For years, the security industry's answer to phishing was simple: turn on multi-factor authentication. Even if someone stole your password, they would still need the code on your phone. But then Adversary-in-the-Middle (AiTM) attacks broke that promise. Instead of stealing your password and hoping for the best, an AiTM attacker lets you log in to the real site yourself, MFA and all, and then walks off with the session you just created.
The result is an attack that turns a single click on a phishing link into full account access, and that can be run against thousands of organizations at once using off-the-shelf kits.
At its core, AiTM describes an attacker who inserts themselves into a conversation between two parties so they can watch, capture, or alter what passes between them. MITRE ATT&CK catalogs it as technique T1557, noting that attackers can abuse ordinary network protocols such as ARP, DNS, and LLMNR to route a victim's traffic through a system they control. MITRE also calls out that this position can be used to grab access tokens and session cookies, which is exactly where the modern version of the attack gets its teeth.
If that sounds like the classic man-in-the-middle (MitM) attack, it is. AiTM is the same idea with a sharper focus. As SentinelOne explains, older MitM attacks often meant listening in on unencrypted traffic, like an open coffee-shop Wi-Fi network. AiTM puts the emphasis on an attacker who actively manipulates the exchange, and in today's usage it most often refers to targeted phishing operations built to defeat strong authentication.
To understand why AiTM is so effective, you need to know one essential fact about the web. After you sign in, the site hands your browser a session cookie so you don't have to re-authenticate on every page. According to Microsoft's security research team, that cookie is the server's proof that you already passed authentication. Whoever holds it, the server treats as you.
An AiTM attack is built to steal that cookie. Here is how a typical run plays out:
Microsoft stresses that this is not a flaw in MFA itself; the MFA check worked perfectly. The attacker simply waited until after it was done and took the result.
A reverse-proxy phishing setup used to take real skill; not as much anymore. Open-source frameworks such as Evilginx2, Modlishka, and Muraena automated much of the work, and MITRE lists evilginx2 as a known AiTM tool that captures passwords, tokens, and session cookies. Criminal entrepreneurs then took the next step: packaging the whole thing as a subscription service.
The clearest example is Tycoon 2FA. Microsoft's March 2026 analysis found that after appearing in August 2023, campaigns built on the kit sent tens of millions of phishing messages and reached more than 500,000 organizations every month. Microsoft attributes its development to a group it tracks as Storm-1747, and says it let even low-skilled criminals get around MFA.
What made Tycoon 2FA feel less like a hacking tool and more like a SaaS product:
The kit proved hard to kill. Proofpoint describes it as the highest-volume AiTM threat in its data, sold by a single main individual to many different threat actors. A coordinated takedown in March 2026, led by Microsoft and Europol, seized more than 300 domains, but Elastic Security Labs reports that operators adapted within weeks and began blending in OAuth device code phishing. Tycoon also rose partly because earlier services like Caffeine and RaccoonO365 were disrupted, a reminder that this market fills gaps quickly.
Stealing the session is only the opening move. The payoff usually comes from what happens inside the compromised mailbox, and it can happen startlingly fast.
The campaign that put AiTM on the map was documented by Microsoft in July 2022. It had attempted to target more than 10,000 organizations since September 2021, spoofing the Office 365 sign-in page with the Evilginx2 kit. Microsoft found that in some cases, attackers launched payment fraud as little as five minutes after stealing a session.
This is business email compromise (BEC) at its most convincing, because the messages come from a genuine, trusted account inside a genuine, ongoing conversation. Microsoft's more recent Tycoon 2FA research describes the same pattern continuing: attackers modify mailbox rules, register new authenticator apps for persistence, and launch fresh phishing waves from the accounts they've taken over. Each victim becomes a launchpad for the next.
The first thing to do is a slightly counterintuitive action: do not abandon MFA. Microsoft makes the point that MFA is so effective at stopping ordinary attacks that it is the very reason AiTM phishing was invented. The goal is to upgrade to MFA that can't be relayed, and then to stop treating a valid session cookie as unquestionable proof of identity.
This is the single biggest fix. CISA's fact sheet on phishing-resistant MFA warns that not all MFA is equally strong, and points to FIDO/WebAuthn and PKI-based methods (like smart cards) as the phishing-resistant options.
These methods are cryptographically tied to the real website's domain. When a victim lands on a lookalike proxy domain, the passkey or security key simply refuses to sign in, so there is nothing valid for the attacker to relay. SMS codes, one-time passcodes, and push approvals, by contrast, can all be passed straight through a proxy, which is exactly what Microsoft saw Tycoon 2FA doing.
If you can't roll it out everywhere at once, start with administrators and other high-value accounts, as Microsoft recommends.
AiTM leaves fingerprints if you know where to look. Microsoft's research highlights several worth hunting for:
Because an AiTM page looks pixel-perfect, the URL is often the only visible clue. Train users to check the address bar before signing in, to be suspicious of unexpected voicemail, document-share, and invoice lures, and to treat QR codes in emails with caution. Pair that with email filtering and browser protections that check links at the time they are clicked, not just when the email arrives.
AiTM isn't a new idea so much as an old one repackaged for the MFA era. Attackers stopped trying to guess or steal the second factor and started stealing the proof that you already passed it. Phishing-as-a-service platforms like Tycoon 2FA then turned that trick into a product anyone can rent for the price of a nice dinner.
The defense is equally clear. Phishing-resistant authentication removes the thing the proxy needs to relay. Conditional access and session controls limit what a stolen cookie can do. Good detection and quick session revocation shrink the damage when something slips through. Organizations that do all three turn AiTM from a scalable business model back into a hard, expensive attack.
RADICL helps organizations close the gaps that these attacks depend on, from strengthening identity and access controls to detecting suspicious logins and session activity in real time. With 24/7 monitoring and rapid response, stolen credentials or session cookies are less likely to give an attacker the time and access they need to move further into the environment.
Want to make your organization a harder target for attacks like AiTM? Contact RADICL to get started.