An evil twin attack is a wireless threat where an attacker impersonates a legitimate access point to intercept network traffic, positioning themselves as an adversary in the middle between the victim and the network. Once a device connects to the rogue access point, the attacker can monitor, manipulate, or capture all communications passing through it.
Evil Twin Attack
An evil twin attack is just a type of machine-in-the-middle attack, or a type of adversary-in-the-middle attack, and it has to do with wireless. It's when an adversary sits in between a wireless device and the rest of the network.
This attack is not too difficult to carry out. Let's say there's an access point for this network, and I happen to know the wireless access point name, the SSID, and also the password. I can set it up on my computer, and people could connect to me just as easily as they could connect to this wireless access point.
Then maybe what I do is I send a deauth and disconnect this machine from the wireless access point, and then that machine reconnects to my machine. Now I'm an adversary in the middle. Any information that's coming to me, the evil twin, gets sent out, and then it comes back through me to get back to this end user. So now this is an adversary in the middle, and we can carry out all of the attacks that you could with an adversary in the middle.
An evil twin is where the attacker spoofs an access point. Here we've got a victim machine, and rather than connecting to the legitimate access point, instead they connect to you, who's posing as the access point. That's where the twin comes in: you're acting as a twin to them. Now you act as an adversary in the middle, and they have to go through you with their communication.
You could even trigger this by somehow disconnecting them, by sending a deauth, and then they have to connect to you, and then you have the advantage of carrying out any of the attacks that an adversary in the middle could carry out.
TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.
Explore free tools and programs →