What is Adversary-in-the-Middle (AiTM)? Session Hijacking at Scale

by Jordan Dean on Oct 05, 2026

hooded-hackers-working-with-computer-data-2026-09-21-23-31-13-utc

For years, the security industry's answer to phishing was simple: turn on multi-factor authentication. Even if someone stole your password, they would still need the code on your phone. But then Adversary-in-the-Middle (AiTM) attacks broke that promise. Instead of stealing your password and hoping for the best, an AiTM attacker lets you log in to the real site yourself, MFA and all, and then walks off with the session you just created.

The result is an attack that turns a single click on a phishing link into full account access, and that can be run against thousands of organizations at once using off-the-shelf kits.

What AiTM Actually Means

At its core, AiTM describes an attacker who inserts themselves into a conversation between two parties so they can watch, capture, or alter what passes between them. MITRE ATT&CK catalogs it as technique T1557, noting that attackers can abuse ordinary network protocols such as ARP, DNS, and LLMNR to route a victim's traffic through a system they control. MITRE also calls out that this position can be used to grab access tokens and session cookies, which is exactly where the modern version of the attack gets its teeth.

If that sounds like the classic man-in-the-middle (MitM) attack, it is. AiTM is the same idea with a sharper focus. As SentinelOne explains, older MitM attacks often meant listening in on unencrypted traffic, like an open coffee-shop Wi-Fi network. AiTM puts the emphasis on an attacker who actively manipulates the exchange, and in today's usage it most often refers to targeted phishing operations built to defeat strong authentication.

The key differences come down to a few points:

  • Passive vs. active. Classic MitM is often about eavesdropping, whereas AiTM is about participating in the conversation and changing its outcome.
  • Opportunistic vs. targeted. Traditional MitM tends to wait for victims on insecure networks. AiTM campaigns go looking for them with tailored phishing lures.
  • Passwords vs. sessions. The prize in a modern AiTM attack is not just your password. It is the authenticated session token that proves you already logged in.

How an AiTM Phishing Attack Works

To understand why AiTM is so effective, you need to know one essential fact about the web. After you sign in, the site hands your browser a session cookie so you don't have to re-authenticate on every page. According to Microsoft's security research team, that cookie is the server's proof that you already passed authentication. Whoever holds it, the server treats as you.

An AiTM attack is built to steal that cookie. Here is how a typical run plays out:

  1. The lure. The victim receives a phishing message: a fake voicemail notice, a shared document, an invoice. In the campaign Microsoft tracked, an HTML attachment claimed a voice message was downloading, then quickly redirected the user.
  2. The mirror. Instead of a hand-built fake login page, the victim lands on a reverse proxy. It relays every request to the real sign-in service and every response back, so the page looks identical, often down to the company's own branding. The web address is the only giveaway.
  3. Two encrypted tunnels. The proxy holds one TLS session with the victim and a second with the real website. The padlock icon still appears, because each leg really is encrypted. The attacker just sits between them.
  4. The victim does the work. The user types their password and approves the MFA prompt. The real service is satisfied and issues a valid session cookie.
  5. The handoff. The proxy grabs the password and, more importantly, the session cookie as it passes through. The victim gets redirected to the legitimate site and suspects nothing.
  6. The replay. The attacker loads the stolen cookie into their own browser and is now signed in as the victim, with no password or MFA prompt required.

Microsoft stresses that this is not a flaw in MFA itself; the MFA check worked perfectly. The attacker simply waited until after it was done and took the result.

Why it Happens at Scale: Phishing-as-a-Service

A reverse-proxy phishing setup used to take real skill; not as much anymore. Open-source frameworks such as Evilginx2, Modlishka, and Muraena automated much of the work, and MITRE lists evilginx2 as a known AiTM tool that captures passwords, tokens, and session cookies. Criminal entrepreneurs then took the next step: packaging the whole thing as a subscription service.

The clearest example is Tycoon 2FA. Microsoft's March 2026 analysis found that after appearing in August 2023, campaigns built on the kit sent tens of millions of phishing messages and reached more than 500,000 organizations every month. Microsoft attributes its development to a group it tracks as Storm-1747, and says it let even low-skilled criminals get around MFA.

What made Tycoon 2FA feel less like a hacking tool and more like a SaaS product:

  • Cheap rentals. Microsoft observed access starting around $120 for 10 days and $350 for a month, sold through Telegram and Signal.
  • A point-and-click dashboard. Customers picked a login theme (Microsoft 365, Outlook, SharePoint, OneDrive, Gmail), configured lures and redirects, and watched captured sessions roll in.
  • Ready-made lures. Templates covered voicemails, shared documents, HR updates, and invoices, delivered as PDFs, QR codes, SVG files, or HTML attachments.
  • Built-in evasion. Custom CAPTCHAs, browser fingerprinting, heavy code obfuscation, and decoy pages shown to anything that looked like a security scanner.
  • Disposable infrastructure. Campaign domains often lived only 24 to 72 hours before being swapped out, which undermines blocklists.
  • Post-reset persistence. Microsoft warns that a stolen session can keep working even after the victim changes their password, unless active sessions and tokens are explicitly revoked.

The kit proved hard to kill. Proofpoint describes it as the highest-volume AiTM threat in its data, sold by a single main individual to many different threat actors. A coordinated takedown in March 2026, led by Microsoft and Europol, seized more than 300 domains, but Elastic Security Labs reports that operators adapted within weeks and began blending in OAuth device code phishing. Tycoon also rose partly because earlier services like Caffeine and RaccoonO365 were disrupted, a reminder that this market fills gaps quickly.

What Attackers Do Once They're In

Stealing the session is only the opening move. The payoff usually comes from what happens inside the compromised mailbox, and it can happen startlingly fast.

The campaign that put AiTM on the map was documented by Microsoft in July 2022. It had attempted to target more than 10,000 organizations since September 2021, spoofing the Office 365 sign-in page with the Evilginx2 kit. Microsoft found that in some cases, attackers launched payment fraud as little as five minutes after stealing a session.

The playbook that followed was patient and methodical:

  • Reconnaissance. Over the following days, attackers checked in every few hours, reading finance-related emails and attachments in search of active payment conversations.
  • Covering tracks. They deleted the original phishing email from the victim's inbox so it couldn't be reported.
  • Hiding replies. They created inbox rules that silently moved messages from the fraud target into an archive folder and marked them read, so the real user never saw the conversation.
  • Hijacking the thread. They replied to real invoice and payment threads with fraudulent instructions, then deleted their own sent messages.
  • Scaling up. In one case, a single compromised mailbox was used for several simultaneous fraud attempts, with the inbox rule updated for each new target.

This is business email compromise (BEC) at its most convincing, because the messages come from a genuine, trusted account inside a genuine, ongoing conversation. Microsoft's more recent Tycoon 2FA research describes the same pattern continuing: attackers modify mailbox rules, register new authenticator apps for persistence, and launch fresh phishing waves from the accounts they've taken over. Each victim becomes a launchpad for the next.

How to Defend Against AiTM

The first thing to do is a slightly counterintuitive action: do not abandon MFA. Microsoft makes the point that MFA is so effective at stopping ordinary attacks that it is the very reason AiTM phishing was invented. The goal is to upgrade to MFA that can't be relayed, and then to stop treating a valid session cookie as unquestionable proof of identity.

Move to phishing-resistant MFA

This is the single biggest fix. CISA's fact sheet on phishing-resistant MFA warns that not all MFA is equally strong, and points to FIDO/WebAuthn and PKI-based methods (like smart cards) as the phishing-resistant options.

These methods are cryptographically tied to the real website's domain. When a victim lands on a lookalike proxy domain, the passkey or security key simply refuses to sign in, so there is nothing valid for the attacker to relay. SMS codes, one-time passcodes, and push approvals, by contrast, can all be passed straight through a proxy, which is exactly what Microsoft saw Tycoon 2FA doing.

If you can't roll it out everywhere at once, start with administrators and other high-value accounts, as Microsoft recommends.

Make stolen sessions harder to use

  • Conditional access. Require compliant or managed devices and trusted network locations. Microsoft notes these policies are evaluated each time a stolen cookie is replayed, so a cookie used from an attacker's laptop can be stopped.
  • Shorter session lifetimes. SentinelOne suggests tightening cookie lifespans to shrink the window in which a stolen session is useful.
  • Revoke sessions, not just passwords. When an account is compromised, resetting the password isn't enough. Revoke all active sessions and tokens, review recently added MFA devices, and remove suspicious inbox rules.

Watch for the telltale signs

AiTM leaves fingerprints if you know where to look. Microsoft's research highlights several worth hunting for:

  • Sign-ins from unusual locations, ISPs, anonymizing VPNs, or Tor.
  • "Impossible travel," where the same session appears in two distant countries at once.
  • The same session ID showing up in a new country or app shortly after the original login.
  • New inbox rules that move, hide, or auto-read messages, especially from finance contacts.
  • Unusual volumes of mailbox access from untrusted devices or IPs.

Keep the human layer sharp

Because an AiTM page looks pixel-perfect, the URL is often the only visible clue. Train users to check the address bar before signing in, to be suspicious of unexpected voicemail, document-share, and invoice lures, and to treat QR codes in emails with caution. Pair that with email filtering and browser protections that check links at the time they are clicked, not just when the email arrives.

The Path to Stronger Defense

AiTM isn't a new idea so much as an old one repackaged for the MFA era. Attackers stopped trying to guess or steal the second factor and started stealing the proof that you already passed it. Phishing-as-a-service platforms like Tycoon 2FA then turned that trick into a product anyone can rent for the price of a nice dinner.

The defense is equally clear. Phishing-resistant authentication removes the thing the proxy needs to relay. Conditional access and session controls limit what a stolen cookie can do. Good detection and quick session revocation shrink the damage when something slips through. Organizations that do all three turn AiTM from a scalable business model back into a hard, expensive attack.

RADICL helps organizations close the gaps that these attacks depend on, from strengthening identity and access controls to detecting suspicious logins and session activity in real time. With 24/7 monitoring and rapid response, stolen credentials or session cookies are less likely to give an attacker the time and access they need to move further into the environment.

Want to make your organization a harder target for attacks like AiTM? Contact RADICL to get started.

Get Email Notifications

No Comments Yet

Let us know what you think