Skip to content
← LibraryTechnique entry
PH-AITM-EVILGINXInitial Access

AITM Phishing — Evilginx / Modlishka

Reverse-proxy phishing kit intercepts the entire auth flow including MFA challenge; harvests the post-auth session cookie.

§ Where this technique fits

PH-AITM-EVILGINX is catalogued under the Initial Access tactic of the offensive-security kill-chain. It appears in 9 approved dossiers in the registry, typically at step 2.8 on average.

§ Dossiers chaining this technique

§ What commonly comes next

  1. 01
    Steal Web Session Cookie
    T1539 · Credential Access
    seen 3×
  2. 02
    Phishing
    T1566 · Initial Access
    seen 2×
  3. 03
    Cloudflare Worker / Edge Function Compromise
    CDN-WORKER-COMPROMISE · Initial Access
    seen 1×
  4. 04
    Exchange Web Services (EWS) Exfil
    M365-EWS-EXFIL · Collection
    seen 1×
  5. 05
    Valid Accounts
    T1078 · Initial Access
    seen 1×