Skip to main content
Mallory
MalwareUsed by 1 actor

EvilProxy

EvilProxy is a phishing-as-a-service/adversary-in-the-middle (AiTM) phishing kit used to capture credentials and valid session cookies, enabling session hijacking and bypass of multi-factor authentication. The content describes it as operating as a proxy between victims and enterprise login portals, with a graphical interface that helps criminals customize and automate phishing campaigns, and notes it emerged in mid-2022. It is repeatedly referenced as one of the most prevalent enterprise-targeted phishing kits, alongside Tycoon 2FA and Sneaky2FA, and as part of the broader shift toward identity-focused attacks against Microsoft 365 and similar cloud services.

Observed behavior includes redirecting victims from legitimate-looking OAuth or authentication flows to EvilProxy-powered phishing pages, intercepting passwords and session cookies, and using the OAuth state parameter in some campaigns to prefill victim email addresses. The content also states EvilProxy can be used in man-in-the-middle proxying to evade traditional session-based detection. Hosting and delivery patterns mentioned include use of Google Sites (sites[.]google[.]com) to host malicious pages, and use in campaigns abusing legitimate OAuth redirection behavior to bypass email and browser phishing protections.

Threat activity in the content links EvilProxy to financially motivated intrusion chains and phishing campaigns. Microsoft reported Storm-1811 used malicious links redirecting users to EvilProxy pages during Quick Assist and Teams-based social engineering operations that led to credential theft and follow-on deployment of tooling such as Qakbot, Cobalt Strike, ScreenConnect, NetSupport Manager, OpenSSH tunneling, SystemBC, and in some cases Black Basta ransomware. EvilProxy is also listed among tools abused by the Black Basta group. Additional reporting cited in the content says EvilProxy activity increased after disruption of Tycoon 2FA, and that phishing-as-a-service offerings such as EvilProxy and NakedPages lowered the technical barrier for AiTM phishing. A separate 2025-2026 campaign described in the content used the EvilProxy phishkit in supply-chain thread-hijacking attacks, with Cloudflare Turnstile CAPTCHA-based anti-bot steps, credential capture, and session token theft, primarily targeting Middle Eastern organizations, with likely victimology in finance and energy sectors.

High-confidence indicators and infrastructure explicitly mentioned for EvilProxy in the content include hosting on sites[.]google[.]com and related example domains/IOCs mphdvh[.]icu, kamitore[.]com, aircosspascual[.]com, and Lustefea[.]my[.]id. Additional campaign-specific indicators associated with EvilProxy-enabled phishing in the supplied content include URI pattern POST ^(/bot/), domain pattern ^loginmicrosoft*, and domains himsanam[.]com, bctcontractors[.]com, studiofitout[.]ro, st-fest[.]org, komarautikat[.]hu, eks-esch[.]de, avtoritet-car[.]com, and karaiskou[.]edu[.]gr.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

THREAT ACTORS

Groups observed using it

1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
Storm-1811

Storm-1811 also provides the target user with malicious links that redirect the user to an EvilProxy phishing site to input credentials. EvilProxy is an adversary-in-the-middle (AiTM) phishing kit used to capture passwords, hijack a user’s sign-in session, and skip the authentication process.

via microsoft security blogmicrosoft.com
MITRE ATT&CK

Techniques & procedures

8 distinct techniques documented for this family, organized by ATT&CK tactic.

Resource Development

1 technique
T1583Acquire InfrastructureEvidence1

One clear trend is the abuse of cloud infrastructure. Phishing incidents on Cloudflare Pages domains nearly tripled from 460 in 2023 to more than 1,370 in 2024... Other widely trusted services, including Azure Blob Storage, Google Firebase, AWS CloudFront, and Amazon S3, have also hosted phishing assets.

Initial Access

3 techniques
T1078Valid AccountsEvidence1

Some of the batch scripts observed reference installing fake spam filter updates requiring the targets to provide sign-in credentials... EvilProxy phishing site to input credentials.

T1566PhishingEvidence3

Security experts have issued a warning about the continued risk of Tycoon 2FA attacks... Before the takedown, Tycoon 2FA was behind tens of millions of phishing messages, reaching over 500,000 organizations each month worldwide.

T1566.002Spearphishing LinkEvidence1

"Several threat actors distributed phishing campaigns containing OAuth redirect URLs... The emails used e-signature requests, social security, financial, and political themes... Most URLs were embedded directly in the email body, but some actors placed the URL... inside a PDF attachment"

Persistence

1 technique
T1078Valid AccountsEvidence1

Some of the batch scripts observed reference installing fake spam filter updates requiring the targets to provide sign-in credentials... EvilProxy phishing site to input credentials.

Privilege Escalation

1 technique
T1078Valid AccountsEvidence1

Some of the batch scripts observed reference installing fake spam filter updates requiring the targets to provide sign-in credentials... EvilProxy phishing site to input credentials.

Stealth

1 technique
T1078Valid AccountsEvidence1

Some of the batch scripts observed reference installing fake spam filter updates requiring the targets to provide sign-in credentials... EvilProxy phishing site to input credentials.

Credential Access

4 techniques
T1056.004Credential API HookingEvidence1

"At this stage, the attack resembles a conventional phishing attempt... sent to phishing frameworks such as EvilProxy... designed to intercept credentials and session cookies."

T1539Steal Web Session CookieEvidence5

On a successful login, the victim is redirected to the legitimate website, while the adversary captures their session cookie (i.e., Steal Web Session Cookie) in addition to their username and password.

T1557Adversary-in-the-MiddleEvidence8

Adversary-in-the-middle (AiTM) phishing kits such as Tycoon2FA and EvilProxy intercept the connection between a user and a legitimate application by proxying a fake login to steal credentials and session cookies in real time, bypassing MFA.

T1557.002ARP Cache PoisoningEvidence1

"The attack redirects victims from an OAuth authentication page to phishing-as-a-service websites such as EvilProxy, allowing the digital thieves to intercept users' credentials and session cookies."

Collection

3 techniques
T1056.004Credential API HookingEvidence1

"At this stage, the attack resembles a conventional phishing attempt... sent to phishing frameworks such as EvilProxy... designed to intercept credentials and session cookies."

T1557Adversary-in-the-MiddleEvidence8

Adversary-in-the-middle (AiTM) phishing kits such as Tycoon2FA and EvilProxy intercept the connection between a user and a legitimate application by proxying a fake login to steal credentials and session cookies in real time, bypassing MFA.

T1557.002ARP Cache PoisoningEvidence1

"The attack redirects victims from an OAuth authentication page to phishing-as-a-service websites such as EvilProxy, allowing the digital thieves to intercept users' credentials and session cookies."

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution1

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping8

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.