---
title: "Evilginx: Modern Phishing and MFA Vulnerabilities | SIRKit"
description: Evilginx and how MFA doesn't protect against this modern phishing technique.
image: https://www.sirkit.ca/hubfs/Imported_Blog_Media/Cyber-Security-Technician.jpg
---

[Skip to main content](https://www.sirkit.ca/blog/a-closer-look-at-evilginx-and-how-mfa-doesnt-protect-against-this-modern-phishing-technique#main-content)

[![sirkit-logo-reverse-with-tm](https://www.sirkit.ca/hubfs/sirkit-logo-reverse-with-tm.svg) ![sirkit-logo-reverse-with-tm](https://www.sirkit.ca/hubfs/sirkit-logo-reverse-with-tm.svg)](https://www.sirkit.ca)

- Show submenu for Services Services 
  
    - [Managed IT](https://www.sirkit.ca/managed-it-services)
    - [Co-Managed IT](https://www.sirkit.ca/co-managed-it-services)
    - [Integrated IT Solutions](https://www.sirkit.ca/integrated-it-solutions)
- [Cybersecurity](https://www.sirkit.ca/cybersecurity)
- [Show submenu for About Us About Us](https://www.sirkit.ca/about) 
    - [Executive Team](https://www.sirkit.ca/about?#exec)
    - [Careers](https://www.sirkit.ca/careers)
    - [Contact Us](https://www.sirkit.ca/contact)
- [Blog](https://www.sirkit.ca/blog)

Open main navigation

Close main navigation

- Show submenu for Services Services 
  
    - Services
    - [Managed IT](https://www.sirkit.ca/managed-it-services)
    - [Co-Managed IT](https://www.sirkit.ca/co-managed-it-services)
    - [Integrated IT Solutions](https://www.sirkit.ca/integrated-it-solutions)
- [Cybersecurity](https://www.sirkit.ca/cybersecurity)
- Show submenu for About Us About Us 
  
    - About Us
    - [About Us](https://www.sirkit.ca/about)
    - [Executive Team](https://www.sirkit.ca/about?#exec)
    - [Careers](https://www.sirkit.ca/careers)
    - [Contact Us](https://www.sirkit.ca/contact)
- [Blog](https://www.sirkit.ca/blog)
- [Connect with our Team](https://www.sirkit.ca/contact)

[Connect with our Team](https://www.sirkit.ca/contact)

[Skip to main content](https://www.sirkit.ca/blog/a-closer-look-at-evilginx-and-how-mfa-doesnt-protect-against-this-modern-phishing-technique#main-content)

This is an announcement bar or top menu bar. Additional content can go here.

[![sirkit logo](https://www.sirkit.ca/hubfs/Sirkit_Primary-Logo-RGB.svg) ![sirkit logo](https://www.sirkit.ca/hubfs/Sirkit_Primary-Logo-RGB.svg)](https://www.sirkit.ca)

- Show submenu for Services Services 
  
    - [Managed IT](https://www.sirkit.ca/managed-it-services)
    - [Co-Managed IT](https://www.sirkit.ca/co-managed-it-services)
    - [Integrated IT Solutions](https://www.sirkit.ca/integrated-it-solutions)
- [Cybersecurity](https://www.sirkit.ca/cybersecurity)
- [Show submenu for About Us About Us](https://www.sirkit.ca/about) 
    - [Executive Team](https://www.sirkit.ca/about?#exec)
    - [Careers](https://www.sirkit.ca/careers)
    - [Contact Us](https://www.sirkit.ca/contact)
- [Blog](https://www.sirkit.ca/blog)

Open main navigation

Close main navigation

- Show submenu for Services Services 
  
    - Services
    - [Managed IT](https://www.sirkit.ca/managed-it-services)
    - [Co-Managed IT](https://www.sirkit.ca/co-managed-it-services)
    - [Integrated IT Solutions](https://www.sirkit.ca/integrated-it-solutions)
- [Cybersecurity](https://www.sirkit.ca/cybersecurity)
- Show submenu for About Us About Us 
  
    - About Us
    - [About Us](https://www.sirkit.ca/about)
    - [Executive Team](https://www.sirkit.ca/about?#exec)
    - [Careers](https://www.sirkit.ca/careers)
    - [Contact Us](https://www.sirkit.ca/contact)
- [Blog](https://www.sirkit.ca/blog)
- [Get Started](https://www.sirkit.ca/contact)

[Get Started](https://www.sirkit.ca/contact)

Categories

- [Cyber-Security Advisories](https://www.sirkit.ca/blog/tag/cyber-security-advisories)
- [Technical Pro-tips and How-to](https://www.sirkit.ca/blog/tag/technical-pro-tips-and-how-to)
- [Knowledge Base (KB)](https://www.sirkit.ca/blog/tag/knowledge-base-kb)
- [SIRKit News](https://www.sirkit.ca/blog/tag/sirkit-news)
- [Product Reviews](https://www.sirkit.ca/blog/tag/product-reviews)
- [SIRKit360® News](https://www.sirkit.ca/blog/tag/sirkit360-news)

# A closer look at Evilginx and how MFA doesn’t protect against this modern phishing technique.

[Kris Wilkinson](https://www.sirkit.ca/blog/author/kris-wilkinson)

Mar 15, 2024

Staying ahead of cybersecurity threats is crucial, and one of the latest to emerge is [Evilginx](https://medium.com/@rencora/phishing-with-evilginx3-mfa-doesnt-stand-a-chance-961634c24bd9). This sophisticated phishing technique imposes significant risks even to the most secure accounts with MFA. This article explores what Evilginx is, the dangers it presents, and effective strategies for safeguarding yourself against this advanced phishing tool. The primary concern with Evilginx is its ability to circumvent 2FA, a security measure that has become a standard defence against unauthorized access.

## What is Evilginx?

Evilginx is the newest iteration in a series of advanced phishing tools that act as “man-in-the-middle” attackers. It intercepts communications between a user and legitimate websites, stealthily capturing login credentials and even bypassing two-factor authentication (2FA). This tool can mimic interactions with well-known platforms, making it challenging to detect and defend against. To truly grasp how Evilginx operates, it’s crucial to understand what a “token” is in the context of online authentication.

In simple terms, a token in online security is like a temporary digital key. When you log in to a website, even with two-factor authentication (2FA), the website generates a unique, one-time-use token. This token verifies that you’ve successfully passed the login challenge (like entering a correct password and a 2FA code). Instead of keeping your password and 2FA code active for the session, the website uses this token to remember that you’ve been authenticated. It’s a way to keep your session secure without constantly sending your sensitive information back and forth. This token is stored on your local computer.

By capturing session tokens (also known as cookies), Evilginx enables attackers to access accounts as if they were legitimate owners, leading to potential data breaches, identity theft, and financial loss. This tool’s effectiveness significantly raises the stakes in the ongoing battle against phishing attacks.

## **Example Attack Scenario**

Here’s a step-by-step breakdown of what happens during an Evilginx attack:

1. **Phishing Stage**: You receive an incredibly legitimate looking email directing you to log in to a website (say, Microsoft 365)  
   ![2024-03-15-11_51_47-Phishing-with-Evilginx3-—-MFA-doesnt-stand-a-chance-_-by-Rencora-_-Medium-and-5](https://www.sirkit.ca/hs-fs/hubfs/2024-03-15-11_51_47-Phishing-with-Evilginx3-%E2%80%94-MFA-doesnt-stand-a-chance-_-by-Rencora-_-Medium-and-5.png?width=563&height=377&name=2024-03-15-11_51_47-Phishing-with-Evilginx3-%E2%80%94-MFA-doesnt-stand-a-chance-_-by-Rencora-_-Medium-and-5.png) ![EvilGynx3](https://www.sirkit.ca/hs-fs/hubfs/Imported_Blog_Media/2024-03-15-11_51_47-Phishing-with-Evilginx3-%E2%80%94-MFA-doesnt-stand-a-chance-_-by-Rencora-_-Medium-and-5.png?width=632&height=423&name=2024-03-15-11_51_47-Phishing-with-Evilginx3-%E2%80%94-MFA-doesnt-stand-a-chance-_-by-Rencora-_-Medium-and-5.png)
2. **The Fake Login Page**: The link in the email redirects you to a malicious site that is almost a perfect replica of the real site. This site is delivered by Evilginx, sitting quietly between you and the actual service provider’s website.
3. **Data Interception**: When you enter your login credentials and 2FA code, Evilginx captures them. But it doesn’t stop there. It also intercepts the token issued by the real website once you’ve authenticated successfully.
4. **Session Hijacking**: With your credentials, 2FA code, and the token, the attacker can now access your account. The token is especially valuable because it grants them access without needing to re-enter the 2FA code, effectively bypassing this security measure.
5. **Unauthorized Access**: Armed with the token, the attacker can do anything from stealing personal information to making transactions, all while impersonating you.

## How to Safeguard Against Token Theft

Protecting yourself from such a nuanced threat involves a multifaceted approach:

- **Stay Skeptical**: Treat unexpected emails with caution, especially those prompting you to log in or verify your account details. 
    - Review the URL you are visiting:![2024-03-15-11_54_32-C__Users_kris.wilkinson_OneDrive-SIRKit-Ltd_Desktop_2024-03-15-11_51_47-Phishi](https://www.sirkit.ca/hs-fs/hubfs/2024-03-15-11_54_32-C__Users_kris.wilkinson_OneDrive-SIRKit-Ltd_Desktop_2024-03-15-11_51_47-Phishi.png?width=527&height=271&name=2024-03-15-11_54_32-C__Users_kris.wilkinson_OneDrive-SIRKit-Ltd_Desktop_2024-03-15-11_51_47-Phishi.png) ![EvilGynx3](https://www.sirkit.ca/hs-fs/hubfs/Imported_Blog_Media/2024-03-15-11_54_32-C__Users_kris_wilkinson_OneDrive-SIRKit-Ltd_Desktop_2024-03-15-11_51_47-Phishi.png?width=630&height=324&name=2024-03-15-11_54_32-C__Users_kris_wilkinson_OneDrive-SIRKit-Ltd_Desktop_2024-03-15-11_51_47-Phishi.png) https://login.microsoft.**phishingInc.com**/  
      Why? “phishingInc.com” is clearly NOT a Microsoft website.
    - Assume all links provided in e-mails are hostile. Visit the company’s website directly and use the URLs they provide on their own website (don’t use what’s included in the e-mail or text message).
    - Assume all attachments received from a third party or links within these attachments are hostile. Contact the sender to verify BEFORE you open anything.
    - For any large change requests sent by e-mail, especially billing related, call the other party to verify in case their mailbox was compromised
    - Use External Sender warnings to notify recipients that the sender is not from your team
    - Separate administrator accounts (admin@you.onmicrosoft.com) from operational accounts (john@yourdomain.com)
    - Were you expecting an email? Call the sender and ensure they meant to send it.
    - Ask your IT department to verify!

- **Use Cloud-Based Monitoring Tools**: Employ comprehensive security solutions that can detect abnormal behaviour in a cloud environment or help identify phishing attempts and malicious websites.
- **Educate Continuously**: Regularly test your team by sending phishing campaigns and monitoring the results. Train Train Train! Cybersecurity education can dramatically reduce the risk of falling for phishing schemes.

## Other Considerations

- Setting up and using Evilginx is very easy and doesn’t take a lot of time or experience. Therefore, all businesses of all sizes are at risk.
- Many vendors are potentially at risk including [Microsoft 365](https://www.sirkit.ca/microsoft-365-experts/), Google Workspace, Amazon, Netflix, LinkedIn, etc. Anyone online.

## In Conclusion

Evilginx showcases the sophistication of modern cyber threats, underlining the importance of being vigilant and informed. Understanding how your data, including tokens, can be compromised is the first step in fortifying your defences. By implementing robust security measures and fostering an environment of cybersecurity awareness, you can significantly reduce the risk of falling victim to such advanced phishing attacks.

Remember, in the digital realm, knowledge is not just power—it’s protection.

If you’d like to chat with us about our [Managed IT & Security Services](https://www.sirkit.ca/managed-it-services/), please [don’t hesitate to reach out](https://www.sirkit.ca/book-a-call/).

 

**Tags:** 

[Cyber-Security Advisories](https://www.sirkit.ca/blog/tag/cyber-security-advisories)

### Related Posts

##### [![What Is Agentic AI in Cybersecurity?](https://www.sirkit.ca/hs-fs/hubfs/AI-Generated%20Media/Images/Cybersecurity%20Operations%20Center%20with%20RealTime%20Data%20Displays-1.png?width=520&height=294&name=Cybersecurity%20Operations%20Center%20with%20RealTime%20Data%20Displays-1.png) Cyber-Security Advisories • May 22, 2026 What Is Agentic AI in Cybersecurity? 6 min read](https://www.sirkit.ca/blog/what-is-agentic-ai-in-cybersecurity)

##### [![What Does Cyber Insurance Cover](https://www.sirkit.ca/hs-fs/hubfs/Screenshot%202026-01-12%20at%203.11.49%20PM.png?width=520&height=294&name=Screenshot%202026-01-12%20at%203.11.49%20PM.png) Knowledge Base (KB) • Jan 12, 2026 What Does Cyber Insurance Cover 5 min read](https://www.sirkit.ca/blog/what-does-cyber-insurance-cover)

##### [![What is a vCIO? Do you Need One?](https://www.sirkit.ca/hs-fs/hubfs/scott-graham-5fNmWej4tAA-unsplash%20(1).jpg?width=520&height=294&name=scott-graham-5fNmWej4tAA-unsplash%20(1).jpg) Cyber-Security Advisories • Oct 9, 2025 What is a vCIO? Do you Need One? 2 min read](https://www.sirkit.ca/blog/what-is-vcio)

### Stay connected.

Join our newsletter to stay informed with the latest technology insights, market and business updates, and Sirkit news and events.

###### Categories

- [Cyber-Security Advisories](https://www.sirkit.ca/blog/tag/cyber-security-advisories)
- [Technical Pro-tips and How-to](https://www.sirkit.ca/blog/tag/technical-pro-tips-and-how-to)
- [Knowledge Base (KB)](https://www.sirkit.ca/blog/tag/knowledge-base-kb)
- [SIRKit News](https://www.sirkit.ca/blog/tag/sirkit-news)
- [Product Reviews](https://www.sirkit.ca/blog/tag/product-reviews)

###### Recent Posts

- [6 AI-Related Cybersecurity Risks Businesses Can’t Ignore](https://www.sirkit.ca/blog/ai-related-cyber-risks)
- [What Is Agentic AI in Cybersecurity?](https://www.sirkit.ca/blog/what-is-agentic-ai-in-cybersecurity)
- [AI Cyber Attacks: What Business Leaders Need to Understand Right Now](https://www.sirkit.ca/blog/ai-cyber-attacks-business-leaders)
- [Vulnerability Assessment vs Penetration Testing](https://www.sirkit.ca/blog/vulnerability-assessment-vs-penetration-testing)
- [Why MFA Alone Is No Longer Enough: How to Prevent Token Theft and AiTM Attacks](https://www.sirkit.ca/blog/prevent-token-theft)

[![Sirkit_Primary-Logo-White-RGB](https://www.sirkit.ca/hubfs/Sirkit_Primary-Logo-White-RGB.svg)](https://www.sirkit.ca)

[1-780-758-5200](tel:17807585200) (Support)

[1-587-404-9002](https://www.sirkit.ca/blog/15874049002) (Sales)

 Unit 217, 236 91 Street SW  
 Edmonton AB, T6X 1W8

- [Managed IT Services](https://www.sirkit.ca/managed-it-services)
- [Cybersecurity](https://www.sirkit.ca/cybersecurity)
- [About Us](https://www.sirkit.ca/about)
- [Contact Us](https://www.sirkit.ca/contact)

©2026 Sirkit. All rights reserved. [Privacy Policy](https://www.sirkit.ca/privacy-policy)  |  [Terms of Use](https://www.sirkit.ca/terms-of-use)  
Sirkit® is a registered trademark.

- <https://www.linkedin.com/company/sirkit/>
- <https://www.instagram.com/sirkit.ca/>
- <https://www.facebook.com/sirkitcanada/>

×

![Managed IT Services Cost eBook Download](https://www.sirkit.ca/hubfs/Sirkit%20Managed%20IT%20PDF%20popup.png)

×

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Kris Wilkinson",
    "url" : "https://www.sirkit.ca/blog/author/kris-wilkinson"
  },
  "dateModified" : "2025-05-14T18:24:04.628Z",
  "datePublished" : "2024-03-15T11:28:07.000Z",
  "headline" : "Evilginx: Modern Phishing and MFA Vulnerabilities | SIRKit",
  "image" : [ "https://www.sirkit.ca/hubfs/Imported_Blog_Media/Cyber-Security-Technician.jpg" ],
  "mainEntityOfPage" : {
    "@id" : "https://www.sirkit.ca/blog/a-closer-look-at-evilginx-and-how-mfa-doesnt-protect-against-this-modern-phishing-technique",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://www.sirkit.ca/hubfs/Logos/SirkitBadge%20(2).png"
    },
    "name" : "Sirkit"
  }
}
```