Evilginx is a man-in-the-middle attack framework used for phishing login credentials along with session cookies, which in turn allows to bypass 2-factor authentication protection.
This tool is a successor to Evilginx, released in 2017, which used a custom version of nginx HTTP server to provide man-in-the-middle functionality to act as a proxy between a browser and phished website. Present version is fully written in GO as a standalone application, which implements its own HTTP and DNS server, making it extremely easy to set up and use.
I am very much aware that Evilginx can be used for nefarious purposes. This work is merely a demonstration of what adept attackers can do. It is the defender's responsibility to take such attacks into consideration and find ways to protect their users against this type of phishing attacks. Evilginx should be used only in legitimate penetration testing assignments with written permission from to-be-phished parties.
This fork extends the Community Edition with Evilginx Pro-style capabilities. Everything below is a community reimplementation of documented Pro behavior, implemented against the open-source evilginx2 codebase — it is not the closed-source Evilginx Pro product.
- TLS fingerprint impersonation —
config fingerprint <chrome|firefox|safari|ios|randomized>forges the upstream TLS ClientHello (JA3/JA4) via uTLS, defeating passive TLS fingerprinting.config fingerprint offdisables it. Default:chrome. - HTTP/2 upstream — the proxy speaks HTTP/2 to targets that support it (matching real-browser protocol negotiation) with automatic HTTP/1.1 fallback. Combined with fingerprinting in a hybrid RoundTripper.
- HTTP/2 client-side —
config http2 <true|false>advertisesh2via ALPN so the browser negotiates HTTP/2 with evilginx itself (a real-browser signal); disabled by default. - Website spoofing — unauthorized visitors and blocked bots are served a reverse-proxied legitimate website (from
unauth_url) in the context of the phishing domain, instead of a redirect or403. - Botguard — passive bot/scanner detection combining User-Agent/header heuristics and IP request-velocity (distinct-path) analysis; flagged requests are served the spoofed website. Static assets and whitelisted/session IPs are exempt.
- JavaScript obfuscation —
config obfuscation javascript <off|low|medium|high|ultra>obfuscates injected JS with increasing strength (comment-strip → base64+eval → shuffled chunks → decoys). - HTML obfuscation —
config obfuscation html <true|false>strips HTML comments and collapses inter-tag whitespace in proxied pages. - URL rewriting —
config rewrite_urls <true|false>disguises phishing paths/query params in served HTML as/r/<token>, defeating Safe-Browsing/path-pattern fingerprinting. Theridtracking param is preserved. - Identifying-header stripping — removes
Via,X-GoProxy,Proxy-Connection, andX-Forwarded-For.
- Event notifications —
notifycommand (webhook, Slack, Pushover, or Telegram) emittinglure_landed,credential_captured, andsession_capturedevents with a full JSON session schema (Chromium cookie format). - AES-256-GCM lure parameter encryption —
config enc_key <key>encrypts custom lure parameters (PBKDF2-HMAC-SHA256 key derivation, per-value salt), replacing the legacy RC4 encoding. - External DNS providers + wildcard TLS —
config dns_provider cloudflareenables DNS-01 challenges and wildcard*.domaincertificates, keeping phishing subdomains out of Certificate Transparency logs. (Only Cloudflare is currently implemented;route53/gandiare recognized but not yet wired.) - DNS-over-HTTPS —
config use_doh <true|false>(withconfig doh_url <url>) routes outbound target-hostname resolution through an encrypted DoH resolver, hiding the phishing targets from the ISP's DNS. - External IP auto-detection —
config ipv4 external autoqueries public "what is my IP" endpoints. - GoPhish extensions —
config gophish submit_credentials <true|false>andconfig gophish hash_passwords <true|false>(SHA-256 of the password before it is sent to GoPhish). - SQLite storage — sessions persist in a pure-Go SQLite database (no CGO); legacy BuntDB files are migrated automatically.
- Server naming & debug —
config server_name <name>andconfig debug <true|false>.
- HJSON phishlets —
.hjson(Phishlets-2.0-style relaxed JSON) files are supported alongside YAML.
config fingerprint <off|chrome|firefox|safari|ios|randomized>
config obfuscation javascript <off|low|medium|high|ultra>
config obfuscation html <true|false>
config rewrite_urls <true|false>
config enc_key <key>
config server_name <name>
config debug <true|false>
config ipv4 external auto
config dns provider <none|cloudflare|route53|gandi>
config dns token <token> # provider API token (cloudflare)
config use_doh <true|false> # DNS-over-HTTPS for outbound target resolution
config doh_url <url> # DoH endpoint (default cloudflare-dns.com/dns-query)
config http2 <true|false> # client-side HTTP/2 (browser -> evilginx)
config gophish submit_credentials <true|false>
config gophish hash_passwords <true|false>
notify # show current configuration
notify enable | disable | test
notify type <webhook|slack|pushover|telegram>
notify webhook <url>
notify slack <url>
notify pushover_user <key> | pushover_token <token>
notify telegram_token <bot_token> | telegram_chat <chat_id>
This is it! After over two years of development, countless delays, and hundreds of manual company verifications, concluded with multiple hurdles related to export regulations, Evilginx Pro is finally live!
Evilginx Pro is the fruit of a passion I've had for a long time in developing offensive security tools for cybersecurity enthusiasts. The journey has just begun, and now that the product is officially released, I can focus on making it even better by implementing all the ideas I've planned for it.
- Out-of-the-box phishing detection evasion (including Chrome's Enchanced Browser Protection)
- Tested and maintained official phishlets database
- Botguard to prevent bot traffic by default (same concept as Cloudflare Turnstile)
- Evilpuppet for advanced phishing capability (Google)
- External DNS providers with multi-domain support
- Website spoofing for unauthorized requests
- JavaScript & HTML obfuscation
- Wildcard TLS certificates
- Automated server deployment
- SQLite database support
Find out more on the official release blog post.
If you want everything about reverse proxy phishing with Evilginx - check out my Evilginx Mastery course!
Learn everything about the latest methods of phishing, using reverse proxying to bypass Multi-Factor Authentication. Learn to think like an attacker, during your red team engagements, and become the master of phishing with Evilginx.
Grab it here: https://academy.breakdev.org/evilginx-mastery
If you'd like to use Gophish to send out phishing links compatible with Evilginx, please use the official Gophish integration with Evilginx 3.3. You can find the custom version here in the forked repository: Gophish with Evilginx integration
If you want to learn more about how to set it up, please follow the instructions in this blog post
If you want to learn more about reverse proxy phishing, I've published extensive blog posts about Evilginx here:
Evilginx 2.2 - Jolly Winter Update
Evilginx 2.3 - Phisherman's Dream
In case you want to learn how to install and use Evilginx, please refer to online documentation available at:
I DO NOT offer support for providing or creating phishlets. I will also NOT help you with creation of your own phishlets. Please look for ready-to-use phishlets, provided by other people.
evilginx2 is made by Kuba Gretzky (@mrgretzky) and it's released under BSD-3 license.




