Skip to content

Repository files navigation

Evilginx2 Logo

Evilginx2 Title

Evilginx 3.0

Evilginx is a man-in-the-middle attack framework used for phishing login credentials along with session cookies, which in turn allows to bypass 2-factor authentication protection.

This tool is a successor to Evilginx, released in 2017, which used a custom version of nginx HTTP server to provide man-in-the-middle functionality to act as a proxy between a browser and phished website. Present version is fully written in GO as a standalone application, which implements its own HTTP and DNS server, making it extremely easy to set up and use.

Screenshot

Disclaimer

I am very much aware that Evilginx can be used for nefarious purposes. This work is merely a demonstration of what adept attackers can do. It is the defender's responsibility to take such attacks into consideration and find ways to protect their users against this type of phishing attacks. Evilginx should be used only in legitimate penetration testing assignments with written permission from to-be-phished parties.

Fork extensions (Pro-style features)

This fork extends the Community Edition with Evilginx Pro-style capabilities. Everything below is a community reimplementation of documented Pro behavior, implemented against the open-source evilginx2 codebase — it is not the closed-source Evilginx Pro product.

Detection evasion

  • TLS fingerprint impersonation — config fingerprint <chrome|firefox|safari|ios|randomized> forges the upstream TLS ClientHello (JA3/JA4) via uTLS, defeating passive TLS fingerprinting. config fingerprint off disables it. Default: chrome.
  • HTTP/2 upstream — the proxy speaks HTTP/2 to targets that support it (matching real-browser protocol negotiation) with automatic HTTP/1.1 fallback. Combined with fingerprinting in a hybrid RoundTripper.
  • HTTP/2 client-side — config http2 <true|false> advertises h2 via ALPN so the browser negotiates HTTP/2 with evilginx itself (a real-browser signal); disabled by default.
  • Website spoofing — unauthorized visitors and blocked bots are served a reverse-proxied legitimate website (from unauth_url) in the context of the phishing domain, instead of a redirect or 403.
  • Botguard — passive bot/scanner detection combining User-Agent/header heuristics and IP request-velocity (distinct-path) analysis; flagged requests are served the spoofed website. Static assets and whitelisted/session IPs are exempt.
  • JavaScript obfuscation — config obfuscation javascript <off|low|medium|high|ultra> obfuscates injected JS with increasing strength (comment-strip → base64+eval → shuffled chunks → decoys).
  • HTML obfuscation — config obfuscation html <true|false> strips HTML comments and collapses inter-tag whitespace in proxied pages.
  • URL rewriting — config rewrite_urls <true|false> disguises phishing paths/query params in served HTML as /r/<token>, defeating Safe-Browsing/path-pattern fingerprinting. The rid tracking param is preserved.
  • Identifying-header stripping — removes Via, X-GoProxy, Proxy-Connection, and X-Forwarded-For.

Ops & automation

  • Event notifications — notify command (webhook, Slack, Pushover, or Telegram) emitting lure_landed, credential_captured, and session_captured events with a full JSON session schema (Chromium cookie format).
  • AES-256-GCM lure parameter encryption — config enc_key <key> encrypts custom lure parameters (PBKDF2-HMAC-SHA256 key derivation, per-value salt), replacing the legacy RC4 encoding.
  • External DNS providers + wildcard TLS — config dns_provider cloudflare enables DNS-01 challenges and wildcard *.domain certificates, keeping phishing subdomains out of Certificate Transparency logs. (Only Cloudflare is currently implemented; route53/gandi are recognized but not yet wired.)
  • DNS-over-HTTPS — config use_doh <true|false> (with config doh_url <url>) routes outbound target-hostname resolution through an encrypted DoH resolver, hiding the phishing targets from the ISP's DNS.
  • External IP auto-detection — config ipv4 external auto queries public "what is my IP" endpoints.
  • GoPhish extensions — config gophish submit_credentials <true|false> and config gophish hash_passwords <true|false> (SHA-256 of the password before it is sent to GoPhish).
  • SQLite storage — sessions persist in a pure-Go SQLite database (no CGO); legacy BuntDB files are migrated automatically.
  • Server naming & debug — config server_name <name> and config debug <true|false>.

Phishlet format

  • HJSON phishlets — .hjson (Phishlets-2.0-style relaxed JSON) files are supported alongside YAML.

New commands

config fingerprint <off|chrome|firefox|safari|ios|randomized>
config obfuscation javascript <off|low|medium|high|ultra>
config obfuscation html <true|false>
config rewrite_urls <true|false>
config enc_key <key>
config server_name <name>
config debug <true|false>
config ipv4 external auto
config dns provider <none|cloudflare|route53|gandi>
config dns token <token>      # provider API token (cloudflare)
config use_doh <true|false>   # DNS-over-HTTPS for outbound target resolution
config doh_url <url>          # DoH endpoint (default cloudflare-dns.com/dns-query)
config http2 <true|false>     # client-side HTTP/2 (browser -> evilginx)
config gophish submit_credentials <true|false>
config gophish hash_passwords <true|false>
notify                        # show current configuration
notify enable | disable | test
notify type <webhook|slack|pushover|telegram>
notify webhook <url>
notify slack <url>
notify pushover_user <key> | pushover_token <token>
notify telegram_token <bot_token> | telegram_chat <chat_id>

Evilginx Pro is now available!

This is it! After over two years of development, countless delays, and hundreds of manual company verifications, concluded with multiple hurdles related to export regulations, Evilginx Pro is finally live!

Evilginx Mastery

Evilginx Pro is the fruit of a passion I've had for a long time in developing offensive security tools for cybersecurity enthusiasts. The journey has just begun, and now that the product is officially released, I can focus on making it even better by implementing all the ideas I've planned for it.

Key features:

  • Out-of-the-box phishing detection evasion (including Chrome's Enchanced Browser Protection)
  • Tested and maintained official phishlets database
  • Botguard to prevent bot traffic by default (same concept as Cloudflare Turnstile)
  • Evilpuppet for advanced phishing capability (Google)
  • External DNS providers with multi-domain support
  • Website spoofing for unauthorized requests
  • JavaScript & HTML obfuscation
  • Wildcard TLS certificates
  • Automated server deployment
  • SQLite database support

Find out more on the official release blog post.

Evilginx Mastery Training Course

If you want everything about reverse proxy phishing with Evilginx - check out my Evilginx Mastery course!

Evilginx Mastery

Learn everything about the latest methods of phishing, using reverse proxying to bypass Multi-Factor Authentication. Learn to think like an attacker, during your red team engagements, and become the master of phishing with Evilginx.

Grab it here: https://academy.breakdev.org/evilginx-mastery

Official Gophish integration

If you'd like to use Gophish to send out phishing links compatible with Evilginx, please use the official Gophish integration with Evilginx 3.3. You can find the custom version here in the forked repository: Gophish with Evilginx integration

If you want to learn more about how to set it up, please follow the instructions in this blog post

Write-ups

If you want to learn more about reverse proxy phishing, I've published extensive blog posts about Evilginx here:

Evilginx 2.0 - Release

Evilginx 2.1 - First Update

Evilginx 2.2 - Jolly Winter Update

Evilginx 2.3 - Phisherman's Dream

Evilginx 2.4 - Gone Phishing

Evilginx 3.0

Evilginx 3.2

Evilginx 3.3

Help

In case you want to learn how to install and use Evilginx, please refer to online documentation available at:

https://help.evilginx.com

Support

I DO NOT offer support for providing or creating phishlets. I will also NOT help you with creation of your own phishlets. Please look for ready-to-use phishlets, provided by other people.

License

evilginx2 is made by Kuba Gretzky (@mrgretzky) and it's released under BSD-3 license.

About

Evilginx2 Community Edition (v3.3.0) extended with Evilginx Pro-style features: website spoofing, event notifications/webhooks, AES-256 lure params, JS obfuscation, botguard. For authorized red-team / phishing-simulation engagements.

Resources

Stars

1 star

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages