TechKnowSurge
VideoSecurityFree

Evil Twin

An evil twin attack is a wireless threat where an attacker impersonates a legitimate access point to intercept network traffic, positioning themselves as an adversary in the middle between the victim and the network. Once a device connects to the rogue access point, the attacker can monitor, manipulate, or capture all communications passing through it.

Complete this video to capture a CTF flag worth 1 point.

About this video

An evil twin attack is a wireless adversary-in-the-middle technique in which an attacker clones a legitimate access point by replicating its SSID and credentials, making the rogue access point appear identical to the real one. Devices on the network may connect to the attacker's access point naturally, or the attacker can accelerate this by sending deauthentication frames to forcibly disconnect targets from the legitimate access point, prompting them to reconnect to the evil twin instead. Once a victim's device is associated with the rogue access point, all of that device's network traffic passes through the attacker before reaching its intended destination and returning the same way, giving the attacker full visibility into the communication stream. From this position, the attacker can execute the full range of adversary-in-the-middle attacks, including credential harvesting, session hijacking, traffic manipulation, and SSL stripping, making the evil twin a versatile and relatively low-barrier threat in any environment that relies on wireless connectivity.

What you'll learn

What's covered

Evil Twin Attack

Key terms

Wireless Access Point
WAP
A device that allows wireless devices to connect to a wired network using Wi-Fi.
Spoofing
An attack where an adversary impersonates a trusted entity by falsifying data such as an IP address or email address.
Man-in-the-Middle Attack
MitM
An attack where an adversary secretly intercepts and potentially alters communications between two parties.
Evil Twin Attack
An attack in which a rogue wireless access point mimics a legitimate one to intercept client connections and enable an adversary-in-the-middle attack.
Deauthentication Frame
A wireless management frame sent to forcibly disconnect a client from a legitimate access point, often used in evil twin attacks to compel the client to reconnect to a rogue access point.
Service Set Identifier
SSID
The network name broadcast by a wireless access point that clients use to identify and connect to a specific Wi-Fi network. SSIDs can be up to 32 characters long and are transmitted in beacon frames; networks may be configured to suppress SSID broadcasting for limited obscurity.

Topics

Evil Twin Wireless Security Adversary In The Middle Rogue Access Point Deauthentication Network Security Cybersecurity

Transcript

An evil twin attack is just a type of machine-in-the-middle attack, or a type of adversary-in-the-middle attack, and it has to do with wireless. It's when an adversary sits in between a wireless device and the rest of the network.

How the Attack Works

This attack is not too difficult to carry out. Let's say there's an access point for this network, and I happen to know the wireless access point name, the SSID, and also the password. I can set it up on my computer, and people could connect to me just as easily as they could connect to this wireless access point.

Then maybe what I do is I send a deauth and disconnect this machine from the wireless access point, and then that machine reconnects to my machine. Now I'm an adversary in the middle. Any information that's coming to me, the evil twin, gets sent out, and then it comes back through me to get back to this end user. So now this is an adversary in the middle, and we can carry out all of the attacks that you could with an adversary in the middle.

The Attack in Summary

An evil twin is where the attacker spoofs an access point. Here we've got a victim machine, and rather than connecting to the legitimate access point, instead they connect to you, who's posing as the access point. That's where the twin comes in: you're acting as a twin to them. Now you act as an adversary in the middle, and they have to go through you with their communication.

You could even trigger this by somehow disconnecting them, by sending a deauth, and then they have to connect to you, and then you have the advantage of carrying out any of the attacks that an adversary in the middle could carry out.

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →