Back to Insights Phishing

Approximately one million euros were transferred to hackers who employed a sophisticated phishing attack.

Client Case Study: Sophisticated Phishing for Session Hijacking and Overcoming Two-Factor Authentication (2FA)

How an attacker bypassed organizational defenses to execute a Man-in-the-Middle attack using Evilginx

During a recent cybersecurity incident, an attacker successfully bypassed users’ Two-Factor Authentication (2FA), hijacked their login sessions, and performed actions as the users within organizational systems. The attack was carried out using a tool called Evilginx, which mimics the organization’s login page, captures login credentials and 2FA codes, and ultimately intercepts the resulting session cookies. This tool provides the attacker with direct access to organizational accounts, including critical mailboxes. This exploitation led to the leak of sensitive information and a significant financial loss estimated at hundreds of thousands of dollars.

Understanding the Sophisticated Phishing Attack

What is Evilginx and how does it exploit user sessions via MitM attacks?

Evilginx is a sophisticated tool that allows attackers to hijack sessions while bypassing Two-Factor Authentication. The attack is executed by creating a phishing site that impersonates the legitimate site, to which users are redirected without their knowledge. When a user attempts to log in, Evilginx performs a Man-in-the-Middle (MitM) attack, routing login requests through the attacker’s server. This allows the attacker to harvest the username, password, and 2FA tokens, thereby storing the user’s credentials and session cookies. Subsequently, the attacker can use these session cookies to access the user’s account without requiring a password or further authentication.

Attack Stages: Session Hijacking via Evilginx

How Evilginx executes the process from login to session acquisition:

  1. Creating a Fake Site: The attacker creates a webpage that looks identical to the legitimate page of a critical service—such as a bank, email provider, or social network. The URL is similar but slightly different, such as “microsoft-login.com” instead of “microsoft.com”.
  2. Luring the User: The attacker sends a link leading to the fake page via email or SMS. The link often appears legitimate, accompanied by a message requesting the user to log in for a specific reason.
  3. The Fake Site as a “Proxy”: When the user enters their username, password, and even the authentication code received on their phone, the fake site forwards all these details to the real site. Because everything passes through the fake site, the victim notices nothing unusual.
  4. Stealing Session Cookies: At the end of the login process, the fake site captures the session cookies—the identifiers issued by the real site to maintain a continuous connection. These cookies allow the user to remain logged in without re-entering credentials.
  5. Using Cookies to Access the Account: With the session cookies in hand, attackers can access the real site and log in as the victim without needing a password or 2FA code. It functions like a “spare key” to the account until the victim logs out or performs an account reset.

Case Study: Mailbox Takeover Used to Transfer Hundreds of Thousands of Dollars

How an attacker bypassed Microsoft 365 2FA and requested a bank account change for an organizational client.

In the specific case we investigated, it was found that the attacker set up an Evilginx server and created a phishing page impersonating the Microsoft 365 login screen. A link to this page was sent to several employees, exploiting an Open Redirect vulnerability recently found on the `Google.com` domain. For example, a link appearing to belong to Google could redirect a user to a malicious site.

Once an employee clicked the link, they were redirected to the phishing site, and the attacker’s Evilginx server successfully captured an active session cookie. Forensic analysis revealed that the organization’s Microsoft 365 session policies were configured to “never expire.” Consequently, the attacker gained access to an employee’s account with mailbox permissions without needing to type a password or provide a 2FA token.

After gaining control of the mailbox, the attacker emailed the company’s clients requesting they change the bank account used for service payments to an account owned by the attacker. To prevent the actual employee from seeing incoming replies, the attacker created a new Inbox Rule directing all emails regarding “receipts” or “payments” to the RSS Feeds folder—a default folder rarely used by users—effectively hiding the correspondence.

One client complied with the fraudulent email request and updated the destination account, resulting in the transfer of hundreds of thousands of dollars to the attacker’s account without any further verification from the company.

Insights from Senior Cybersecurity Experts at IPV Security

To prevent similar scenarios, we recommend organizations implement the following steps:

  • Bank Account Change Procedures: Establish a mandatory policy, signed by vendors and clients, requiring that any change to bank details must include a voice verification call and a formal account confirmation document from the bank.
  • Device-Based Authentication: Consider using hardware-based solutions such as FIDO2 or device-based tokens that physically authenticate the user and do not rely solely on intercepted codes.
  • Session Lifetime Limits: Limit the duration of active sessions when connecting to organizational applications.
  • Conditional Access Policies: Configure Conditional Access mechanisms to allow logins only from relevant countries or specific IP addresses, and set alerts for logins from new IP addresses.
  • Behavioral Detection: Implement security mechanisms based on behavioral patterns to identify anomalous activities and provide real-time alerts.
  • Employee Awareness Training: Conduct quarterly phishing simulations and training sessions to recognize phishing sites and increase vigilance regarding potential risks.
  • Blocking Suspicious Sites: Implement DNS-based filtering and access control systems to block access to unverified sites that may be used for phishing.

Summary

The described incident highlights the vulnerability of Two-Factor Authentication when it relies solely on transmitted tokens. Attackers can bypass these defenses using tools like Evilginx to perform sophisticated session cookie hijacking. Implementing advanced, proactive security measures and frequent employee awareness training can reduce the risk and prevent such breaches.

**Interested in phishing simulations and lectures to increase organizational cybersecurity awareness? *

Continue the Conversation

Facing a cybersecurity challenge? Let's talk about how a managed program can strengthen your resilience.

Start a conversation