Attack technique

Adversary-in-the-Middle (AiTM) Phishing

A real-time phishing technique that uses a proxy server to relay a victim's login between them and the real website, stealing the session cookie and bypassing most multi-factor authentication.

Definition

Adversary-in-the-middle (AiTM) phishing is a real-time phishing technique in which an attacker positions a reverse proxy between a victim and the legitimate website they are logging into, typically Microsoft 365 or Google Workspace. The proxy forwards every keystroke and prompt back and forth so the login appears completely normal to the victim, including any multi-factor authentication challenge, but once the session is established the attacker captures the resulting session cookie and uses it to sign in as the victim without ever needing the password again.

Unlike a traditional phishing page that only harvests a static username and password, an AiTM kit, commonly built on Evilginx-style reverse-proxy frameworks, sits between the victim and the real login service for the entire authentication flow. The victim types their real password into what looks like a normal Microsoft or Google login page, the proxy passes it straight through to the genuine site, and if the account has MFA enabled the victim also completes that step normally, unaware the proxy is relaying it. The moment authentication succeeds, the real site issues a session token, and the proxy silently captures a copy of it before handing the victim their expected inbox or dashboard.

This is what makes AiTM so damaging: the stolen session cookie represents an already-authenticated session, so the attacker does not need the password again and does not need to solve MFA at all, since the victim already did it for them. With that cookie, the attacker can open the victim's mailbox in their own browser, often from a different country, and it frequently goes unnoticed because the session appears legitimate to the application. For banks and other regulated institutions in Indonesia, AiTM attacks against employee or partner Microsoft 365 accounts have become a common precursor to business email compromise, since access to a real corporate mailbox is far more convincing than any spoofed email.

Because AiTM specifically defeats one-time codes and push-based MFA, the most effective defense is phishing-resistant authentication such as FIDO2 security keys or passkeys, which cryptographically bind the login to the legitimate domain and cannot be relayed through a proxy. Conditional access policies that flag logins from unfamiliar IP ranges or impossible travel, short session token lifetimes, and continuous access evaluation all reduce the window an attacker has to exploit a stolen cookie. Just as importantly, employees still need to recognize the lookalike domains AiTM kits rely on, since the entire attack starts with a convincing phishing link.

At a glance

Severity
High
Prevalence
Growing rapidly
Primary targets
Microsoft 365 and Google Workspace accounts
Also known as
AiTM, man-in-the-middle phishing

How it works

  1. 1

    Lure delivery: the victim receives a phishing email or message with a link to a near-identical fake Microsoft 365 or Google login page.

  2. 2

    Proxy relay: a reverse-proxy toolkit sits between the victim and the real site, forwarding the username and password through in real time.

  3. 3

    MFA relay: any one-time code or push approval the victim enters is also passed straight through, so it satisfies the real site's MFA check.

  4. 4

    Session capture: once the real site authenticates the session, the proxy silently captures the resulting session cookie or token.

  5. 5

    Session replay: the attacker loads the stolen cookie into their own browser and is signed in as the victim without needing the password again.

  6. 6

    Follow-on abuse: the attacker reads mail, sets forwarding rules, or launches business email compromise from inside the compromised mailbox.

Warning signs

  • A login page that looks correct but sits on an unfamiliar or slightly misspelled domain
  • Being asked to complete MFA for a login you did not initiate
  • Unexpected "new sign-in" or "unusual activity" alerts from Microsoft or Google shortly after clicking a link
  • Browser warnings about certificate mismatches on a login page
  • A login flow that redirects through an unexpected intermediate domain before reaching the real site

How to defend

  • Adopt phishing-resistant MFA such as FIDO2 security keys or passkeys, which cannot be relayed through a proxy
  • Enforce conditional access policies that block or challenge logins from unfamiliar locations or impossible travel
  • Shorten session token lifetimes and enable continuous access evaluation where supported
  • Train employees to verify the exact domain in the address bar before entering credentials, even when a page looks identical to the real one
  • Monitor for and revoke suspicious active sessions immediately when account compromise is suspected
  • Run realistic phishing simulations that include lookalike-domain scenarios to build the habit of checking the URL

Real-world example

A relationship manager at a Jakarta bank clicks a link in an email claiming her Microsoft 365 password is expiring. The page looks identical to the real login and even prompts her for the approval code from her authenticator app, which she enters without hesitation. Behind the scenes, an AiTM proxy relayed both her password and the approval through to the real Microsoft servers, then captured the resulting session cookie. Minutes later, the attacker is reading her mailbox from an unfamiliar location, with a valid session and no MFA prompt required.

How Claro helps

Claro's phishing simulations include lookalike-domain scenarios that mirror how AiTM kits present a near-perfect copy of a Microsoft 365 or Google login screen, so employees learn to check the address bar even when a page looks and behaves exactly like the real thing. Results feed each user's risk score and trigger just-in-time training, helping Indonesian financial and government tenants demonstrate OJK and ISO 27001 awareness controls against this fast-growing MFA bypass technique.

Frequently asked questions

What is Adversary-in-the-Middle (AiTM) Phishing?

Adversary-in-the-middle (AiTM) is a phishing technique where attacker infrastructure sits between the user and the real site, relaying traffic in real time to steal both the password and the session cookie, which lets it bypass many forms of multi-factor authentication.

Does adversary-in-the-middle phishing steal my password?

It usually does, since the proxy relays your real password to the genuine site, but the more damaging theft is the session cookie issued after login. That cookie lets the attacker access your account without needing your password or MFA again.

Why does AiTM phishing bypass multi-factor authentication?

Because the proxy relays the entire login flow in real time, including any one-time code or push approval you provide. You are completing MFA for the real site, but the attacker captures the resulting authenticated session anyway.

How is AiTM different from a normal phishing page?

A normal phishing page only captures whatever you type into it, typically a username and password. An AiTM kit acts as a live proxy for the entire session, so it also captures the session token issued after successful login, which defeats most MFA.

What actually stops AiTM phishing?

Phishing-resistant authentication methods such as FIDO2 security keys and passkeys are the most reliable defense, because they cryptographically verify the exact domain being logged into and cannot be relayed through a proxy the way one-time codes can.

Reduce your human risk

Claro measures and lowers the risk these terms describe, in English and Bahasa Indonesia.

Request a demo