Since Evilginx was invented in 2017, phishing attacks using this method have increased significantly. Before that, phishing was simpler, attackers would create a mimic page that requested a username and password, which was then forwarded to the attacker’s server
However, with the introduction and widespread enforcement of multi-factor authentication (MFA), the use of reverse proxies for phishing has grown. Tools like EvilGinx, GoPhish, and PhishyFish have become some of the most commonly used platforms for phishing. Although these tools were originally intended for phishing simulations and security awareness training, many attackers have exploited them unethically, leading to numerous phishing campaigns targeting corporations and individuals
In response, security products have developed methods to detect and block these attacks by identifying phishing sites based on specific criteria
In this blog series, we highlight the new techniques attackers use to conceal their phishing websites and evade detection