Researchers at Lexfo are tracking three sophisticated phishing kits that were built using open-source components, primarily based on the publicly available adversary-in-the-middle (AiTM) attack framework “Evilginx.” The phishing kits are designed to proxy “live Microsoft 365 authentication sessions to capture session cookies and OAuth tokens in real time, bypassing MFA entirely.”
The kits also use AI to generate personalized phishing lures with a variety of different delivery methods.
“[T]he tool supports a broad lure-generation capability: HTML email templates with per-recipient personalisation (victim domain, company name, randomised strings), dynamically generated PDF, DOCX, PPTX, ZIP, and EML attachments, AI-generated voicemail .wav lures, QR code embedding, and calendar meeting invite abuse for inbox placement,” the researchers write. “A Letter-to-Image feature, described in the guide itself as useful for ‘spam filter evasion techniques,’ converts the HTML body into an image before delivery, defeating content-based filtering. Sender identity rotation, attachment encryption, and From address obfuscation complete the anti-detection layer.”
The researchers conclude that organizations should now assume that threat actors of any skill level have the means to bypass multi-factor authentication via phishing attacks.
“The accessibility of this ecosystem also carries a broader defensive implication,” the researchers write. “The tooling documented here - Evilginx forks, Device Code Flow abuse, pre-built phishing kits - is either publicly available on GitHub or commercially distributed through platforms like Telegram for a few hundred dollars. The technical barrier to running a functional AiTM campaign has dropped to near zero....Defenders must operate under the assumption that any threat actor, regardless of sophistication, is capable of bypassing MFA through session hijacking or Device Code Flow abuse, and adjust detection and response posture accordingly.”
Infosecurity Magazine has the story: Open Directory Exposes Three Evilginx Phishing Operators
