Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now

EvilProxy

6
Global rank
47 infographic chevron month
Month rank
42 infographic chevron week
Week rank

EvilProxy is a phishing-as-a-service (PhaaS) platform that enables cybercriminals to bypass multi-factor authentication (MFA) and hijack user sessions. It leverages reverse proxy techniques to harvest credentials and session cookies, posing a serious threat to both individuals and enterprises.

Phishingkit
Type
Unknown
Origin
1 August, 2022
First seen
7 October, 2026
Last seen

How to analyze EvilProxy with ANY.RUN

Type
Unknown
Origin
1 August, 2022
First seen
7 October, 2026
Last seen

IOCs

IP addresses
48.209.138.168
74.179.77.204
150.171.28.11
23.207.210.146
184.24.77.17
150.171.27.11
104.18.22.222
150.171.109.100
35.190.80.1
23.11.41.157
20.190.160.65
23.52.181.212
172.211.123.250
92.123.104.54
150.171.22.17
150.171.109.98
131.253.33.203
23.52.181.141
92.123.104.36
48.192.1.65
Hashes
8232c450f967d7f2f22c54582f0667f4c033ae62e6d450ff8a35c47486249443
0cf098dfe5bbb46fc0132b3cf0c54b06b4d2c8390d847ee2a65d20f9b7480f4c
9b32c491d0bfebdca1455f73c3c6f71796d433a39818c06c353da588de650f81
2824cf97513dc3ecc261f378bfd595ae95a5997e9d1c63f5731a58b1f8cd54f9
64e01bc292ba2ea1699576fcc445367047520ee895e290ccee20c24c9336d8ef
2445cad863be47bb1c15b57a4960b7b0d01864e63cdfde6395f3b2689dc1444b
ff702ca753a7e3b75f9d9850cc9343e28e8d60f8005a2c955c8ac2105532b2c9
af889c1deb6f9248961c2f8ba4307a8206d7163616a5b7455d17cead00068317
728d8cbd71263680a4e41399db65b3f2b8175d50ca630afd30643ced9ffe831f
22bc37b47ce8a832f39701641dc358357676e9be187a93a4c5d4b016e29238ae
cc3e9077fcc9bd0dfc5dd3924c6c48b8345f32cee24fccc508c279f45b2abe61
14895bf43ce9b76c0ff4f9aef93dbe8bb6ca496894870cf0c007b189e0cef00e
7ccc7b17bfe01c3c7dd33eff8f80d0b57fc9b175815e766c9c1c1e893725e20f
6c69ce0fe6fab14f1990a320d704fee362c175c00eb6c9224aa6f41108918ca6
5f4229d18e5606330146ee13bdf726e10c1e06cbb15368c47f1ae68abe9ce4ba
ec78ddd4ccf32b5d76ec701a20167c3fbd146d79a505e4fb0421fc1e5cf4aa63
41ce6a7b18364efecced0419b42165d4f86c43643bbe1043014d4142cf86186a
57f81a5fcbd1fefd6ec3cdd525a85b707b4eead532c1b3092daafd88ee9268ec
89082fb05229826bc222f5d22c158235f025f0e6df67ff135a18bd899e13bb8f
e848603b7a73a88e3fe7bffa20e83397f5d1e93e77babb31473cc99e654a27b7
Domains
go.microsoft.com
static.edge.microsoftapp.net
ocsp.digicert.com
api.edgeoffer.microsoft.com
fe3cr.delivery.mp.microsoft.com
oneocsp.microsoft.com
login.live.com
update.googleapis.com
copilot.microsoft.com
clients2.googleusercontent.com
edge-cloud-resource-static.azureedge.net
edge-mobile-static.azureedge.net
edge.microsoft.com
config.edge.skype.com
slscr.update.microsoft.com
www.bing.com
a.nel.cloudflare.com
zpibbbil.webmarketing-seo.info
edge-consumer-static.azureedge.net
client.wns.windows.com
URLs
http://ocsp.digicert.com/mfewtzbnmeswstajbgurdgmcgguabbtrjrydryt%2bapf3gspypfhbxr5xtqqus9tippmhxdiunkhmewnpyim8s8yceajtxtab8my1oj8mfwpz%2f7y%3d
http://oneocsp.microsoft.com/ocsp/mfqwujbqme4wtdajbgurdgmcgguabbq3l3%2f%2fa6adk8nray2gxzvayrhg4aqub6t%2b2v%2bxq3lso2d33ojhnyhhqoucezmaaaafuwohyjguzpcaaaaaaau%3d
http://crl.microsoft.com/pki/crl/products/microoceraut2011_2011_03_22.crl
http://edge.microsoft.com/browsernetworktime/time/1/current?cup2key=2:0nhs5pv9mqj0s0ydvsfmtsqnjg6y6kmslx_ahukdxvs&cup2hreq=e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
https://config.edge.skype.com/config/v1/edge/133.0.3065.92?clientid=4489578223053569932&agents=edge%2cedgeconfig%2cedgeservices%2cedgefirstrun%2cedgefirstrunconfig&osname=win&client=edge&channel=stable&scpfre=0&osarch=x86_64&osver=10.0.19045&wu=1&devicefamily=desktop&uma=0&sessionid=72&mngd=0&installdate=1661339457&edu=0&soobedate=1504771245&bphint=2&fg=1&lbfgdate=1791395527&lafgdate=0
https://edge.microsoft.com/serviceexperimentation/v3/?osname=win&channel=stable&osver=10.0.19045&devicefamily=desktop&installdate=1661339457&clientversion=133.0.3065.92&experimentationmode=2&scpguard=0&scpfull=0&scpver=0
https://copilot.microsoft.com/c/api/user/eligibility
https://api.edgeoffer.microsoft.com/edgeoffer/pb/experiments?appid=edge-extensions&country=us
https://config.edge.skype.com/config/v1/edge/133.0.3065.92?clientid=4489578223053569932&agents=edgeruntime%2cedgeruntimeconfig%2cedgedomainactions&osname=win&client=edge&channel=stable&scpfre=0&osarch=x86_64&osver=10.0.19045&wu=1&devicefamily=desktop&uma=0&sessionid=72&mngd=0&installdate=1661339457&edu=0&soobedate=1504771245&bphint=2&fg=1&lbfgdate=1791395527&lafgdate=0
https://www.bing.com/api/shopping/v1/user/shoppingsettings?enabledservicefeaturesv2=edgeserverux.shopping.cashbackeumarkets,edgeserverux.shopping.msedgeshoppingcashbackdismisstimeout2s
https://edge.microsoft.com/extensionwebstorebase/v1/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=edgecrx&prodchannel=&prodversion=133.0.3065.92&lang=en-us&acceptformat=crx3,puff&x=id%3djmjflgjpcpepeafmmgdpfkogkghcpiha%26v%3d1.2.1%26installedby%3dother%26uc%26ping%3dr%253d292%2526e%253d1
https://edge.microsoft.com/entityextractiontemplates/api/v1/assets/find-assets?name=arbitration_priority_list&version=24.*.*&channel=stable&key=d414dd4f9db345fa8003e32adc81b362
https://edge.microsoft.com/entityextractiontemplates/api/v1/assets/find-assets?name=edge_hub_apps_manifest_gz&version=4.11.*&channel=stable&key=d414dd4f9db345fa8003e32adc81b362
https://edge.microsoft.com/entityextractiontemplates/api/v1/assets/find-assets?name=domains_config_gz&version=3.*.*&channel=stable&key=d414dd4f9db345fa8003e32adc81b362
https://update.googleapis.com/service/update2/json?cup2key=14:aav84bx_kkefxmkc2tagma28utmbbqamztbgond8fj4&cup2hreq=41db12deba724ffb5f4f1b639a8604b1da966bc8590f35c12acfd18b91d814d6
https://clients2.googleusercontent.com/crx/blobs/azpvhcqildrgqxyclcenwovmaua7lwu2mln7dephdl7eqkp9gczqmiehkjncu7a_eigr4ip8elijgyg1mgbqewwsojngu_j8zva9cfi_aj--ikwjbypwnpfv9nmzws17bigaxlka5c7tdptpcgaddf44n1nzr3cqv7qk/ghbmnnjooekpmoecnnnilnnbdlolhkhi_1_110_1_0.crx
https://edge.microsoft.com/abusiveadblocking/api/v1/blocklist
http://ocsp.digicert.com/mfewtzbnmeswstajbgurdgmcgguabbq50otx%2fh0ztl%2bz8sipi7wewvxdlqqutijuibiv5unu5g%2f6%2brks7qyxjzkceaz1vqyrvgl0erhqlcpm8gy%3d
https://th.bing.com/th?id=odswg.iotdlocalicon&w=16&h=16&c=1&rs=1&p=0
https://login.live.com/rst2.srf
Last Seen at

Recent blog posts

post image
5 Critical Pain Points of Modern US SOCs and...
watchers 2720
comments 0
post image
IronChain Ransomware Threatens Businesses wit...
watchers 4259
comments 0
post image
Threat Coverage Digest: New Malware Reports a...
watchers 11807
comments 0

What is EvilProxy malware?

EvilProxy is a reverse-proxy phishing kit sold on dark-web marketplaces that has been active since mid-2022. The platform operates as a commercial service with subscription-based offerings for 10, 20, and 31 days. This advanced toolkit has fundamentally changed how cybercriminals conduct phishing attacks by providing even low-skilled threat actors with the capability to bypass multi-factor authentication (MFA) protections.

The toolkit got notorious for letting attackers create convincing replicas of legitimate websites while maintaining real-time communication with the authentic service. This reverse-proxy architecture allows EvilProxy to intercept and manipulate communications between victims and legitimate services without detection. The service targets major platforms including Apple, Google, Facebook, Microsoft, Twitter, GitHub, GoDaddy, and even niche platforms like PyPI.

What sets EvilProxy apart from traditional phishing kits is its sophisticated evasion capabilities. The platform incorporates advanced detection mechanisms to identify security researchers, automated analysis systems, and virtual machines. When suspicious activity is detected, EvilProxy can redirect connections to legitimate websites or completely drop connections to avoid analysis.

Similar to other phishkits like Tycoon 2FA and Sneaky2FA, EvilProxy primarily relies on phishing as its initial infection vector. Phishing emails impersonating legitimate organizations or services are the most common method. These emails often contain urgent requests, security alerts, or enticing offers to trick recipients into clicking malicious links.

The links can be disguised through URL shorteners, legitimate-looking domain names, or by embedding them within seemingly harmless attachments (e.g., HTML files). Attackers heavily leverage social engineering tactics to manipulate victims.

Once an account is compromised via EvilProxy, the attackers can use it to send out more phishing emails to the victim's contacts, leading to a chain reaction of compromises within an organization or its network.

Get started today for free

Analyze malware and phishing in a fully-interactive sandbox

Create free account

What EvilProxy Can Do to User Device

When a user visits an EvilProxy-hosted phishing page, the malicious service:

  • Captures login credentials entered by the user in real-time.
  • Harvests session cookies and authentication tokens automatically.
  • Bypasses device-based security measures by operating at the application layer.
  • Maintains persistent access through stolen session tokens, even after the initial interaction.
  • Installs secondary malware may follow once initial access is obtained.
  • Can potentially access stored passwords and autofill data if users interact with the fraudulent interface.

The endpoint device itself may not show traditional signs of infection, making EvilProxy attacks particularly insidious. Users may notice unusual login notifications or unexpected account activity, but the device's security software typically cannot detect the attack since no malicious code is installed locally.

How EvilProxy Threatens Businesses and Organizations

EvilProxy poses severe threats to businesses and organizations across multiple dimensions:

  • Executive Targeting: Threat actors are increasingly using toolkits like EvilProxy to pull off account takeover attacks aimed at high-ranking executives at prominent companies. This can lead to business email compromise (BEC) attacks, fraudulent financial transactions, and corporate espionage.
  • Scale of Operations: Security researchers have observed that EvilProxy facilitates over one million attacks monthly, indicating the massive scale of potential exposure for organizations worldwide.
  • Multi-Factor Authentication Bypass: The service's ability to harvest session cookies thereby bypassing non-phishing resistant MFA means that even organizations with robust security policies may be vulnerable.
  • Data Exfiltration: Once inside, attackers can access confidential files, source code, or customer records.
  • Lateral Movement: Access to one account can help escalate privileges or compromise other users.
  • Reputational Damage and Compliance Violations: Especially in industries with strict data regulations.
  • Supply Chain Risks: By targeting platforms like GitHub and PyPI, EvilProxy can potentially compromise software development pipelines and create supply chain vulnerabilities.
  • Financial Impact: Successful account takeovers can lead to direct financial losses through fraudulent transactions, regulatory compliance violations, data breach costs, and reputation damage.

Use ANY.RUN free for 14 days

Try the full power of interactive analysis

Start your free trial

How Does EvilProxy Function?

EvilProxy operates through a reverse-proxy architecture that works as an intermediary between victims and legitimate services. The operation involves several key components:

  1. Reverse Proxy Technology: Actors use the kit to proxy victim's session, which means, EvilProxy creates a transparent tunnel between the victim and the real service.
  2. Real-Time Credential Harvesting: When users enter credentials on the phishing page, EvilProxy simultaneously submits these credentials to the legitimate service, capturing the resulting authentication tokens and session cookies.
  3. Session Token Theft: The service intercepts and stores session tokens generated during the authentication process, allowing attackers to maintain access even after the initial phishing interaction concludes.
  4. Anti-Detection Measures: EvilProxy incorporates an advanced fingerprinting technology to detect security researchers, automated analysis tools, and virtual machines. The bad actors are especially diligent when it comes to detecting possible virtual machines, typically used by security analysts to research malicious content.
  5. Dynamic Content Delivery: The PhaaS can serve different content based on the victim's location, device type, and other characteristics to maximize the success rate of attacks.

EvilProxy Attack Chain Live

ANY.RUN’s Interactive Sandbox contains thousands of EvilProxy samples that can be found with the aid of ANY.RUN’s Threat Intelligence Lookup:

threatName:"evilproxy"

EvilProxy malware samples found via TI Lookup EvilProxy malware samples found via Threat Intelligence Lookup

You can choose a freshly submitted analysis session and view EvilProxy in action along with its network connections, process details, attackers’ TTPs, and IOCs extracted from the malware’s configuration.

Watch an analysis session of EvilProxy fresh sample

EvilProxy analysis in Interactive Sandbox EvilProxy attack analysis in ANY.RUN Interactive Sandbox

The execution chain of the EvilProxy phishing kit begins when a victim receives a phishing email that appears to originate from a trusted service or brand, such as DocuSign, Adobe, Concur, or another legitimate-looking website. These emails often contain a malicious link that exploits an open redirect vulnerability on a legitimate domain, allowing attackers to bypass email security filters and avoid detection.

When the victim clicks the link, they are redirected through several legitimate websites before landing on a phishing page that impersonates a genuine login portal—typically Microsoft 365 or a similar service. In one observed task, the lure involved a fake voicemail message that prompted the user to enter their email address, after which they were redirected to a counterfeit Microsoft login page. Another case involved a fake "Secure Vault" prompt.

View another analysis session of EvilProxy

EvilProxy analysis in Interactive Sandbox EvilProxy attack abusing Secure Vault

The phishing pages are powered by the EvilProxy framework, which acts as a reverse proxy. It fetches live content from the real login page and displays it to the victim, making the phishing site look legitimate. As the victim enters their username, password, and two-factor authentication (2FA) code, EvilProxy intercepts these credentials in real time. The stolen credentials and 2FA tokens are immediately used on the attacker’s side to generate a valid session cookie, effectively bypassing MFA protections.

The attacker hijacks the session by proxying the victim’s traffic, allowing them to impersonate the victim and access the legitimate service without needing to re-enter credentials or 2FA tokens. This enables persistent access to the account. To evade detection, EvilProxy employs techniques such as browser fingerprinting, IP reputation checks, and filtering out connections from security researchers, bots, VPNs, proxies, Tor nodes, and virtual machines.

ANY.RUN’s Residential Proxy feature in the Sandbox helps users mask their traffic to appear as if it originates from real consumer devices rather than hosting environments, enabling full observation of the phishing attack chain without being blocked.

EvilProxy analysis in Interactive Sandbox Set up Residential Proxy when starting a new analysis in Interactive Sandbox

Gathering Threat Intelligence on EvilProxy malware

Threat intelligence provides actionable data for proactively defending against EvilProxy and the like.

ANY.RUN’s Threat Intelligence Lookup supports quick IOC checks for immediate verdicts but also allows deep research that brings understanding of malware’s behaviors, architecture, and tactics.

Extract IOCs from Sandbox analyses and explore them further via Threat Intelligence Lookup:

domainName:"*msftdocs.com"

EvilProxy domains in TI Lookup Search for EvilProxy-associated domain IOCs by pattern

Threat intelligence empowers defenders to:

  • Identify and block EvilProxy domains and IPs in near real-time.
  • Gather IOCs related to active EvilProxy campaigns.
  • Analyze infrastructures associated with EvilProxy operators.
  • Track adversary tactics, techniques, and procedures (TTPs) to preemptively defend against evolving campaigns.
  • With TI feeds, SOC teams can enrich alerts, prioritize responses, and reduce false positives.

Integrate ANY.RUN’s threat intelligence solutions in your company

Contact us

Conclusion

EvilProxy is a powerful weapon in the phishing landscape, offering a turnkey solution for bypassing MFA and hijacking sessions. It demonstrates the growing professionalization of cybercrime and underscores the urgent need for organizations to upgrade their defenses. Traditional security measures are no longer enough—organizations must adopt phishing-resistant MFA, leverage threat intelligence, and continually train users to recognize the signs of these highly convincing attacks.

Gather actionable intelligence via ANY.RUN’s TI Lookup: start with 50 trial requests.

HAVE A LOOK AT

Agent Tesla screenshot
Agent Tesla
agenttesla trojan rat stealer
Agent Tesla is spyware that collects information about the actions of its victims by recording keystrokes and user interactions. It is falsely marketed as a legitimate software on the dedicated website where this malware is sold.
Read More
Ransomware screenshot
Ransomware
ransomware
Ransomware is a type of malicious software that locks users out of their system or data using different methods to force them to pay a ransom. Most often, such programs encrypt files on an infected machine and demand a fee to be paid in exchange for the decryption key. Additionally, such programs can be used to steal sensitive information from the compromised computer and even conduct DDoS attacks against affected organizations to pressure them into paying.
Read More
Bluesky Ransomware screenshot
BlueSky ransomware, first identified in June 2022, shares code similarities with other well-known ransomware families like Conti and Babuk. It primarily spreads via phishing emails and malicious links and can propagate through networks using SMB protocols. BlueSky uses advanced evasion techniques, such as hiding its processes from debuggers via the NtSetInformationThread API, making it difficult for analysts to detect and mitigate its attacks.
Read More
Tykit screenshot
Tykit
tykit
Tykit is a sophisticated phishing-as-a-service (PhaaS) kit that emerged in May 2025, designed to steal Microsoft 365 corporate credentials through an innovative attack vector: malicious SVG files.
Read More
Akira Ransomware screenshot
Akira Ransomware emerged in March 2023 and compromised over 250 organizations by January 2024 with approximately $42 million in ransom payments. It employs double extortion tactics exfiltrating data before encryption and threatening to publish it on a dedicated website.
Read More
Arechclient2 screenshot
Arechclient2
arechclient2
The Arechclient2 malware is a sophisticated .NET-based Remote Access Trojan (RAT) that collects sensitive information, such as browser credentials, from infected computers. It employs various stealth techniques, including Base64 encoding to obscure its code and the ability to pause activities to evade automated security tools. The malware also can adjust Windows Defender settings and uses code injection to manipulate legitimate processes.
Read More