1---2name: performing-initial-access-with-evilginx33description: Perform authorized initial access using EvilGinx3 adversary-in-the-middle phishing framework to capture session tokens and bypass multi-factor authentication during red team engagements.4license: Apache-2.05---6# Performing Initial Access with EvilGinx3
7
8## Overview
9
10EvilGinx3 is a man-in-the-middle attack framework used for phishing login credentials along with session cookies, enabling bypass of multi-factor authentication (MFA). Unlike traditional credential phishing that only captures usernames and passwords, EvilGinx3 operates as a transparent reverse proxy between the victim and the legitimate authentication service, intercepting the full authentication flow including MFA tokens and session cookies. This makes it the primary tool for red teams demonstrating the risk of adversary-in-the-middle (AiTM) attacks against organizations relying solely on MFA for protection.
11
12
13## When to Use
14
15- When conducting security assessments that involve performing initial access with evilginx3
16- When following incident response procedures for related security events
17- When performing scheduled security testing or auditing activities
18- When validating security controls through hands-on testing
19
20## Most Often Missed & How to Confirm
21
22- Phishlet tuning is the #1 miss: stock phishlets break when the target updates JS/login domains. Confirm every `auth_urls`, `sub_filter`, and `js_inject` host resolves through the proxy — a blank or styling-broken login page means the phishlet needs `proxy_hosts`/`sub_filter` fixes, not a "tool doesn't work" conclusion.
23- Domain reputation and TLS are routinely skipped — age the domain, set categorization, and verify Let's Encrypt issued (`phishlets` shows cert OK). A fresh look-alike domain gets blocked by SmartScreen/Safe Browsing before the victim ever submits.
24- The real prize is the captured session cookie, not the password: MFA bypass only works if you import the full token set (e.g., o365 `ESTSAUTH`/`ESTSAUTHPERSISTENT`, Okta `sid`/`idx`) and reach the app without re-prompt.
25- Use `lures edit 0 redirect_url` to bounce victims to the real site post-capture so the AiTM stays unnoticed; missing this often tips off the target.
26- Blacklist scanners (`blacklist unauth`) so bots/sandboxes don't burn the domain before delivery.
27- Positive signal: `sessions <id>` shows non-empty captured cookies/tokens AND those cookies imported via Cookie-Editor load the authenticated app (mailbox/SharePoint) without an MFA prompt.
28- Don't conclude the AiTM failed until: (1) the proxied login page renders and accepts creds, (2) `tokens`/cookies were actually captured (not just username/password), (3) the cookie set imported and bypassed MFA in a clean browser profile, and (4) the domain wasn't blocked at delivery (check it loads from an external network).
29
30## Prerequisites
31
32- Familiarity with red teaming concepts and tools
33- Access to a test or lab environment for safe execution
34- Python 3.8+ with required dependencies installed
35- Appropriate authorization for any testing activities
36
37## Objectives
38
39- Deploy EvilGinx3 with custom phishlets targeting authorized scope
40- Configure DNS and SSL certificates for the phishing domain
41- Capture session tokens that bypass MFA protections
42- Import stolen session cookies into a browser to hijack authenticated sessions
43- Integrate with GoPhish or custom delivery mechanisms for phishing email campaigns
44- Document the complete attack chain from phishing email to authenticated access
45
46## MITRE ATT&CK Mapping
47
48- **T1566.002** - Phishing: Spearphishing Link
49- **T1557** - Adversary-in-the-Middle
50- **T1539** - Steal Web Session Cookie
51- **T1078** - Valid Accounts
52- **T1556** - Modify Authentication Process
53- **T1550.004** - Use Alternate Authentication Material: Web Session Cookie
54
55## Workflow
56
57### Phase 1: Infrastructure Setup
581. Register a convincing lookalike domain (e.g., using homoglyphs or typosquatting)
592. Provision a VPS and point the domain's DNS A record to the server IP
603. Install EvilGinx3:
61 ```bash
62 git clone https://github.com/kgretzky/evilginx2.git
63 cd evilginx2
64 make
65 sudo ./bin/evilginx -p ./phishlets
66 ```
674. Configure the domain and IP in EvilGinx3:
68 ```
69 config domain example-phish.com
70 config ipv4 <server-ip>
71 ```
725. EvilGinx3 automatically provisions Let's Encrypt certificates for configured hostnames
73
74### Phase 2: Phishlet Configuration
751. Select or create a phishlet for the target service (e.g., Microsoft 365, Google Workspace):
76 ```
77 phishlets hostname o365 login.example-phish.com
78 phishlets enable o365
79 ```
802. Verify phishlet is active and SSL certificate is issued:
81 ```
82 phishlets
83 ```
843. Create a lure URL for the phishing campaign:
85 ```
86 lures create o365
87 lures get-url 0
88 ```
894. Optionally configure a redirect URL for post-capture:
90 ```
91 lures edit 0 redirect_url https://legitimate-site.com
92 ```
93
94### Phase 3: Phishing Delivery
951. Craft a pretext email with the lure URL embedded
962. Use GoPhish or manual SMTP for email delivery:
97 ```
98 # Integration with EvilGoPhish for combined campaigns
99 # Provides GoPhish email tracking + EvilGinx3 credential capture
100 ```
1013. Implement URL masking or shortening if needed for link obfuscation
1024. Deploy landing page with appropriate social engineering pretext
103
104### Phase 4: Session Hijacking
1051. Monitor EvilGinx3 for captured sessions:
106 ```
107 sessions
108 sessions <session-id>
109 ```
1102. Extract captured session cookies from the session:
111 ```
112 # Session output includes:
113 # - Username and password
114 # - Session cookies (authentication tokens)
115 # - Custom captured parameters
116 ```
1173. Import session cookies into a browser using a cookie editor extension:
118 - Export cookies in JSON format
119 - Use Cookie-Editor or EditThisCookie browser extension
120 - Navigate to the target service to validate session hijack
1214. Establish persistent access by creating application passwords or OAuth tokens
122
123### Phase 5: Post-Access Activities
1241. Enumerate mailbox contents, contacts, and shared drives
1252. Identify additional targets for lateral phishing
1263. Check for access to connected cloud applications (SharePoint, Teams, OneDrive)
1274. Document all captured credentials and access achieved
128
129## Tools and Resources
130
131| Tool | Purpose | Platform |
132|------|---------|----------|
133| EvilGinx3 | AiTM phishing framework | Linux |
134| GoPhish | Phishing campaign management | Cross-platform |
135| EvilGoPhish | Combined EvilGinx3 + GoPhish integration | Linux |
136| Cookie-Editor | Browser cookie import/export | Browser Extension |
137| Modlishka | Alternative AiTM proxy framework | Linux |
138| Muraena | Alternative AiTM phishing proxy | Linux |
139
140## Phishlet Targets
141
142| Target Service | Phishlet | Captured Data |
143|---------------|----------|---------------|
144| Microsoft 365 | o365 | Session cookies, credentials |
145| Google Workspace | google | Session cookies, credentials |
146| Okta | okta | Session tokens, credentials |
147| GitHub | github | Session cookies, credentials |
148| AWS Console | aws | Session tokens, credentials |
149
150## Detection Indicators
151
152| Indicator | Detection Method |
153|-----------|-----------------|
154| Newly registered lookalike domains | Domain monitoring and certificate transparency logs |
155| SSL certificates for suspicious domains | CT log monitoring (crt.sh, Censys) |
156| Unusual login locations after phishing | SIEM correlation of authentication events |
157| Session cookie replay from different IP | Conditional access policy alerts |
158| AiTM proxy headers in traffic | Network inspection for proxy artifacts |
159
160## Validation Criteria
161
162- [ ] EvilGinx3 deployed with valid SSL certificates
163- [ ] Phishlet configured and enabled for target service
164- [ ] Lure URL generated and accessible
165- [ ] Test credentials captured successfully through phishing flow
166- [ ] Session cookies captured and validated for MFA bypass
167- [ ] Session hijack demonstrated in browser with stolen cookies
168- [ ] Post-authentication access to target service confirmed
169- [ ] Evidence documented with screenshots and session logs