My Simple and Personal Reflection on the “Evilginx MFA Hijack Lab” at DAM 2025

A Day to Remember at DAM 2025

Tuesday, July 15, was one of those days that leaves a lasting mark. Twelve colleagues, a day filled with achievements, goals, and shared experiences, and a closing activity as challenging as it was rewarding. We gathered at the Bogotá Chamber of Commerce for our DAM 2025 event, an opportunity that went far beyond simply focusing on Dapango Technologies’ operational objectives. We connected on a human level, shared conversations, discussed plans, and, most importantly, reaffirmed why we are walking this path together.

The final activity of the day was something I approached with curiosity and a fair amount of uncertainty. As someone without technical programming expertise or deep technological training, I wasn’t sure how much I could contribute. The exercise had a name that already hinted at complexity: “Evilginx MFA Hijack Lab” 2025. From the title alone, I expected a challenging experience. What I didn’t expect was how much it would broaden my understanding of the world I am indirectly part of every day.

Opening the Door to a New Perspective

The goal of the lab was clear: to learn how Multi-Factor Authentication (MFA) systems can be compromised using Evilginx. This tool simulates a phishing environment to capture session tokens and effectively “hijack” a legitimate session. All of this was, of course, conducted in a controlled, educational environment.

While the technical terms might sound intimidating to someone outside the IT field, the real value for me was the teamwork and guidance I received. I had the good fortune to pair up with Ronald Contreras, whose patience, expertise, and willingness to explain each step made the experience both accessible and engaging.

We worked using Ubuntu via PowerShell on Windows, executing Linux commands that, for me, were like learning a new language. Ronald not only walked me through the sequence of actions but also helped me understand the reasoning behind each step, translating the “technical” into something I could grasp.

When Technical Barriers Turn into Lessons this 2025

We eventually reached a point in the lab where we couldn’t proceed due to missing certificates. While this could have been frustrating, it instead became a critical moment of reflection. Ronald summarized it perfectly:

“This exercise shows that a well-prepared person can do this quickly and easily, and even obtain information from multiple applications at once.”

That statement stayed with me. It drove home a critical truth: knowledge is both power and responsibility. Even though I am not an engineer or developer, I left the exercise with a much clearer understanding of the risks we face in the digital world and why our company’s security practices need to be robust and constantly updated.

Understanding the Real Risk of MFA Attacks this 2025

Before this lab, I, like many others, considered Multi-Factor Authentication a near-foolproof security measure. The exercise shattered that assumption. We saw firsthand how, in just minutes, an attacker could impersonate a session through a well-crafted trap that captures legitimate credentials.

It was eye-opening to realize that MFA, while important, is not invulnerable. This reinforced my respect for the work our technical teams do and highlighted the importance of every role in the organization. Whether technical or non-technical, each contribution strengthens the company’s security posture.

The Human Side of a Technical Challenge this 2025

Beyond the technical insights, what I valued most was the human aspect of the experience. This activity, at the end of such an intense day, gave me the chance to see my colleagues in a different light, as mentors, allies, and teammates willing to extend a hand to ensure no one is left behind.

The spirit of collaboration was tangible. It reminded me that building a strong company is not only about numbers or projects, it’s about trust, solid relationships, and continuous learning from one another.

Gratitude and Moving Forward

I am grateful to the entire team for making this day so impactful, and especially to Ronald for his generosity in sharing his knowledge. The “Evilginx MFA Hijack Lab” didn’t just teach me about cybersecurity vulnerabilities; it deepened my connection to our company’s mission.

What we experienced on July 15 will serve as a foundation for Dapango Technologies as we continue building a secure and ethical future. If there is one takeaway, it’s this: our growth as a company depends on our ability to learn, share, and grow together, always united, constantly vigilant.

At Dapango Technologies, we strengthen cybersecurity by up to 95%, guarantee 99.9% uptime, and simplify regulatory compliance, laying the foundation for agile, future-ready growth.

We advance with purpose!

Technology that builds resilience, innovation that inspires confidence, and a lasting strategy.

Leave a Reply

Your email address will not be published.

Avatar

jhannac