite abuse for inbox placement,” the researchers write. “A Letter-to-Image feature, described in the guide itself as useful for ‘spam filter evasion techniques,’ converts the HTML body into an image before delivery, defeating content-based filtering. Sender identity rotation, attachment encryption, and From address obfuscation complete the anti-detection layer.”

The researchers conclude that organizations should now assume that threat actors of any skill level have the means to bypass multi-factor authentication via phishing attacks.

“The accessibility of this ecosystem also carries a broader defensive implication,” the researchers write. “The tooling documented here - Evilginx forks, Device Code Flow abuse, pre-built phishing kits - is either publicly available on GitHub or commercially distributed through platforms like Telegram for a few hundred dollars. The technical barrier to running a functional AiTM campaign has dropped to near zero....Defenders must operate under the assumption that any threat actor, regardless of sophistication, is capable of bypassing MFA through session hijacking or Device Code Flow abuse, and adjust detection and response posture accordingly.”

Infosecurity Magazine has the story: Open Directory Exposes Three Evilginx Phishing Operators

 

FAQs

How does Evilginx enable MFA bypass?

Evilginx is an open-source AiTM framework that sits between a victim and the real login page, forwarding traffic while secretly recording session cookies and OAuth tokens. Once captured, attacke

How should organizations defend against AiTM and Device Code Flow phishing?

Security teams should assume any attacker, regardless of skill, can bypass MFA through session hijacking or Device Code Flow abuse. Defenses should shift toward detecting anomalous session/token reuse and layered email security rather than relying on MFA alone.

What is an adversary-in-the-middle (AiTM) phishing attack?

An AiTM attack proxies a live login session between a victim and a legitimate service like Microsoft 365, capturing session cookies and authentication tokens in real time instead of just a password. Because the attacker relays the genuine session, MFA is bypassed entirely once the token is stolen.

See KnowBe4 Defend™ in Action

Learn how Defend™ strategically enhances Microsoft 365's native security to catch the threats Secure Email Gateways (SEGs) miss.

Request a Demo

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.