The Rise of AiTM Phishing: Bypassing MFA at Scale
What is AiTM phishing?
Unlike traditional phishing that simply steals credentials, adversary-in-the-middle (AiTM) phishing sets up a proxy between the victim and the legitimate login page. The victim interacts with the real site through the attacker's proxy, which captures both the credentials and the session cookie generated after MFA verification.
This means that even organizations with strong MFA deployed can be compromised. The attacker doesn't bypass MFA technically: they let the user complete it and then steal the authenticated session.
What we're seeing in the field
In 2026, we've responded to a significant increase in AiTM-based compromises. Common patterns include phishing emails disguised as Microsoft 365 login notifications, fake document sharing links that redirect through AiTM proxies, QR code phishing ('quishing') that sends users to AiTM pages on mobile devices where URL inspection is harder, and increasingly convincing clone pages that are nearly indistinguishable from legitimate Microsoft login flows.
The toolkits behind these attacks (like EvilProxy and Tycoon 2FA) are now available as services, lowering the barrier for attackers.
How to defend against AiTM attacks
Implement phishing-resistant MFA methods such as FIDO2/WebAuthn hardware keys or Windows Hello for Business. These methods use cryptographic binding to the legitimate site, making AiTM proxying ineffective. Configure conditional access policies to require compliant devices and block legacy authentication. Implement token protection policies in Azure AD to bind session tokens to specific devices. Deploy advanced anti-phishing solutions that can detect AiTM proxy infrastructure. Train users to recognize the subtle signs of AiTM phishing.
Talk to a senior responder about The Rise of AiTM Phishing: Bypassing MFA at Scale.
Schedule a response callNeed incident response?
- Two-hour SLA
- Dutch senior responders