WaterISAC Navigation
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
Home Posts Threat Awareness – Phishing Kits Allow Threat Actors to Bypass MFA
Become a Member

Log in

  • Upcoming Events
  • Resource Center
  • Tools
  • Webcasts
  • Contaminant Databases
  • Community Partners
  • About
  • Log in

  • My Account

  • Logout

  • Report Incident
  • Contact Us
  • NRWA Signup
  • WaterISAC Champions
More Resources

Threat Awareness – Phishing Kits Allow Threat Actors to Bypass MFA

Author: Alec Davison

Created: Tuesday, September 6, 2022 - 19:41

Categories: Cybersecurity

A reverse-proxy Phishing-as-a-Service (PaaS) toolkit, dubbed EvilProxy, is being advertised on cybercriminal marketplaces. EvilProxy provides threat actors with the means to bypass multi-factor authentication (MFA) on Apple, Google, Microsoft, and other prominent web applications. This specific PaaS toolkit utilizes a session hijacking proxy attack, where the threat actor sits in between the user and target website or application and are able to harvest authentication credentials. Like many exploit kits, EvilProxy offers its malicious customers a user-friendly GUI where attackers are provided detailed instructional videos and tutorials and the ability to manage phishing campaigns. This service could enable low-skill attackers the ability to target well defended organizations and potentially cause significant damage or disruption. For mitigation information including IOCs read more at HelpNetSecurity or read more at BleepingComputer.

Related Resources

(TLP:CLEAR) Vulnerability Notification – Critical Vulnerability in Fortinet EMS Actively Exploited, CVE-2026-35616

May 29, 2026 in Cybersecurity, Security Preparedness

(TLP:CLEAR) GAO Report: Actions Needed to Address Persistent Cybersecurity Threats to the Water and Wastewater Sector

May 28, 2026 in Cybersecurity, Federal & State Resources, OT-ICS Security

(TLP:CLEAR) FBI Releases Multiple Alerts on Credential Theft and Evolving Ransomware Intrusion Techniques

May 28, 2026 in Cybersecurity, Federal & State Resources, Security Preparedness

Become a Member
FAQs
About
Report Incident

Terms & Conditions
Privacy Policy
AI Policy
Contact Us

LinkedIn

1250 I Street NW, Suite 350
Washington, DC 20005
1-866-H2O-ISAC (1-866-426-4722)
© 2026 WaterISAC. All Rights Reserved.

Toggle the Widgetbar