Imagine clicking a link, logging in, approving your multi-factor authentication (MFA) prompt, and getting on with your day—completely unaware that a criminal has just logged into your account at the exact same moment.
This is Adversary-in-the-Middle (AiTM) phishing. Instead of stealing passwords for later use, these attacks silently hijack an already-authenticated session in real time. While MFA remains a critical first step, AiTM exploits something it was never designed to protect: the trusted session that exists after authentication is complete.
Traditional phishing collected credentials. Modern phishing targets the authenticated session itself. Security researchers have documented a significant shift towards token theft, driven by Phishing-as-a-Service (PhaaS) platforms like Evilginx. These toolkits allow low-skilled attackers to deploy sophisticated campaigns against Microsoft 365 and Google Workspace at scale.
An AiTM site is not a static replica of a login page; it is a live reverse proxy sitting between the user and the real service. Every keystroke, redirect, and server response flows through the attacker's system in real time. Because the page mirrors the real service—complete with accurate branding and functional MFA prompts—the only clue is a slightly altered URL, which is easily missed on mobile screens or under time pressure.
MFA protects the moment of login, not what follows. Once MFA succeeds, the service issues a session cookie. This token signals to the application that the user is verified, meaning no further passwords or MFA challenges are required. AiTM attacks simply wait for this cookie to be issued and steal it. The attacker imports the cookie into their own browser and immediately resumes the session. Microsoft tracked a 146% rise in AiTM attacks over the past year, as cybercriminals increasingly pivot towards accounts already protected by MFA.
Because the attacker operates inside a legitimate session, the aftermath is incredibly quiet. There are no failed MFA attempts or unusual login alerts in standard sign-in logs.
Proofpoint research shows that once inside, attackers commonly:
Defending against AiTM requires security controls that extend beyond the login screen:
MFA is a baseline, not a finish line. The businesses that successfully mitigate AiTM risk are those that protect the session and identity layers, not just the login prompt. Want to review your identity security controls? Contact us today to schedule a consultation and identify your critical gaps.

























