Back to glossary

Evil twin attack

2 min read

In wireless security, an evil twin attack sets up a rogue access point that clones the name of a legitimate network, so nearby devices connect to the attacker instead. It is the exercise a wireless test runs and the one that lands clearly in a presentation to management, because it needs no vulnerability in the real network at all.

July 29, 2026
Compartir:

How it works

Wi-Fi clients identify a network by its name, and many are configured to reconnect automatically to a name they have used before. An evil twin exploits that. The attacker stands up an access point broadcasting the same name as a network the targets trust, often with a stronger signal, so devices in range associate with it instead of the real one. From there the attacker is in the middle of the connection: they can present a captive portal that asks for credentials, harvest whatever the device tries to send, or relay traffic to observe it. An evil twin is a specific case of a rogue access point. A rogue access point is any unauthorised one; an evil twin is the one that clones a legitimate network’s name to lure its clients.

What goes wrong

The reason this works is that it attacks the client, not the network, so the organisation’s careful configuration of the real access point is bypassed entirely. On engagements the failure is a client set to auto-join a familiar name without verifying the network is genuine, and, on enterprise networks, 802.1X clients that do not validate the server’s certificate, which lets the impostor complete the authentication and capture the credentials. From the attacker’s side, no exploit is needed against the infrastructure: the whole attack lives in the client’s willingness to trust a name. It also lands well in a management briefing, because a captured login demonstrates the risk without any jargon.

Where this shows up in an audit

We test whether clients will trust an impostor: whether devices auto-join a cloned network, whether enterprise clients validate the authentication server’s certificate, and what an evil twin can capture once a device connects. The finding is written against the client-side trust gap, with the capture demonstrated, because the fix is client configuration and user behaviour rather than the access point. It sits alongside general adversary-in-the-middle techniques and the wireless posture measured against WPA3. This is part of how we test whether your clients trust an impostor.

¿Quieres ver cómo trabajamos en Asperis Security?

Agenda 30 minutos con uno de nuestros especialistas. Revisamos tu stack y te decimos qué conviene probar primero.