Email phishing techniques evolve every day. One particularly concerning threat is EvilGinx, a sophisticated advanced phishing attack, often termed "man-in-the-middle" or adversary-in-the-middle that we’re seeing Canadian business fall victim to. It's designed to bypass multifactor authentication (MFA) by capturing authentication tokens and session cookies in real time. Its ability to bypass MFA can result in unauthorized access to IT systems and compromised data, potentially leading to financial loss, reputational damage and legal consequences. Here’s a breakdown of how it works and its implications:
1. Man-in-the-Middle Phishing
2. Bypassing MFA
Step-by-Step Attack Scenario
What’s most significant about EvilGinx is that one does not have to be a security specialist to execute an attack. A simple demonstration is showcased in this video titled “I Stole a Microsoft 365 Account. Here’s How.” Watch the video here.
How to Defend Against EvilGinx
The best approach to cybersecurity is a multi-layered one that includes phishing resistant MFA, Managed Detection and Response, Security Awareness Training, conditional access policies and of course, a Managed Service Provider to implement these solutions to keep your business secure as the cyber threat landscape evolves.
Phishing Resistant MFA
Managed Detection and Response for Microsoft 365: Many Microsoft 365-reliant businesses are now adopting Managed Detection and Response (MDR) to protect all users, applications, and environments to detect and resolve email phishing attacks.
Awareness and Training: Educate users about the risks of phishing and teach them to recognize suspicious links and websites. A critical security best practice is to ensure employees don't click on links. If an email requests a login into Microsoft 365, only a known URL should be used to login. Always review the URL you are visiting.
Conditional Access Policies: Implement conditional access policies that mandate the use of compliant devices and adds an extra layer of security.
Managed Security Services: Managed Service Providers (MSP) provide organizations with the technological leadership and tools necessary to keep businesses secure today. An MSP can implement all the above noted modern security defenses to prevent man-in-the-middle attacks and, as threats evolve, an MSP will ensure you have the best defenses in place.
EvilGinx represents a sophisticated advancement in phishing techniques, demonstrating the importance of continuous security hardening to counteract evolving threats. Reach out to us to learn more about our Managed IT and Security Services.