Skip to content
KitploitKITPLOIT
도구블로그
제출
도구블로그
제출

해킹, 침투 테스트 및 사이버 보안 도구를 당신의 보안 무기고에!

Kitploit은 해킹, 사이버 보안 및 침투 테스트 도구 디렉토리입니다. 최신 프로젝트 업데이트를 발견하여 취약점을 찾고, 시스템을 분석하고, 테스트를 자동화하고, 보안을 강화하세요.

··피드·문의·개인정보·© 2026 Kitploit

도구 디렉토리

카테고리

모든 카테고리 보기
Loading categories
Evilginx-Phishing-Infra-Setup — Evilginx 피싱 인프라 설정 가이드 - Evilginx 및 Gophish 인프라 보안, IOCs 제거, 피싱 TTPs | Kitploit
도구/GitHubGitHub/an0nud4y/evilginx-phishing-infra-setup
Phishing ToolsIDS/IPS EvasionPhishingCommand and ControlSocial EngineeringLearning & EducationRed TeamingCurated ResourcesEmail Security

인기

모두 보기 →

커뮤니티에서 가장 많이 사용되는 도구를 찾아보세요.

모든 도구 탐색

도구 컬렉션을 둘러보세요

모든 도구 보기 →
공유
GitHuban0nud4y/evilginx-phishing-infra-setup

Evilginx-Phishing-Infra-Setup

Evilginx 피싱 인프라 설정 가이드 - Evilginx 및 Gophish 인프라 보안, IOCs 제거, 피싱 TTPs

저장소 보기
5981151년 전Kitploit 검토 완료

피싱 공격 인프라 설정 가이드

참고: 이는 제 개인 노트의 복사본입니다. 이 내용을 완전히 신뢰하지 마세요.

목차

  • 블로그/발표
  • 레드팀/피싱 인프라 자동화
  • 도메인 구매 및 분류 기법
  • 도구를 사용한 피싱 이메일 작성 개선
  • 이메일 스팸성 테스트
  • 피싱 이메일 모의 / 퍼플팀 피싱
  • Awesome Enterprise Email Security
  • 이메일을 받은편지함에 전달하기
  • Evilginx를 이용한 피싱 공격
    • Evilginx Phishlet 구축
    • Evilginx 설치 스크립트
    • Evilginx 인프라 보안 팁
    • Evilginx 연구 블로그/발표
    • Evilginx 방어 전략
  • GoPhish 인프라 보안
    • GoPhish 연구 블로그/발표
    • Gophish 대안
  • AiTM 사후 이용 / 피싱 연구 블로그/발표
  • 기타 기법/블로그/연구
  • 피싱 연구 발표

블로그/발표

  • BHIS | 피싱 공격 구축 방법 - 코딩 TTP : https://m.youtube.com/watch?si=YTjMa8XBusj_tPdc&v=VglCgoIjztE&feature=youtu.be

레드팀/피싱 인프라 자동화

  • https://github.com/dazzyddos/HSC24RedTeamInfra/blob/main/RedTeamInfraAutomation.pdf
  • OFFENSIVEX 2024 - Vincent Yiu - 2024년 레드팀 팁 : https://youtu.be/ECIBCbMfeo4?feature=shared
  • https://github.com/bluscreenofjeff/Red-Team-Infrastructure-Wiki
  • 즉석에서 피싱 인프라 배포 : https://github.com/VirtualSamuraii/flyphish
  • https://labs.jumpsec.com/putting-the-c2-in-c2loudflare/

도메인 구매 및 분류 기법

  • 만료된 도메인 확인 및 가능한 좋은 도메인 구매

    • https://expireddomains.net/
  • 도메인 분류

    • Bluecoat/Symantec - https://sitereview.bluecoat.com/#/
    • McAfee - https://www.trustedsource.org
    • Palo Alto Wildfire - https://urlfiltering.paloaltonetworks.com
    • Websense - https://csi.forcepoint.com & https://www.websense.com/content/SiteLookup.aspx (등록 필요)
    • FortiGuard - https://www.fortiguard.com/webfilter
    • IBM X-force - https://exchange.xforce.ibmcloud.com
    • Cyren - https://www.cyren.com/security-center/url-category-check-gate
    • Checkpoint - https://www.checkpoint.com/urlcat/main.htm (등록 필요)
    • Trend Micro - https://global.sitesafety.trendmicro.com/
    • Sophos - https://secure2.sophos.com/en-us/support/contact-support.aspx (제출만 가능; 확인 불가) (Submit a Sample -> Web Address 클릭)
    • BrightCloud - http://www.brightcloud.com/tools/url-ip-lookup.php
    • LightSpeed Systems - https://archive.lightspeedsystems.com/
  • 도메인 평판 확인/제출 자동화

    • Domainhunter: https://github.com/threatexpress/domainhunter
    • Chameleon : https://github.com/mdsecactivebreach/Chameleon
  • 블로그

    • https://medium.com/@frsfaisall/mastering-modern-red-teaming-infrastructure-leveraging-old-domains-for-reputation-based-bypasses-1fd8cc1768f7

도구를 사용한 피싱 이메일 작성 개선

  • mgeeky : https://github.com/mgeeky/Penetration-Testing-Tools/tree/master/phishing
  • HTML-Linter (일반적인 피싱 이메일 단어 회피) : https://github.com/mgeeky/Penetration-Testing-Tools/blob/master/phishing/phishing-HTML-linter.py
  • Decode-Spam-Headers : https://github.com/mgeeky/decode-spam-headers

이메일 스팸성 테스트

  • https://www.mail-tester.com/

피싱 이메일 모의 / 퍼플팀 피싱

  • https://delivr.to/

Awesome Enterprise Email Security

  • https://github.com/0xAnalyst/awesome-email-security
  • Gartner Magic Quadrant for Email Security Platforms (이메일 보안 플랫폼 부문 매직 쿼드런트) email-security-providers

이메일을 받은편지함에 전달하기

  • 방법 -1 : 이메일 서비스 제공업체 사용

    • SendGrid 사용 - http://sendgrid.com/
      • 유용한 서비스지만, 솔직히 스팸 목록에 오르지 않으려면 Pro 요금제가 필요함
    • MailGun - https://app.mailgun.com/
      • 문제 없었음
    • Amazon AWS SES
    • Brevo : https://www.brevo.com/free-smtp-server/
    • Outlook
    • Gmail
    • Azure Tenant를 설정하여 attackdomain.onmicrosoft.com 같은 onmicrosoft.com 도메인을 확보하면 이메일 발송 및 피싱 도메인으로 모두 사용 가능
    • LarkSuite (사용자 정의 도메인 지원) : https://www.larksuite.com/
    • Zoho (Zoho "무료 평생" 이메일 옵션 사용) : https://www.zoho.com/mail/custom-domain-email.html
    • Yandex : https://360.yandex.com/business/domain-mail/
  • 방법 - 2 : 기타 기법

    • 기법 1 : Andre Rosario - BreakDev Red Discord

      • 이메일 필터링으로 인해 이메일 전달에 문제가 있다면 Microsoft 365와 Azure IPP를 사용하여 대상자에게 암호화된 이메일을 보내는 것을 고려하세요!
        • 이메일이 합법적인 Microsoft SMTP 서버에서 발송되므로 차단할 수 없습니다.
        • 암호화된 이메일을 받은 대상자만 열어볼 수 있으며, DFIR 팀에 전달하더라도 해당 사용자로 로그인해야 메시지를 확인할 수 있습니다.
        • Microsoft Admin 포털에서 사용자 정의 도메인을 쉽게 오케스트레이션하고 가짜 계정을 많이 만들 수 있습니다.
        • M365를 사용하면 표시 이름을 임의로 설정할 수 있습니다. 따라서 대상자의 Outlook에서는 이메일이 [email protected]에서 온 것처럼 보이지만 실제로는 [email protected]에서 온 것입니다 (기술에 능숙한 사람은 쉽게 알아차릴 수 있음)
        • 이메일이 합법적인 Microsoft IP 및 도메인에서 오므로 도메인 분류나 수명에 대해 걱정할 필요가 없습니다. Microsoft 자체이기 때문입니다.
    • 기법 2 : Azure 외부 초대 기능 사용 - BreakDev Red Discord

      • Azure 외부 초대를 사용하면 피싱 URL로 리디렉션되는 링크가 포함된 이메일을 보낼 수 있습니다.

Evilginx를 이용한 피싱 공격

  • Evilginx Phishlet 구축

    • Evilginx 마스터리 코스 : https://academy.breakdev.org/evilginx-mastery
    • Evilginx 문서 : https://help.evilginx.com/
    • Evilginx Phishlet 컬렉션 : https://github.com/An0nUD4Y/Evilginx2-Phishlets
    • Evilginx 잘 알려지지 않은 기법 : https://github.com/An0nUD4Y/Evilginx2-Phishlets?tab=readme-ov-file#some-less-known-techniques
  • Evilginx 설치 스크립트

    • https://gist.github.com/dunderhay/d5fcded54cc88a1b7e12599839b6badb
  • Evilginx 인프라 보안 팁 -

    • https://github.com/An0nUD4Y/Evilginx2-Phishlets#securing-evilginx-infra-tips

      root@kitploit:~
      - URL 경로 패턴 매칭을 통한 탐지를 피하기 위해 피싱 페이지의 URL 재작성 (Kuba)
      - IOC 제거 (X-Evilginx 헤더 및 기본 인증서 세부 정보)
      - 인증되지 않은 리디렉션 정적 콘텐츠 수정
      - 각 서브도메인에 대해 요청하는 대신 Let'sEncrypt에서 루트 도메인에 대한 와일드카드 인증서를 요청하도록 코드 수정 (Kuba 블로그 참조) - 참고 저장소 https://github.com/ss23/evilginx2
      - TLS 핑거프린팅(JA3 및 JA3S)을 방지하기 위해 evilginx를 프록시 뒤에 배치
      - 가능하다면 중간에 cloudflare 사용 (SSL 설정을 올바르게 구성해야 함, cloudflare 설정에서 Full로 변경)
      - 알려진 ASN 블랙리스트를 사용하여 탐지 회피 (예: https://github.com/aalex954/evilginx2-TTPs#ip-blacklist)
      - 콘텐츠 로딩 시간을 줄이기 위해 phishlet의 proxyhost 수를 가능한 줄임
      - Azure에서 Evilginx를 호스팅하고 해당 도메인 사용 (phishlet의 프록시 호스트를 1개로 제한하거나 방법을 찾아서, 여러 Azure 서브도메인을 만들어 시도)
      - 콘텐츠 기반 탐지를 피하기 위해 페이지 콘텐츠를 수정하는 sub_filters 추가 (예: Favicon, 양식 제목 글꼴 또는 스타일, 관련된 모든 것)
      - phishlet sub_filters를 사용하여 도메인을 기록하거나 이후 분석에 도움이 될 수 있는 피드백/원격 측정/로그/분석 서브도메인 차단
      - js-injected가 정적인지 동적인지 확인하고, 정적이라면 evilginx js-inject 코드를 수정하여 각 사용자/대상에 대해 동적/난독화된 js 버전 생성
      - Evilginx 인프라 IP가 유출되지 않도록 주의, DNS 기록을 확인하여 어디에도 저장되지 않았는지 확인 (분석가가 도메인의 이전 DNS 레코드를 찾을 수 있음)
      - 다음 연구를 숙지: https://catching-transparent-phish.github.io/catching_transparent_phish.pdf , 저장소 - https://catching-transparent-phish.github.io/
      

Evilginx 연구 블로그/발표 :

  • 잔잔한 바다는 숙련된 피셔맨을 만들지 않는다 - Kuba Gretzky (x33fc0n 2024) :
    • 발표 : https://youtu.be/Nh99d3YnpI4?si=Ltwus2PS0z97gf2R
    • 슬라이드 : https://github.com/kgretzky/talks/blob/main/2024/x33fcon/a-smooth-sea-never-made-a-skilled-phisherman.pdf
  • 초기 접근의 삼위일체 : https://trustedsec.com/blog/the-triforce-of-initial-access
    • Bobber : https://github.com/Flangvik/Bobber
  • Canary AiTM 탐지 우회 : https://insights.spotit.be/2024/06/03/clipping-the-canarys-wings-bypassing-aitm-phishing-detections/
  • Cloudflare 및 HTML 난독화를 사용하여 Evilginx 보호 : https://www.jackphilipbutton.com/post/how-to-protect-evilginx-using-cloudflare-and-html-obfuscation
  • (Evilginx 이메일 전달 신뢰도 향상) SPF, DMARC, DKIM, MX 레코드 추가 : https://fortbridge.co.uk/research/add-spf-dmarc-dkim-mx-records-evilginx/
    • https://m3rcer.netlify.app/redteaming/spamfilterbypass/
  • 피싱 전술 및 OPSEC : https://mgeeky.tech/uploads/WarCon22 - Modern Initial Access and Evasion Tactics.pdf
  • Evilginx + BITB + 회피 전술 : https://youtu.be/p1opa2wnRvg
  • 낚싯바늘, 줄, 그리고 피슐렛 - Evilginx로 AD FS 정복하기 : https://research.aurainfosec.io/pentest/hook-line-and-phishlet/
  • O365 피싱 인프라 - https://badoption.eu/blog/2023/12/03/PhishingInfra.html
  • 보이지 않는 나 – 피싱 인프라 보호 : https://redsiege.com/blog/2024/01/you-cant-see-me-protecting-your-phishing-infrastructure/

Evilginx에 대한 방어 전략

  • 중간자 피싱 해체 및 대응 - X33fcon 2024 - https://youtu.be/-W-LxcbUxI4
  • HoneyTokens을 사용한 AiTM 탐지 : https://zolder.io/using-honeytokens-to-detect-aitm-phishing-attacks-on-your-microsoft-365-tenant/
  • 현대 피싱으로부터 보호 : https://bleekseeks.com/blog/how-to-protect-against-modern-phishing-attacks
  • https://www.youtube.com/watch?v=wTLB0Yh70_0
  • JA3, JA3S, JA4 지문 인식을 통한 evilginx 탐지
    • JA4 데이터베이스 : https://ja4db.com/

GoPhish 인프라 보안 강화

이 수정 사항은 최신 evilginx + gophish 버전(evilginx3.3)에서도 작동합니다.

  • 팁 : evilginx와 함께 사용할 때 피싱 템플릿에서 {{.URL}} 매개변수를 사용하세요 ( https://github.com/kgretzky/evilginx2/issues/1042#issuecomment-2052073864)

  • GoPhish 인프라 보안을 위한 GoPhish 소스 코드 및 파일 구조 수정

    • X-Gophish 인스턴스 제거 ( X-Gophish-Contact , X-Gophish-Signature)

    • config/config.go 파일에서 const ServerName= "gophish" 를 제거하고 const ServerName= "IGNORE"로 변경

    • config.json 파일에서 기본 관리자 서버 포트 변경

    • 테스트 이메일 메시지 서명 수정, SMTP 테스트 중 탐지 방지를 위해. Controllers > api > util.go

      root@kitploit:~
      Controllers > api > util.go
      models > testdata > email_request.go
      models > testdata > email_request_test.go
      models > testdata > maillog.go
      models > testdata > maillog_test.go
      models > testdata > smtp_test.go
      
    • 404 응답 변경

AiTM 사후 익스플로잇 / 피싱 연구 블로그/발표

  • AiTM (사후 익스플로잇) : https://www.youtube.com/live/WY4mH-8TbWY?si=LkZ1LuduDln1vRuj
    • https://youtu.be/py68OE4tQ4Q?si=n6QlNuro88c1PRzn
  • https://trustedsec.com/blog/the-triforce-of-initial-access
  • https://www.youtube.com/live/tOzURCc-qUc?si=DMkLwXHVQomRMEJD## 기타 기술/블로그/연구
  • 합법적인 사이트를 피싱에 악용하기 : https://lots-project.com/
  • Muraena : https://github.com/muraenateam/muraena
  • NecroBrowser : https://github.com/muraenateam/necrobrowser
  • BITB : https://mrd0x.com/browser-in-the-browser-phishing-attack/
    • Frameless-bitb : https://github.com/waelmas/frameless-bitb
      • https://youtu.be/luJjxpEwVHI?si=sk8kMfdfhZbTz8qR
    • CuddlePhish : https://github.com/fkasler/cuddlephish
    • https://pushsecurity.com/blog/phishing-2-0-how-phishing-toolkits-are-evolving-with-aitm/
    • Okta와 Azure 연결, Okta 및 Frame Buster 우회를 위한 자동 MFA 구독을 통한 BITB 수행 : https://x.com/otterhacker/status/1929487165458641045?s=46&t=mlJvZy0Zrkrxzuvtt7m2cQ
      • https://github.com/OtterHacker/OktaGinx/
  • 프로그레시브 웹 앱(PWA) 피싱 : https://mrd0x.com/progressive-web-apps-pwa-phishing/
  • noVNC 피싱 : https://adepts.of0x.cc/novnc-phishing/

피싱 연구 발표

  • https://youtu.be/zmo_tPbCXtA?si=4imjZtwQ6I9iu_tP
도구 다운로드
  • 대량 이메일도 보낼 수 있습니다. 참고: https://learn.microsoft.com/en-us/entra/external-id/tutorial-bulk-invite
  • 이메일을 받은편지함에 전달하기 위한 무작위 팁

    • 평판이 좋은 도메인 보유, 도메인 분류 확인
    • 1년 이상 된 도메인 사용 또는 expireddomain 사용
    • 유효한 DKIM, DMARC, SPF 보유
      • Mailgoose (SPF, DMARC, DKIM 구성이 올바르게 설정되었는지 확인) : https://github.com/CERT-Polska/mailgoose
    • 이메일에 수신 거부 링크 추가
    • 먼저 무해한 이메일 발송 (평판 구축에 도움될 수 있음)
    • 이메일 발송에 사용되는 도메인과 동일한 도메인의 링크를 이메일에 포함
  • 블로그/발표/참고자료

    • Outlook_Email_Auth_Bypass : https://gitlab.com/hxxpxxp/outlook_email_auth_bypass (Outlook 데스크톱 및 웹 앱에서 이메일의 "보낸 사람" 헤더의 "표시 이름"이 사용자에게 표시되는 보낸 사람 이메일을 조작할 수 있어 더 설득력 있는 피싱 이메일을 만들 수 있음)
    • Spy Pixel - 이메일 추적용 이미지 픽셀 : https://github.com/collinsmc23/spy-pixel
    • EchoSpoofing : https://labs.guard.io/echospoofing-a-massive-phishing-campaign-exploiting-proofpoints-email-protection-to-dispatch-3dd6b5417db6
    • Blackhat USA 2024 - 새로운 이메일 스푸핑 공격 패턴 : https://github.com/onhexgroup/Conferences/blob/main/Black Hat USA 2024 slides/Hao Wang %26 Caleb Sargent %26 Harrison Pomeroy %26 Renana Friedlich_Into the Inbox Novel Email Spoofing Attack Patterns.pdf
  • X-Evilginx 헤더 제거 (req.Header.Set이 있는 모든 코드 줄을 확인하고 core/http_proxy.go 파일에서 관련 함수를 주석 처리)

    root@kitploit:~
      // 469번 줄 주석 처리
      req.Header.Set(p.getHomeDir(), o_host)
      
      // 659번 줄 주석 처리
      req.Header.Set(p.getHomeDir(), o_host)
      
      // 1791-1793번 줄 함수 주석 처리
      func (p *HttpProxy) getHomeDir() string {
      	return strings.Replace(HOME_DIR, ".e", "X-E", 1)
      }
      
      // 52-54번 줄 주석 처리
      const (
      	HOME_DIR = ".evilginx"
      )
    
  • 인증되지 않은 리디렉션 정적 콘텐츠를 수정하려면 core/http_proxy.go 파일에서 <html>을 검색하고 HTML 코드를 수정하여 정적 시그니처를 제거합니다.

  • 또한 정적 삽입 js 코드 시그니처 탐지를 피하기 위해 아래와 같이 코드를 수정할 수 있습니다.

    • import에 "github.com/tdewolff/minify/js"를 추가해야 함

      root@kitploit:~
      	re := regexp.MustCompile(`(?i)(<\s*/body\s*>)`)
      	var d_inject string
      
      	if script != "" {
      		minifier := minify.New() // "github.com/tdewolff/minify/js"
      		minifier.AddFunc("text/javascript", js.Minify)
      		obfuscatedScript, err := minifier.String("text/javascript", script)
      		if err != nil {
      			// 오류 처리 - 난독화 실패
      			d_inject = "<script" + js_nonce + ">" + "function doNothing() {var x =0};" + script + "</script>\n${1}"
      		}
      		d_inject = "<script" + js_nonce + ">" + "function doNothing() {var x =0};" + obfuscatedScript + "</script>\n${1}"
      		//d_inject = "<script" + js_nonce + ">" + "function doNothing() {var x =0};" + script + "</script>\n${1}"
      
      	} else if src_url != "" {
      		d_inject = "<script" + js_nonce + " type=\"application/javascript\" src=\"" + src_url + "\"></script>\n${1}"
      	} else {
      		return body
      	} 
      
  • core/cert.db 파일도 수정

  • gophish의 "rid" 변경

  • evilginx 앞에 nginx, caddy 또는 기타 프록시 사용

  • 리디렉터 사용

    • cloudflare turnstile을 evilginx 리디렉터로 사용하고 봇 차단
      • https://github.com/kgretzky/evilginx2/blob/master/redirectors/turnstile/index.html
    • html/js 기반 리디렉터 난독화
      • 의심스러운 HTTP User-Agent 목록: https://github.com/mthcht/awesome-lists/blob/main/Lists/suspicious_http_user_agents_list.csv
      • https://github.com/DosX-dev/WebSafeCompiler
    • gabagool 피싱 키트에서 사용하는 봇 탐지 방법: https://medium.com/@traclabs_/aitm-phishing-hold-the-gabagool-analyzing-the-gabagool-phishing-kit-531f5bbaf0e4
    • 리디렉션을 위한 Meta HTML 태그
      • <meta http-equiv="refresh" content="5;url=https://example.com">
  • 기본 lure URL 패턴(길이 8의 임의 문자열) 변경

    root@kitploit:~
       // core/terminal.go 파일의 728번 줄
      		l := &Lure{
      			Path:     "/" + GenRandomString(8),
      			Phishlet: args[1],
      		}
    
  • URL 경로 패턴 매칭을 통한 탐지를 피하기 위해 피싱 페이지의 URL 재작성 (Kuba). [이 기능은 Evilginx 공개 버전에서 사용할 수 없으며 직접 구현해야 합니다.]

    root@kitploit:~
    # Evilginx Pro 버전에서만 작동
    # 공개 버전에서도 유사한 기능을 구현할 수 있습니다.
    rewrite_urls:
    
    trigger:
    domains: ['www.linkedin.com']
    paths: ['^/login$']
    rewrite:
    path: '/this/is/not/the/path/you/are/looking/for.php'
    query:
    
        {key:'a', value: 'HOW'}
        {key:'b', value: 'MUCH'}
        {key:'d', value: 'IS'}
        {key:'e', value: 'THE'}
        {key:'f', value: 'PHISH'}
        {key:'q', value: '{id}'}
    
    

    Untitled

  • lure/세션 식별자 쿠키 서명 패턴 및 값 수정 (by @rad9800 )

    • 규칙 1: 쿠키 이름=XXXX-XXXX & 값=64_hex_chars - https://gist.github.com/rad9800/bb73de360fc07ac544f0bc9faac9082d#file-index-js-L130
      • 관련 Evilginx 코드 기능 (쿠키 이름): https://github.com/kgretzky/evilginx2/blob/9e32484719681892945130187ea52737b3d72051/core/http_proxy.go#L1984
      • 관련 Evilginx 코드 기능 (쿠키 값): https://github.com/kgretzky/evilginx2/blob/9e32484719681892945130187ea52737b3d72051/core/http_proxy.go#L895
    • 규칙 2: 스크립트 경로=/s/64_hex_chars.js 및 content-length=0
    • 규칙 3: 규칙 1과 규칙 2 모두 존재
      • 전체 스니펫 js 블롭 로직은 여기: https://gist.github.com/rad9800/bb73de360fc07ac544f0bc9faac9082d
  • Referrer 헤더가 피싱 도메인 이름을 유출하지 않도록 차단 - 이 연구 블로그 참조:

    • http_proxy.go 파일의 여기에 아래 줄 추가 (Chrome은 이를 존중하지 않으며 url() CSS 함수에 의해 요청이 시작될 때 - 블로그 참조)
      • resp.Header.Set("Referrer-Policy", "no-referrer")
      • phishlet에서 자동화하려면 이 PR 확인: https://github.com/kgretzky/evilginx2/pull/1006
  • 피싱 도메인 유출을 통한 원격 측정/카나리/탐지를 피하기 위해 자체 CSP(Content Security Policy) 정의

    • 자세한 내용은 다음 참조: https://insights.spotit.be/2024/06/03/clipping-the-canarys-wings-bypassing-aitm-phishing-detections/
  • 대상 사이트가 카나리 토큰(CSS, JS)을 사용하는지 확인하고 회피

    • (CSS,JS) 카나리 AiTM 탐지 우회: https://insights.spotit.be/2024/06/03/clipping-the-canarys-wings-bypassing-aitm-phishing-detections/
    • https://blog.thinkst.com/2024/01/defending-against-the-attack-of-the-cloned-websites.html
  • JA4 핑거프린트 회피

    • https://github.com/refraction-networking/utls
    • https://github.com/juzeon/spoofed-round-tripper
  • BITB + evilginx + 프레임 버스팅 우회

    • https://x.com/otterhacker/status/1929487165458641045?s=46&t=mlJvZy0Zrkrxzuvtt7m2cQ
      • OktaGinx : https://github.com/OtterHacker/OktaGinx/blob/main/okta.yaml#L17
    • https://github.com/waelmas/frameless-bitb
    • 프레임 버스팅 우회 예시 Subfilter from : https://github.com/OtterHacker/OktaGinx/blob/44fed02954b6cd65e17ab581209a4d0f3b734c24/okta.yaml#L124 and https://github.com/OtterHacker/OktaGinx/blob/44fed02954b6cd65e17ab581209a4d0f3b734c24/okta.yaml#L82
      root@kitploit:~
      - triggers_on: 'login.microsoftonline.com'
      orig_sub: ''
      domain: 'okta.com'
      search: 'if\(e.self===e.top\){'
      replace: 'if(true){window.oldself=e.self;e.self=e.top;'
      mimes: ['text/html', 'charset=utf-8']
      ```- triggers_on: 'login.microsoftonline.com'
      orig_sub: ''
      domain: 'okta.com'
      search: 'X-Frame-Options: DENY'
      replace: 'Test: test'
      mimes: ['text/html', 'charset=utf-8']
      
      • 일반적으로 사용되는 프레임 버스팅 기법
        • https://en.wikipedia.org/wiki/Framekiller
        • https://seclab.stanford.edu/websec/framebusting/framebust.pdf
          • iframe 존재 감지를 위한 일반적인 기법
            root@kitploit:~
              if (top != self)
              if (top.location != self.location)
              if (top.location != location)
              if (parent.frames.length > 0)
              if (window != top)
              if (window.top !== window.self)
              if (window.self != window.top)
              if (parent && parent != window)
              if (parent && parent.frames && parent.frames.length>0)
              if((self.parent&&!(self.parent===self))&&(self.parent.frames.length!=0))
            
          • iframe이 감지된 후 리디렉션을 수행하기 위해 웹사이트에서 사용할 수 있는 방법
            root@kitploit:~
            top.location.replace(self.location)
             top.location.href = window.location.href
             top.location.replace(document.location)
             top.location.href = window.location.href
             top.location.href = "URL"
             document.write(’’)
             top.location = location
             top.location.replace(document.location)
             top.location.replace(’URL’)
             top.location.href = document.location
             top.location.replace(window.location.href)
             top.location.href = location.href
             self.parent.location = document.location
             parent.location.href = self.document.location
             top.location.href = self.location
             top.location = window.location
             top.location.replace(window.location.pathname)
             window.top.location = window.self.location
             setTimeout(function(){document.body.innerHTML=’’;},1);
             window.self.onload = function(evt){document.body.innerHTML=’’;}
             var url = window.location.href; top.location.replace(url)
            
  • https://janbakker.tech/evilginx-resources-for-microsoft-365/
  • Evilginx + BITB - https://www.youtube.com/watch?v=luJjxpEwVHI&feature=youtu.be
  • 낚시바늘, 줄, 그리고 싱커: Evilginx를 사용한 Windows Hello for Business 피싱 : https://medium.com/@yudasm/bypassing-windows-hello-for-business-for-phishing-181f2271dc02
  • 저항하는 자 피싱하기 - Dirk Jan의 Microsoft Entra 기본 새로 고침 토큰 피싱 : https://youtu.be/tNh_sYkmurI?si=qcb917IB5zHU1fQk
  • X33fcon 2024 - https://youtu.be/Nh99d3YnpI4?si=Ltwus2PS0z97gf2R
  • 통 속의 물고기처럼 피싱하기 - 링크 크롤러 우회 : ****https://posts.specterops.io/like-shooting-phish-in-a-barrel-926c1905bb4b
  • 물고기처럼 마시기 - 피싱 사이트를 자연스럽게 만드는 방법 ****: https://posts.specterops.io/drink-like-a-phish-b9e91d0b5677
  • 피시들에게 먹이 주기 : ****https://posts.specterops.io/feeding-the-phishes-276c3579bba7
  • https://posts.specterops.io/phish-out-of-water-aaeb677a5af3
  • https://youtu.be/6jYZQKDlKco?si=cpfd4tWQ4V8ZAZaI
  • https://posts.specterops.io/one-phish-two-phish-red-teams-spew-phish-1a2f02010ed7
  • Push Security 피싱 도구 탐지 : https://gist.github.com/rad9800/bb73de360fc07ac544f0bc9faac9082d
    • Push Security의 Chrome 확장 프로그램은 다소 취약한 규칙으로 evilginx를 탐지합니다.
      • 규칙 1: 쿠키 이름=XXXX-XXXX & 값=64_hex_chars
      • 규칙 2: 스크립트 경로=/s/64_hex_chars.js & content-length=0
      • 규칙 3: 규칙 1과 규칙 2 모두 존재
      • 전체 js 블롭 로직은 여기 있습니다 https://gist.github.com/rad9800/bb73de360fc07ac544f0bc9faac9082d
  • https://janbakker.tech/evilginx-loves-temporary-access-passes-too/
  • controllers/phish.go 파일에 아래 사용자 정의 함수 추가

    root@kitploit:~
    func customNotFound(w http.ResponseWriter, r *http.Request) {
    	http.Error(w, "Try again!", http.StatusNotFound)
    }
    
  • 이제 모든 http.NotFound(w, r) 인스턴스를 customNotFound(w, r)로 대체

  • controllers/phish.go 파일에서 robots.txt 하드코딩된 응답 제거 및 수정

    • phish.go 파일의 해당 코드를 아래와 같이 수정

      root@kitploit:~
      //수정된 응답
      // RobotsHandler는 검색 엔진 등이 피싱 자료를 인덱싱하는 것을 방지합니다.
      func (ps *PhishingServer) RobotsHandler(w http.ResponseWriter, r *http.Request) {
      	fmt.Fprintln(w, "User-agent: *\nDisallow: /*/*\nDisallow: /.git/*")
      }
      
  • 요청의 "rid" GET 매개변수 수정

    • "rid"의 모든 인스턴스를 다른 것으로 수정해야 합니다.
    • 이는 evilginx3.3 소스 코드에도 있으므로 거기도 수정해야 합니다.
  • 고급 방어를 위해, 정적 폴더를 수정하고 이름을 다른 것으로 변경할 수 있으며, 내부 파일도 이름을 변경하여 경로 기반 탐지를 피할 수 있습니다. 관련 소스 코드도 수정하는 것을 잊지 마세요.

    • 예: 이미지 이름, pixel.png와 같은 것들을 다른 것으로 변경
  • util/util.go 파일에서 인증서 속성 변경

    root@kitploit:~
    	template := x509.Certificate{
    		SerialNumber: serialNumber,
    		Subject: pkix.Name{
    			//Organization: []string{"Gophish"},
    			Organization: []string{"Microsoft Corporation"},
    		},
    
  • Nginx를 사용하여 트래픽을 프록시하여 Golang 서버 지문을 피합니다.

    • service nginx start

    • gophish config.json에서 http 포트를 80에서 8080으로, https 포트를 기본값에서 60002로 변경해야 합니다.

      root@kitploit:~
      {
      	"admin_server": {
      		"listen_url": "127.0.0.1:60002",
      		"use_tls": true,
      		"cert_path": "gophish_admin.crt",
      		"key_path": "gophish_admin.key",
      		"trusted_origins": []
      	},
      	"phish_server": {
      		"listen_url": "127.0.0.1:8080",
      		"use_tls": false,
      		"cert_path": "example.crt",
      		"key_path": "example.key"
      	},
      	"db_name": "sqlite3",
      	"db_path": "gophish.db",
      	"migrations_prefix": "db/db_",
      	"contact_address": "",
      	"logging": {
      		"filename": "",
      		"level": ""
      	}
      }
      
    • 아래 설정은 User-Agent에 "Bot" 또는 "bot"이 포함된 모든 요청을 차단합니다.

      root@kitploit:~
      # /etc/nginx/nginx.conf
      
      events {
          # Define event processing parameters here
          worker_connections 1024; # Adjust according to your requirements
      }
      
      http {
      
          upstream backend {
              server localhost:8080;
          }
          # HTTP server
          server {
              listen 80 default_server;
              
      
              # Reject requests with "bot" or "Bot" in User-Agent
              if ($http_user_agent ~* (bot|Bot)) {
                  return 403;
              }
      
              location / {
                  proxy_pass http://backend;
                  proxy_set_header Host $host;
                  proxy_set_header X-Real-IP $remote_addr;
                  proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
                  proxy_set_header X-Forwarded-Proto $scheme;
              }
          }
      
          upstream backend_https {
              server localhost:60002;
          }
          # HTTPS server
          server {
              listen 60001 ssl default_server;
      
              ssl_certificate /root/Phishing/gophish-mod/gophish_admin.crt;
              ssl_certificate_key /root/Phishing/gophish-mod/gophish_admin.key;
      
              # Reject requests with "bot" or "Bot" in User-Agent
              if ($http_user_agent ~* (bot|Bot)) {
                  return 403;
              }
      
              location / {
                  proxy_pass https://backend_https;
                  proxy_set_header Host $host;
                  proxy_set_header X-Real-IP $remote_addr;
                  proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
                  proxy_set_header X-Forwarded-Proto $scheme;
              }
          }
      }
      
      
    • 특정 User-Agent만 허용하려면 아래 설정을 사용하세요. 이 설정은 모든 요청을 차단하고 User-Agent가 "iamdevil"인 요청만 허용합니다.

      root@kitploit:~
      # /etc/nginx/nginx.conf
      
      events {
          # Define event processing parameters here
          worker_connections 1024; # Adjust according to your requirements
      }
      
      http {
      
          upstream backend {
              server localhost:8080;
          }
      
          # HTTP server
          server {
              listen 80 default_server;
      
              # Reject requests with user agent other than "iamdevil"
              if ($http_user_agent != "iamdevil") {
                  return 403;
              }
      
              location / {
                  proxy_pass http://backend;
                  proxy_set_header Host $host;
                  proxy_set_header X-Real-IP $remote_addr;
                  proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
                  proxy_set_header X-Forwarded-Proto $scheme;
              }
          }
      
          upstream backend_https {
              server localhost:60002;
          }
      
          # HTTPS server
          server {
              listen 60001 ssl default_server;
      
              ssl_certificate /root/Phishing/gophish-mod/gophish_admin.crt;
              ssl_certificate_key /root/Phishing/gophish-mod/gophish_admin.key;
      
              # Reject requests with user agent other than "iamdevil"
              if ($http_user_agent != "iamdevil") {
                  return 403;
              }
      
              location / {
                  proxy_pass https://backend_https;
                  proxy_set_header Host $host;
                  proxy_set_header X-Real-IP $remote_addr;
                  proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
                  proxy_set_header X-Forwarded-Proto $scheme;
              }
          }
      }
      
  • 서명된 추적 픽셀을 기반으로 한 탐지를 피하기 위해 Gophish 추적 픽셀 서명 수정

  • Gophish 이메일 헤더 시퀀스 패턴 변경. 이는 gophish를 탐지하는 데 사용될 수 있습니다(From BreakDev Red Community).

  • gophish 앞에 PostFix를 설정하여 IOCs 및 기타 탐지 요소와 이메일의 스팸성 제거 및 헤더 수정 및 수정.

  • GoPhish 연구 블로그/발표 :

    • https://edermi.github.io/post/2021/modding_gophish/
    • https://www.sprocketsecurity.com/resources/never-had-a-bad-day-phishing-how-to-set-up-gophish-to-evade-security-controls
    • https://cyberwarfare.live/wp-content/uploads/2023/08/OPSEC-on-the-High-Seas_-A-Gophish-Adventure.pdf
    • https://www.sprocketsecurity.com/resources/never-had-a-bad-day-phishing-how-to-set-up-gophish-to-evade-security-controls
    • https://github.com/puzzlepeaches/sneaky_gophish
    • https://cybercx.co.nz/blog/identifying-gophish-servers/
    • https://github.com/gophish/gophish/issues/1553#issuecomment-523969887
  • GoPhish 대안 :

    • SniperPhish : https://github.com/GemGeorge/SniperPhish
    • Mailcow : https://github.com/mailcow/mailcow-dockerized
    • EvilnoVNC : https://github.com/JoelGMSec/EvilnoVNC
    • MultiEvilnoVNC : https://blog.wanetty.com/blog/tools/multievilnovnc
    • https://fhlipzero.io/blogs/6_noVNC/noVNC.html
    • Delusion (NoVNC 기반 툴킷) : https://cloud.google.com/blog/topics/threat-intelligence/session-stealing-browser-in-the-middle
    • NoVNC 탐지 : https://gist.github.com/rad9800/bb73de360fc07ac544f0bc9faac9082d
  • noVNC와 Docker : https://powerseb.github.io/posts/Another-phishing-tool/
    • https://github.com/powerseb/NoPhish
    • https://fhlipzero.io/blogs/6_noVNC/noVNC.html
    • https://github.com/Macmod/YesPhish/tree/patchright-chrome
  • EvilQR - QR 피싱
    • QR 생성 : https://github.com/Flangvik/QRucible
    • https://badoption.eu/blog/2024/01/08/mobilephish.html
    • QR2Ascii : https://github.com/Jojodicus/qr2eascii
    • https://github.com/kgretzky/evilqr , https://breakdev.org/evilqr-phishing/
    • https://github.com/swagkarna/EvilJack
    • https://techcommunity.microsoft.com/t5/microsoft-security-experts-blog/hunting-for-qr-code-aitm-phishing-and-user-compromise/bc-p/4054850
  • NoPhish (docker 및 noVNC) : https://github.com/powerseb/NoPhish 및 https://badoption.eu/blog/2023/07/12/entra_phish.html
  • EvilGoPhish : https://github.com/fin3ss3g0d/evilgophish
  • 스미싱 : https://blog.shared-video.mov/systematic-destruction-hacking-the-scammers-pt.-2
  • CloudFlare Workers를 이용한 피싱
    • TryCloudflare : https://developers.cloudflare.com/cloudflare-one/connections/connect-networks/do-more-with-tunnels/trycloudflare/
    • https://github.com/zolderio/AITMWorker
    • https://gist.github.com/RedTeamOperations/33f245a777c9b322b0466b59d6687f15
    • https://cyberwarfare.live/wp-content/uploads/2023/08/Certified-Red-Team-CredOps-Infiltrator-CRT-COI-1.pdf
  • Cloudflare 공개 버킷을 이용한 피싱 : https://developers.cloudflare.com/r2/buckets/public-buckets/
    • https://medium.com/trac-labs/aitm-phishing-hold-the-gabagool-analyzing-the-gabagool-phishing-kit-531f5bbaf0e4
  • 피싱을 위한 Google Open Redirection
    • https://untrustednetwork.net/en/2024/02/26/google-open-redirect/
    • Open Redirect (작동 안 함) : https://googleweblight.com/i?u=m4lici0u5.com
    • Open Redirect : https://www.google.com/url?q=https://m4lici0u5.com
    • Open Redirect : https://business.google.com/website_shared/launch_bw.html?f=https://m4lici0u5.com
    • 더 많은 내용은 다음에서 확인 가능 : https://lots-project.com/
  • https://blog.delivr.to/delivr-tos-top-10-payloads-dec-24-pastejacking-image-less-qr-codes-and-concatenated-zip-a32e668106dd#878d
  • Azure Information Protection을 이용한 메일 보호 우회 피싱
    • https://youtu.be/tHNi5BzScVo?si=H2czog19AmTp_O26
    • https://youtu.be/EYUp_MNtJIk?si=sg_9RQggDvqOSLNL
    • https://youtu.be/KhdzIPPW4W0?si=E4CmWx0iO8EaR6JF
  • https://nicolasuter.medium.com/aitm-phishing-with-azure-functions-a1530b52df05
  • https://pushsecurity.com/blog/a-new-class-of-phishing-verification-phishing-and-cross-idp-impersonation/
  • https://blog.delivr.to/delivr-tos-top-10-payloads-dec-24-pastejacking-image-less-qr-codes-and-concatenated-zip-a32e668106dd#878d
  • https://trustedsec.com/blog/oops-i-udld-it-again
  • Docusign 악용을 통한 자격 증명 피싱 : https://sublime.security/blog/living-off-the-land-credential-phishing-via-docusign-abuse/
  • EML 첨부 파일을 이용한 숨겨진 자격 증명 피싱 : https://sublime.security/blog/hidden-credential-phishing-within-eml-attachments/
  • https://sublime.security/blog/talking-year-end-credential-phishing-scams-over-turkey/
  • Microsoft Customer Voice를 이용한 피싱 : https://cofense.com/blog/microsoft-customer-voice-urls-used-in-latest-phishing-campaign
  • https://www.youtube.com/live/tOzURCc-qUc?si=DMkLwXHVQomRMEJD
  • DoubleClickJacking : https://www.paulosyibelo.com/2024/12/doubleclickjacking-what.html
    • https://safetyscience.info/labs/doubleclickjacking/
  • 다양한 기술 비교 : https://blog.quarkslab.com/technical-dive-into-modern-phishing.html
  • https://cloud.google.com/blog/topics/threat-intelligence/session-stealing-browser-in-the-middle
  • 수신 Microsoft Teams 웹훅 악용 피싱 : https://www.blackhillsinfosec.com/wishing-webhook-phishing-in-teams/
    • https://www.youtube.com/live/kMMZrd9intI?si=rd_EKWmXeKbbGAEI
  • Rogue RDP 또는 RDP (.rdp) 피싱 : https://github.com/GoSecure/pyrdp
    • https://cloud.google.com/blog/topics/threat-intelligence/windows-rogue-remote-desktop-protocol
    • https://www.blackhillsinfosec.com/rogue-rdp-revisiting-initial-access-methods/
  • https://easydmarc.com/blog/google-spoofed-via-dkim-replay-attack-a-technical-breakdown/
  • SVG 피싱 : https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/pixel-perfect-trap-the-surge-of-svg-borne-phishing-attacks/
  • 초기 접근을 위한 ClickOnce 피싱 활용 : https://www.netspi.com/blog/technical-blog/adversary-simulation/all-you-need-is-one-a-clickonce-love-story/
  • https://denniskniep.github.io/posts/09-device-code-phishing/
  • https://badoption.eu/blog/2025/04/25/github.html
  • https://atticsecurity.com/blog/aitm-for-whfb-persistence/
  • [반드시 확인] Evilworker : https://github.com/Ahaz1701/EvilWorker
    • https://medium.com/@ahaz1701/evilworker-da94ae171249