Reverse-proxy phishing can capture sessions after MFA
A post published on August 9, 2026 describes kits that relay login and MFA interactions with a real service to intercept the resulting session cookie. It cites Evilginx, Modlishka, and Muraena.
Published on August 9, 2026, the post describes a reverse-proxy phishing pattern: a kit relays the victim’s login and multifactor authentication (MFA) interaction to a real service, then intercepts the resulting session cookie. Examples cited include Evilginx, Modlishka, and Muraena.
The post says engineers can consider this attack pattern when designing anti-phishing defenses and authentication systems. To verify the account, consult the original post and check whether it names the same kits and describes cookie capture after the MFA interaction; the available summary does not specify defensive measures.