ojo con esto, da igual que tengas 2FA. El Evilginx(entre muchos otros) tiene para instagram. Configurarlo es medio complicado, pero una vez que lo tienes...
Phishing 2.0
Phishing
2.0 makes all of these mitigations obsolete. Phishing 2.0 is a far more sophisticated, far more
evil attack.
Image source:
https://breakdev.org/evilginx-2-next-generation-of-phishing-2fa-tokens/
Phishing 2.0 uses a transparent reverse proxy to mount a man-in-the-middle (MITM) attack against all users in the same network segment. Its ultimate goal is not to capture usernames and passwords – those are just collateral – but the keys to the kingdom:
the user’s session token.
While MITM attacks are nothing new (Citibank was attacked way back in
2006!), lately highly automated ‘script-kiddie level’ tools, such as
Evilginx2 and
Modlishka, have become publicly available. I must admit that I’m quite impressed by the hard work and the technical accomplishments behind the previous sentence. In order for Phishing 2.0 to work, the tools need to intimately integrate with the target site(s) and therefore utilise deep, complex URL rewriting techniques in HTML content and JavaScript – and all in real time!
In Phishing 2.0, instead of a fake page created by the attacker, the victim sees the real and unaltered PayPal page in their browser – only that the page is served by a transparent proxy decrypting and re-encrypting all data in real time. As the tools will automatically acquire a valid TLS certificate, the URL bar will have the padlock icon, but still needs a fake domain like ‘paybal.com’.
In order to direct traffic to the proxy, the attacker sets up a reverse proxy on the same network, and routes all traffic through it via traditional
ARP poisoning etc. While Phishing 2.0 sounds quite hard to mount properly, the current tools hide the technical challenges in a way that most UI designers would be proud of.
To reiterate, using contemporary toolkits, the technically demanding Phishing 2.0 becomes Phishing for Dummies. There is no need to hand craft real-looking sites and e-mails. Script-kiddie level automated tools are freely available and, to top it all, shared, untrusted networks are increasingly common (WLAN).
Once set up, the Phishing 2.0 proxy will transparently intercept passwords, 2FA access tokens and session tokens. The impact is tremendous. The user doesn’t need to click on any links to end up at the fake site. The phishing site is no longer a copy – it
is the real site, just accessed through a relay. There is no natural protection from using exotic languages like Finnish, so relying on the ‘spot the sketchy Google-translated sites’ offers no protection. As the site looks absolutely identical and shows the padlock on the address bar, it gives the victim a false sense of security.
SMS OTP, mobile authenticators, everything that the user puts in is intercepted by the attacker and stored for future use.