Submitted:
02 June 2026
Posted:
04 June 2026
You are already at the latest version
Abstract
Keywords:
1. Introduction
2. Methodology
2.1. Stage 1: Data Collection
- Scientific and conference literature: a review of presentations and papers from key events such as Black Hat USA (2005, 2011, 2015, 2016), DEF CON (2007), and academic publications (e.g., Case of Study: Identity Theft in a University WLAN from 2013 and ETGuard: Detecting D2D Attacks using Wireless Evil Twins from 2019).
- Security institution and government reports: analysis of official documents, including the Office of Inspector General (OIG) report of the U.S. Department of the Interior from 2020, OPCW statements from 2018, WatchGuard Threat Lab research (2021–2023), and CISA and ENISA reports from 2025–2026.
- Recent industry data from 2025–2026: CVE vulnerability reports1, vendor analyses, and data from NIST (SP 800-97), Verizon DBIR (2023–2026), and IBM X-Force Threat Intelligence.
2.2. Stage 2: Data Analysis
2.3. Stage 3: Synthesis and Original Contribution
- Classical mutation (2005–2013): long-lived rogue APs with active deauthentication and traffic sniffing.
- Hybrid mutation (2014–2019): technical integration with social engineering – phishing captive portals and D2D (Device-to-Device, i.e., direct communication between devices without infrastructure mediation), where the rogue AP serves solely for initial infection and then disappears.
- Flash mutation (2020–2026): ultra-short-lived attacks, often without the use of deauthentication (bypassing PMF), based on natural client roaming.
- Opportunistic-hybrid mutation (projected 2026+): combination of flash mutation with contextual elements and automation.
3. The Problem of Documentation and Classification of Evil Twin Attacks
3.1. Low Attack Detectability
3.2. Difficulties in Identifying and Apprehending the Perpetrator
3.3. Misclassification in Industry Reports
3.4. Impact of Protective Mechanisms on Attack Attractiveness
4. Chronological Analysis of Key Incidents and Demonstrations
4.1. Black Hat USA 2005: First Public Demonstration
4.2. DEF CON 15 (2007): The Multipot Variant
4.3. Black Hat Workshops (2011–2016): Practical Training
4.4. Case Study: University of Santiago De Guayaquil (2013)
4.5. Republican National Convention in Cleveland (2016)
4.6. GRU Operation Against the OPCW in The Hague (2018)
4.7. DOI OIG Penetration Tests (2018–2019)
4.8. ETGuard: D2D Attack Detection (2019)
4.9. WatchGuard Threat Lab Research (2021–2023)
4.9.1. Research Results
4.9.2. Critical Assessment of the TWE Standard
4.10. Attacks at Airports in Australia (2024)
4.11. Attack Warnings in Brazil (2025)
5. Authors’ Contribution: Analysis, Modelling, and Classification of the Evil Twin Attack
5.1. MITRE ATT &CK and the Evil Twin Attack
5.1.1. Position of the Evil Twin Attack in the MITRE ATT &CK Framework
- Credential Access (TA0006) – credential theft through phishing on captive portals,
- Collection (TA0009) – passive and active network traffic eavesdropping,
- Defense Evasion (TA0005) – circumvention of HTTPS protections (e.g., SSL stripping),
- Command and Control (TA0011) – integration with command and control channels,
- Lateral Movement (TA0008) – leveraging obtained credentials for lateral movement within the network.
5.1.2. Chronological Evolution of the Evil Twin Attack
5.2. Kill Chain of the Evil Twin Attack – A Conceptual Perspective
5.2.1. Evil Twin Kill Chain Stages
- [A] Reconnaissance (radio reconnaissance) – identification of SSIDs, security types, client behaviour, probe requests.
- [B] Weaponization (ET preparation)6 – configuration of the rogue AP, captive portal, and automation.
- [C] Delivery (vector delivery) – deauthentication, SSID spoofing, forced connection.
- [D] Initial Access (TA0001) – the victim connects to the rogue AP.
- [E] Credential Access (TA0006) – credential phishing, session token interception.
- [F] Collection (TA0009) – traffic sniffing, session hijacking, data interception.
- [G] Execution / Payload Delivery (optional) – malware delivery via captive portal or MITM.
- [H] Command and Control (TA0011) – C2 communication initialisation, beaconing.
- [I] Lateral Movement (TA0008) – lateral movement within the victim’s network.
- [J] Impact (TA0040) – further operational objectives of the campaign.
5.2.2. Kill Chain – MITRE ATT &CK Mapping
5.3. Evil Twin as a Campaign Initialisation Vector
5.3.1. Introduction and Concept Redefinition
5.3.2. Evil Twin and the Limitations of the Classical Technical Perspective
5.3.3. Evil Twin as a Kill Chain Initialisation Vector
5.3.4. Comparison with Other Initialisation Vectors
5.3.5. Implications for Threat Modelling and Defence
5.4. Proposed Metric: Exposure Time
5.4.1. Introduction and Motivation
5.4.2. Absence of the Temporal Dimension in MITRE ATT &CK
5.4.3. Formalisation of Exposure Time
5.4.4. Exposure Time Scale
5.4.5. Attack Profitability Model
5.4.6. Attack Effectiveness Model: The “Compromise Window” Concept
5.5. Proposed Mutation Taxonomy of the Evil Twin Attack
5.5.1. Introduction and Concept Redefinition
5.5.2. Variants Vs. Mutations
5.5.3. Key Findings
- Functional transformation: the changing function of the attack, from a simple technique to a multi-stage vector, demonstrates the mutational character of this threat.
- Attack role: the changing role in offensive campaigns enables multifunctional utilisation – not only as an Initial Access vector but as a tool initiating further techniques.
- New classification: the mutation taxonomy enables a more precise capture of the Evil Twin attack’s evolution and its adaptation to new technological challenges.
5.6. Mapping the Evil Twin Attack Beyond MITRE ATT &CK
5.6.1. Introduction and Problem Definition
5.6.2. The Radio Layer as an Attack Domain
- Reconnaissance [A]: interception of information on available APs, SSIDs, channels – a phase not covered by ATT&CK, pertaining exclusively to the radio layer.
- Weaponization [B]: configuration of the rogue AP – preparation of conditions for obtaining Initial Access.
- Delivery [C]: access point impersonation and forcing the victim’s connection – a technique not described in ATT&CK in the radio context.
5.6.3. Comparison with Existing MITRE ATT &CK Extensions
5.6.4. Implications and Conclusions
6. Hypotheses on the Evolution of the Evil Twin Attack
6.1. Introduction
6.2. Hypothesis 1 – Near-Zero Exposure Attacks
6.3. Hypothesis 2 – AI Exploitation
6.4. Hypothesis 3 – IoT Integration
6.5. Hypothesis 4 – Complex Attacks Leveraging 5G
7. Summary and Conclusions
Author Contributions
Funding
Institutional Review Board Statement
Informed Consent Statement
Data Availability Statement
Acknowledgments
Conflicts of Interest
| 1 | E.g., CVE-2018-6402: the possibility of forcing Ecobee 4 devices to deauthorize and connect to an unencrypted Wi-Fi network with the same SSID, even if the device settings specify WPA2 encryption, provided the competing network has a stronger signal. |
| 2 | NIST SP 800-97 is a key document on Wi-Fi security – it discusses rogue AP detection, beacon fingerprinting, and mutual authentication as defenses against the Evil Twin. |
| 3 | An annual ENISA threat report – in the 2024–2025 editions, attacks on Wi-Fi/5G are classified as MitM/network interception. |
| 4 | Thomas d’Otreppe de Bouvette – creator of Aircrack-ng, the most popular Wi-Fi security auditing toolkit (first version: February 2006) and the OpenWIPS-ng wireless intrusion detection system. |
| 5 | In MITRE ATT&CK, the closest techniques are: T1557 – Adversary-in-the-Middle, T1595 – Active Scanning. |
| 6 | Weaponization – a phase of the attack model (kill chain): preparation of the “attack payload,” i.e., development of tools, exploits, and fake portals. This is not yet an attack on the victim – it is the arming stage prior to logical contact. |
| 7 | Watering hole attacks are sophisticated cyberattacks in which adversaries compromise legitimate, niche websites frequently visited by a specific target group. |
| 8 | The function was intentionally employed rather than a simple product – one cannot assume that data are exfiltrated at a constant rate. For example: at the onset of the attack, may be low (observation phase), but when the user logs into their bank – increases dramatically. |
References
- Alotaibi, B.; Elleithy, K. Rogue Access Point Detection: Taxonomy, Challenges, and Future Directions. Wireless Personal Communications, 2016. [Google Scholar] [CrossRef]
- Kohlios, C.P.; Hayajneh, T. A Comprehensive Attack Flow Model and Security Analysis for Wi-Fi and WPA3. Electronics 2018, 7, 284. [Google Scholar] [CrossRef]
- Nazir, R.; Laghari, A.A.; Kumar, K.; David, S.; Ali, M. Survey on Wireless Network Security. Arch. Comput. Methods Eng. 2022, 29, 1591–1610. [Google Scholar] [CrossRef]
- Vanhoef, M.; Piessens, F. Key Reinstallation Attacks: Forcing Nonce Reuse in WPA2. In Proceedings of the Proceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Security (CCS), 2017; ACM; pp. 1313–1328. [Google Scholar] [CrossRef]
- Verizon. Data Breach Investigations Report (DBIR). Accessed. 2025. (accessed on 2026-01-15).
- Verizon. 2025 Data Breach Investigations Report. Verizon Bus. Accessed. 2025. (accessed on 2026-01-15). Technical report. [Google Scholar]
- Verizon. Credential Stuffing and Credential Abuse – DBIR Insights. Accessed. 2025. (accessed on 2026-01-15).
- Beyond Identity. Key Takeaways from the Verizon DBIR 2025, 2025. Accessed. (accessed on 2026-01-15).
- Keepnet Labs. Verizon DBIR 2025 Analysis: Key Findings. Accessed. 2025. (accessed on 2026-01-15).
- Mimecast. Verizon DBIR: Human Error Remains Top Factor. Accessed. 2025. (accessed on 2026-01-15).
- SpyCloud. Insights from the Verizon DBIR 2025, 2025. Accessed. (accessed on 2026-01-15).
- Descope. Verizon DBIR 2025: Identity and Access Trends. Accessed. 2025. (accessed on 2026-01-15).
- Conti, M.; Dragoni, N.; Lesyk, V. A Survey of Man In The Middle Attacks. IEEE Commun. Surv. Tutor. 2016, 18, 2027–2051. [Google Scholar] [CrossRef]
- National Institute of Standards and Technology. NIST Special Publication 800-97: Establishing Wireless Robust Security Networks. Accessed. 2007. (accessed on 2026-01-15). Technical report, NIST. [Google Scholar]
- Frankel, S.; Eydt, B.; Owens, L.; Scarfone, K. Establishing Wireless Robust Security Networks: A Guide to IEEE 802.11i; Accessed; NIST, 2007; (accessed on 2026-01-15)Technical Report SP 800-97. [Google Scholar]
- European Union Agency for Cybersecurity (ENISA). ENISA Threat Landscape 2025; Accessed; ENISA, 2025; (accessed on 2026-01-15)Technical report. [Google Scholar]
- European Union Agency for Cybersecurity (ENISA). ENISA Threat Landscape 2025 – Booklet; Accessed; ENISA, 2025; (accessed on 2026-01-15)Technical report. [Google Scholar]
- Banakh, R.; Nyemkova, E.; Justice, C.; Piskozub, A.; Lakh, Y. Data Mining Approach for Evil Twin Attack Identification in Wi-Fi Networks. Data 2024, 9, 119. [Google Scholar] [CrossRef]
- Wakhloo, A.; Ghergulescu, I.; Moldovan, A.N. Investigation of WiFi Security Auditing Tools for Evil Twin Attacks and Detection. In Proceedings of the Hybrid Intelligent Systems (HIS 2023); Springer, 2024; Vol. 1060, p. LNNS . [Google Scholar] [CrossRef]
- Chatzisofroniou, G.; Kotzanikolaou, P. Exploiting WiFi Usability Features for Association Attacks in IEEE 802.11: Attack Analysis and Mitigation Controls. J. Comput. Secur. 2022, 30, 357–380. [Google Scholar] [CrossRef]
- Beetle; Potter, B. Rogue Squadron: Evil Twins, 802.11intel, Radical RADIUS, and Wireless Weaponry for Windows. Black Hat. USA Accessed. 2005. (accessed on 2026-05-06). [Google Scholar]
- Gopinath, K.N. Multipot: A More Potent Variant of Evil Twin. DEF CON 15. Accessed. 2007. (accessed on 2026-05-06).
- Gopinath, K.N. Multipot: A More Potent Variant of Evil Twin – Whitepaper. Accessed. 2007. (accessed on 2026-05-06).
- Gopinath, K.N. Multipot: A More Potent Variant of Evil Twin – Presentation. Accessed. 2007. (accessed on 2026-05-06).
- Ramachandran, V. Official Instagram Profile, 2026. Accessed. (accessed on 2026-05-06).
- Ramachandran, V. Official Facebook Profile, 2026. Accessed. (accessed on 2026-05-06).
- d’Otreppe de Bouvette, T. Aircrack-ng, 2006. Official project website. Accessed. (accessed on 2026-05-06).
- Black Hat USA 2011 Archives. Accessed. 2011; (accessed on 2026-05-06).
- Advanced Wi-Fi Pentesting. Black Hat. USA 2015 Train. Accessed. 2015. (accessed on 2026-05-06).
- Advanced Wi-Fi Attack and Defense for Hackers and Pentesters. Black Hat USA 2016 Training, Accessed. 2016; (accessed on 2026-05-06).
- Briones, J.M.; Coronel, M.A.; Chavez-Burbano, P. Case of Study: Identity Theft in a University WLAN, Evil Twin and Cloned Authentication Web Interface. International Journal of Wireless and Ad Hoc Communication. Accessed. 2013. (accessed on 2026-05-06). [CrossRef]
- TrustedSec. Social Engineer Toolkit, 2026. GitHub repository. Accessed. (accessed on 2026-05-06).
- TrustedSec. Social Engineer Toolkit User Manual. Accessed. 2026. (accessed on 2026-05-06).
- Shinal, J. Fake Wi-Fi Hotspots Lure RNC Attendees. USA Today. Accessed. 2016. (accessed on 2026-05-06).
- Greenwald, G. Journalists and Trump delegates among those tricked by fake Wi-Fi networks at RNC, 2016. The Intercept. Accessed. (accessed on 2026-05-06).
- Intercept, T. Glenn Greenwald Profile, 2026. Accessed. (accessed on 2026-05-06).
- The Intercept Digital media outlet founded in 2014. Accessed. 2014. (accessed on 2026-05-06).
- Intercept, T. The Intercept, 2026. Accessed. (accessed on 2026-05-06).
- Organisation for the Prohibition of Chemical Weapons. OPCW – About Us, 2026. Official OPCW website. Accessed. (accessed on 2026-05-06).
- OPCW. Organisation for the Prohibition of Chemical Weapons. Accessed. 2026. (accessed on 2026-05-06).
- Government of the United Kingdom. Salisbury attack: UK government response, 2018. Accessed; Official UK government collection; (accessed on 2026-05-06).
- Organisation for the Prohibition of Chemical Weapons. Summary of the Report on Activities Carried Out in Support of a Request for Technical Assistance by the United Kingdom. Technical Report S/1612/2018, OPCW, 2018. Accessed. (accessed on 2026-05-06). Technical report confirming nerve agent identification.
- Organisation for the Prohibition of Chemical Weapons. Report of the OPCW Fact-Finding Mission in Syria Regarding the Incident of Alleged Use of Chemical Weapons in Douma. Technical Report S/1731/2019, OPCW, 2019. Final report. Accessed. (accessed on 2026-05-06).
- Federal Bureau of Investigation. Aleksei Sergeyevich Morenets, 2026. Accessed. (accessed on 2026-05-06).
- UK Sanctions List – Aleksei Morenets, 2026. Accessed. (accessed on 2026-05-06).
- Federal Bureau of Investigation. Evgenii Mikhaylovich Serebriakov. Accessed. 2026. (accessed on 2026-05-06).
- OpenSanctions Entry – Evgenii Serebriakov. Accessed. 2026. (accessed on 2026-05-06).
- Federal Bureau of Investigation. Oleg Mikhaylovich Sotnikov, 2026. Accessed. (accessed on 2026-05-06).
- OpenSanctions. Oleg Mikhaylovich Sotnikov. Accessed. 2026; (accessed on 2026-05-06).
- Federal Bureau of Investigation. Alexey Valerevich Minin, 2026. Accessed. (accessed on 2026-05-06).
- OpenSanctions. Alexey Valerevich Minin. Accessed. 2026. (accessed on 2026-05-06).
- Lowenthal, M.M. Intelligence: From Secrets to Policy, 8th ed.; CQ Press: Washington, DC, 2020. [Google Scholar]
- Government of the United Kingdom. Minister for Europe statement: Attempted hacking of the OPCW by Russian military intelligence. Accessed. 2018. (accessed on 2026-05-06).
- OPCW. EC-89 United States National Statement, 2018. Accessed. (accessed on 2026-05-06).
- BBC News. Russia cyber-plots: US, UK and Netherlands allege attacks. Accessed. 2018. (accessed on 2026-05-06).
- Intelligence, CrowdStrike. FANCY BEAR (APT28): A Window into Russia’s Cyber Espionage Operations. Technical report, CrowdStrike. Accessed. 2016. (accessed on 2026-05-06). Threat intelligence report.
- U.S. Department of the Interior Office of Inspector General. Evil Twins, Eavesdropping, and Password Cracking: How OIG Successfully Attacked the U.S. Department of the Interior’s Wireless Networks. Accessed. 2020. (accessed on 2026-05-06).
- GovInfo. Evil Twins, Eavesdropping, and Password Cracking. Accessed. 2020. (accessed on 2026-05-06).
- Jain, V.; Laxmi, V.; Gaur, M.S.; Mosbah, M. ETGuard: Detecting D2D Attacks Using Wireless Evil Twins. Accessed. 2019, [1903.05843. (accessed on 2026-05-06).
- Shrivastava, P.; Jamal, M.S.; Kataoka, K. EvilScout: Detection and Mitigation of Evil Twin Attack in SDN Enabled WiFi. IEEE Trans. Netw. Serv. Manag. 2020, 17, 89–102. [Google Scholar] [CrossRef]
- Kitisriworapan, S.; Jansang, A.; Phonphoem, A. Client-Side Rogue Access-Point Detection Using a Simple Walking Strategy and Round-Trip Time Analysis. EURASIP J. Wirel. Commun. Netw. 2020, 2020, 252. [Google Scholar] [CrossRef]
- da Silva, L.M.; Andreghetti, V.M.; Romero, R.A.F.; Branco, K.R.L.J.C. Analysis and Identification of Evil Twin Attack through Data Science Techniques Using AWID3 Dataset. In Proceedings of the Proceedings of the 6th International Conference on Machine Learning and Machine Intelligence (MLMI 2023), 2023; ACM; pp. 168–175. [Google Scholar] [CrossRef]
- WatchGuard Technologies. WatchGuard Technologies. Accessed. 2026; (accessed on 2026-05-06).
- WatchGuard Technologies. Six Wi-Fi Attacks Impacting Hotel Guests. Accessed. 2026. (accessed on 2026-05-06).
- WatchGuard Technologies. Exposed: Networks Vulnerable to Evil Twin Attacks. Accessed. 2026. (accessed on 2026-05-06).
- WatchGuard Technologies. Trusted Wireless Environment. Accessed. 2026. (accessed on 2026-05-06).
- Messer, P. Rogue Access Points, 2026. Accessed. (accessed on 2026-05-06).
- Miercom. Miercom, 2026. Accessed. (accessed on 2026-05-06).
- Australian Federal Police. Man charged over creation of Evil Twin free Wi-Fi networks to access personal data. Accessed. 2024. (accessed on 2026-05-06).
- Security Affairs. Evil Twin WiFi attack on plane, 2024. Accessed. (accessed on 2026-05-06).
- TechTudo. Depois que conheci esse golpe, nunca mais usei redes de Wi-Fi públicas. Accessed. 2025. (accessed on 2026-05-06).
- Digital, Olhar. Cuidado com o Evil Twin! Conheça o golpe do Wi-Fi falso e veja como se prevenir. Accessed. 2025. (accessed on 2026-05-06).
- Canaltech. Agências dos EUA e Europa recomendam desligar Wi-Fi ao sair de casa. entenda. Accessed. 2025. (accessed on 2026-05-06).
- Jana, S.; Kasera, S.K. On Fast and Accurate Detection of Unauthorized Wireless Access Points Using Clock Skews. In Proceedings of the Proceedings of the 14th ACM International Conference on Mobile Computing and Networking (MobiCom). ACM, 2008; pp. 104–115. [Google Scholar] [CrossRef]
- Han, H.; Sheng, B.; Tan, C.C.; Li, Q.; Lu, S. A Timing-Based Scheme for Rogue AP Detection. IEEE Trans. Parallel Distrib. Syst. 2011, 22, 1912–1925. [Google Scholar] [CrossRef]
- Lanze, F.; Panchenko, A.; Ponce-Alcaide, I.; Engel, T. Undesired Relatives: Protection Mechanisms Against the Evil Twin Attack in IEEE 802.11. In Proceedings of the Proceedings of the 10th ACM International Symposium on QoS and Security for Wireless and Mobile Networks (Q2SWinet), 2014; ACM; pp. 87–98. [Google Scholar] [CrossRef]
- Schepers, D.; Ranganathan, A.; Vanhoef, M. On the Robustness of Wi-Fi Deauthentication Countermeasures. In Proceedings of the Proceedings of the 15th ACM Conference on Security and Privacy in Wireless and Mobile Networks (WiSec ’22), 2022; ACM; pp. 245–256. [Google Scholar] [CrossRef]
- Lounis, K.; Ding, S.H.H.; Zulkernine, M. Cut It: Deauthentication Attacks on Protected Management Frames in WPA2 and WPA3. In Proceedings of the Foundations and Practice of Security (FPS 2021); Springer, 2022; Vol. 13291, LNCS, pp. 235–251. [Google Scholar] [CrossRef]
- Cisco Systems. Cisco Adaptive Wireless Intrusion Prevention System. Accessed. 2026. (accessed on 2026-05-07).
- Cisco Systems. Cisco CleanAir Technology. Accessed. 2026. (accessed on 2026-05-07). [Google Scholar]
- Cheng, Y.; Liao, X.; Wu, B. Who is Peeping at Your Passwords at Starbucks? — To Catch an Evil Twin Access Point. In Proceedings of the Proceedings of the 2010 IEEE/IFIP International Conference on Dependable Systems and Networks (DSN); IEEE, 2010; pp. 323–332. [Google Scholar] [CrossRef]
- Monica, D.; Ribeiro, C. WiFiHop — Mitigating the Evil Twin Attack through Multi-hop Detection. Proceedings of the Proceedings of the 16th European Symposium on Research in Computer Security (ESORICS 2011) 2011, Vol. 6879, LNCS, 21–39. [Google Scholar] [CrossRef]
- Yang, C.; Song, Y.; Gu, G. Active User-Side Evil Twin Access Point Detection Using Statistical Techniques. IEEE Trans. Inf. Forensics Secur. 2012, 7, 1638–1651. [Google Scholar] [CrossRef]
- Nakhila, O.; Zou, C. User-Side Wi-Fi Evil Twin Attack Detection Using Random Wireless Channel Monitoring. In Proceedings of the Proceedings of the 2016 IEEE Military Communications Conference (MILCOM); IEEE, 2016; pp. 1243–1248. [Google Scholar] [CrossRef]
- Kuo, E.C.; Chang, M.S.; Kao, D.Y. User-Side Evil Twin Attack Detection Using Time-Delay Statistics of TCP Connection Termination. In Proceedings of the Proceedings of the 20th International Conference on Advanced Communication Technology (ICACT); IEEE, 2018; pp. 1–6. [Google Scholar] [CrossRef]
- Hewlett Packard Enterprise. Aruba RFProtect Wireless Intrusion Protection. Accessed. 2026. (accessed on 2026-05-07).
- Cisco Systems. Cisco Meraki Air Marshal, 2026. Accessed. (accessed on 2026-05-07).
- Vanhoef, M.; Ronen, E. Dragonblood: Analyzing the Dragonfly Handshake of WPA3 and EAP-pwd. In Proceedings of the 2020 IEEE Symposium on Security and Privacy (SP), 2020; pp. 517–533. [Google Scholar] [CrossRef]
- Halbouni, A.; Ong, L.Y.; Leow, M.C. Wireless Security Protocols WPA3: A Systematic Literature Review. IEEE Access 2023, 11, 112438–112450. [Google Scholar] [CrossRef]
- Chatzoglou, E.; Kampourakis, G.; Kolias, C. How is Your Wi-Fi Connection Today? DoS Attacks on WPA3-SAE. J. Inf. Secur. Appl. 2022, 64, 103058. [Google Scholar] [CrossRef]
- Kamble, A.; Kshirsagar, D. Feature Selection in Wireless Intrusion Detection System for Evil Twin Attack Detection. In Proceedings of the Proceedings of the 3rd International Conference on Innovative Sustainable Computational Technologies (CISCT); IEEE, 2023; pp. 1–6. [Google Scholar] [CrossRef]
- Liu, X.; Yang, J.; Chen, Y.; Guo, X.; Xie, Y. Real-Time Identification of Rogue WiFi Connections in the Wild. IEEE Access 2022, 10, 126896–126910. [Google Scholar] [CrossRef]
- Thankappan, M.; Rifa-Pous, H.; Garrigues, C. A Signature-Based Wireless Intrusion Detection System Framework for Multi-Channel Man-in-the-Middle Attacks Against Protected Wi-Fi Networks. IEEE Access 2024, 12, 23096–23121. [Google Scholar] [CrossRef]
- Thankappan, M.; Rifa-Pous, H.; Garrigues, C. A distributed and cooperative signature-based intrusion detection system framework for multi-channel man-in-the-middle attacks against protected Wi-Fi networks. Int. J. Inf. Secur. 2024, 23, 3457–3479. [Google Scholar] [CrossRef]
- Feng, X.; Li, Q.; Sun, K.; Yang, Y.; Xu, K. Man-in-the-Middle Attacks without Rogue AP: When WPAs Meet ICMP Redirects. In Proceedings of the 2023 IEEE Symposium on Security and Privacy (SP), 2023; pp. 694–709. [Google Scholar] [CrossRef]
- Muthalagu, R.; Sanjay, S. Evil Twin Attack Mitigation Techniques in 802.11 Networks. Int. J. Adv. Comput. Sci. Appl. (IJACSA) 2021, 12. [Google Scholar] [CrossRef]
- Louca, C.; Peratikou, A.; Stavrou, S. A Novel Evil Twin MiTM Attack through 802.11v Protocol Exploitation. Comput. Secur. 2023, 130, 103261. [Google Scholar] [CrossRef]
- Vanhoef, M. Fragment and Forge: Breaking Wi-Fi Through Frame Aggregation and Fragmentation. In Proceedings of the 30th USENIX Security Symposium (USENIX Security 21), 2021; pp. 161–178. [Google Scholar]
- Braga, D.D.A.; Kulatova, N.; Sabt, M.; Fouque, P.A.; Bhargavan, K. From Dragondoom to Dragonstar: Side-channel Attacks and Formally Verified Implementation of WPA3 Dragonfly Handshake. In Proceedings of the 2023 IEEE 8th European Symposium on Security and Privacy (EuroSP), 2023; pp. 707–723. [Google Scholar] [CrossRef]
- Kumar, Y.; Kumar, V. A Systematic Review on Intrusion Detection System in Wireless Networks: Variants, Attacks, and Applications. Wireless Personal Communications, 2023. [Google Scholar] [CrossRef]
- Nivaashini, M.; Thangaraj, P. Computational Intelligence Techniques for Automatic Detection of Wi-Fi Attacks in Wireless IoT Networks. Wirel. Netw. 2021, 27, 2761–2784. [Google Scholar] [CrossRef]



| Year | Type | Event / Significance |
|---|---|---|
| 2005 | Demo | Black Hat USA — “Rogue Squadron” (Beetle, Potter); first public ET demonstration |
| 2007 | Demo | DEF CON 15 — “Multipot”; multi-point ET variant bypassing WIPS |
| 2008 | Tool | KARMA — ET automation through probe request listening |
| 2011 | Demo | Black Hat — Ramachandran workshops; practical ET training |
| 2013 | Tool | MANA — KARMA extension incorporating WPA-Enterprise attacks |
| 2013 | Case study | University of Santiago de Guayaquil — ET + SET + cloned captive portal |
| 2016 | Incident | Avast at RNC, Cleveland — 1200+ victims, 68.3% identities exposed |
| 2018 | Incident | GRU vs OPCW, The Hague — confirmed intelligence operation (close-access) |
| 2018 | Standard | WPA3 + PMF (IEEE 802.11w) — management frame protection |
| 2018–19 | Incident | DOI OIG, USA — ET test across 91 government locations; no detection |
| 2018 | Standard | Trusted Wireless Environment — 6 Wi-Fi threat categories |
| 2019 | Research | ETGuard (Jain et al.) — ET detection based on beacon fingerprinting |
| 2021–23 | Research | WatchGuard Threat Lab — tests across 45+ locations; 91% vulnerable |
| 2024 | Incident | Australia — ET attacks at airports; 7-year and 4-month sentence |
| 2025 | Incident | Brazil — media warnings against ET in public networks |
| Mechanism | Year | Protection Type | Scope of Operation | Limitations Against ET |
|---|---|---|---|---|
| WPA2-Enterprise (EAP-TLS) | 2004 | Mutual authentication | RADIUS certificate verification; encrypted transmission | Requires PKI; not for public networks; client may accept forged cert. |
| Clock skew / HW FP | 2008–14 | Passive detection | AP ID via TSF clock skew [74,75] or HW traits [76] | Calibration needed; environmental sensitivity; limited scalability |
| PMF (802.11w) | 2009/18 | Frame protection | Blocks deauth/disassoc spoofing; mandatory in WPA3 [77] | No protection against ET without deauth (new clients, open nets, auto-connect) [78] |
| WIPS (dedicated radio) | 2010+ | Active det./blocking | Continuous scanning; rogue AP detection; containment frames | Dedicated HW with 3rd radio; ineffective for short ET (<60 s); cost |
| Cisco wIPS / CleanAir | 2010+ | Spectrum + WIPS | Interference and rogue AP detection at spectrum level [79,80] | Cisco HW only; no protocol-level attack detection |
| Client-side detection | 2010–18 | Active/passive | Route analysis [81]; WiFiHop [82]; stats [83]; channel mon. [84]; TCP delay [85] | Network-dependent; limited in high-load networks |
| Aruba RFProtect | 2012+ | Multi-sensor | Threat classification; auto rogue AP containment [86] | Sensor density dependent; false positives in multi-tenant env. |
| Meraki Air Marshal | 2014+ | Cloud WIPS | Auto SSID spoof detection; cloud mgmt [87] | Requires cloud; limited local policy control |
| WPA3-SAE | 2018 | Encryption | No offline dictionary attacks; forward secrecy; per-session protection [88,89] | Does not verify AP identity — encrypted connection to rogue AP possible [90] |
| TWE (6 categories) | 2018 | Comprehensive standard | Auto detection and blocking of 6 Wi-Fi threat types; HW cert. | Single vendor (WatchGuard); certified HW required; no independent audit |
| ETGuard | 2019 | Passive fingerprinting | Beacon frame sequence analysis; real-time pre-assoc. detection | Academic prototype; 802.11a/b/g only; needs production validation |
| EvilScout (SDN) | 2020 | Detection + mitigation | SDN-based centralised ET detection and containment [60] | Requires SDN; not for traditional networks |
| ML-based WIDS | 2022–23 | ML classification | Feature sel. + classifiers on AWID/AWID3 [62,91]; CSI FP [92] | Training data needed; limited cross-HW generalisability |
| Sig.-based MC-MitM IDS | 2024 | Passive signature-based | Distributed multi-ch. MitM detection [93,94]; TPR≥90% | 60 s delay; sensor deployment; known signatures only |
| Period | Variant / Platform | Data Theft | D./D. | MITRE Tactics | Cases |
|---|---|---|---|---|---|
| 2004–07 | Classical ET + deauth; laptop + Wi-Fi card | Sniffing | V.L/V.L | TA0001, TA0009 | — |
| 2008–13 | KARMA/MANA + portal; Pineapple Mk4 | Portal phish. + sniff. | L/L | TA0001, TA0006 | Conf. |
| 2014–17 | SSL strip / HSTS bypass; Pineapple + bettercap | MitM, cred. harv. | L–M/M | TA0006, TA0009, TA0005 | RNC ’16 |
| 2018–19 | Close-access ET, D2D; spec. HW / RPi | 802.1X cred. theft | M–H/M | TA0001, TA0006, TA0008 | OPCW, DOI |
| 2020–22 | Ultra-short (<60 s), PMF bypass; RPi 4/Zero | Malware via portal | H/H | TA0001, TA0005, TA0011 | Few publ. |
| 2023–25 | Flash ET, AI portals; phone + Pineapple | AI phish., token theft | V.H/V.H | TA0001, TA0006, TA0009, TA0011 | AU ’24, BR ’25 |
| Stage | Name | Layer | MITRE ATT&CK | Description |
|---|---|---|---|---|
| [A] | Reconnaissance | Radio | (pre-TA0001) | SSID scanning, probe request analysis, client behaviour profiling |
| [B] | Weaponization | Radio | (pre-TA0001) | Rogue AP configuration, captive portal preparation, automation setup |
| [C] | Delivery | Radio | (pre-TA0001) | Deauthentication, SSID spoofing, forced client connection |
| [D] | Initial Access | Network | TA0001 | Victim connects to rogue AP — critical inflection point |
| [E] | Credential Access | Application | TA0006 | Phishing via captive portal, session token interception |
| [F] | Collection | Network | TA0009 | Traffic sniffing, session hijacking, data interception |
| [G] | Execution / Payload Delivery | Application | TA0002 | Malware delivery via portal or MitM (optional) |
| [H] | Command & Control | Network | TA0011 | C2 channel initialisation, beaconing |
| [I] | Lateral Movement | Network | TA0008 | Movement within victim’s network using obtained credentials |
| [J] | Impact | Application | TA0040 | Further campaign objectives, data exfiltration, disruption |
| Period / Mutation | Dominant Char. | Kill Chain | MITRE Tactics | Notes |
|---|---|---|---|---|
| 2004–07 Classical ET | AP spoof, sniffing | A→B→C→D→F | TA0001, TA0009 | Simple, passive |
| 2008–13 KARMA/MANA | SSID auto, captive portal | A→...→E→F | TA0001, TA0006, TA0009 | Active credential theft |
| 2014–17 SSL stripping | Active MITM, HTTPS bypass | A→...→F→G | +TA0005 | Increased complexity |
| 2018–19 Close-access | Short-lived, prepayload | A→...→G→H | +TA0011 | ET as campaign initiator |
| 2020–22 Ultra-short ET | PMF bypass, mobile D2D | A→...→I | +TA0008 | Lateral movement |
| 2023–25 Flash ET + AI | AI phishing, cred. stuffing | A→...→J | +TA0040 | Full kill chain |
| Range | Level | Typical Attack Character | Detectability | Profitability |
|---|---|---|---|---|
| 0–10 s | Very short | Flash / fully automated (PMKID, rapid KARMA/MANA) | Very low | Very high |
| 10–30 s | Short | Automated ET + deauth / probe response spoofing | Low | High |
| 30–60 s | Medium | Contemporary automated ET (full beacon/probe/deauth emission) | Medium | Moderate |
| 60–120 s | Long | Classical ET with captive portal or manual interaction | High | Low |
| > 120 s | Very long | Persistent rogue AP (presence maintenance) | Very high | Very low |
| Scenario / Attack Mutation | Range | Ref. Value |
|---|---|---|
| Aggressive variants with KARMA/MANA + auto-connect | 0.70–0.90 | 0.85 |
| Flash mutation without deauthentication (strong signal + roaming) | 0.10–0.40 | 0.35 |
| Classical / hybrid with captive portal | 0.20–0.50 | 0.25–0.35 |
| Mass deauthentication (pre-PMF) | 0.80–0.95 | 0.90 |
| Enterprise environments WPA3-Enterprise + certificates | 0.05–0.20 | 0.10 |
Disclaimer/Publisher’s Note: The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor(s) and not of MDPI and/or the editor(s). MDPI and/or the editor(s) disclaim responsibility for any injury to people or property resulting from any ideas, methods, instructions or products referred to in the content. |
© 2026 by the authors. Licensee MDPI, Basel, Switzerland. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license (http://creativecommons.org/licenses/by/4.0/).