Avatier

MFA bypass

AiTM phishing

Also called: adversary-in-the-middle phishing

AiTM phishing, or adversary-in-the-middle phishing, is a technique that places a proxy between the victim and the real login page. The victim signs in normally, including MFA, while the proxy passes everything through and records the password and the session cookie the site issues. The attacker then reuses that cookie to enter the account without MFA.

How it works

The attacker sends a link to a proxy site that shows the genuine login page, relayed live. When the victim enters a password and one-time code or push approval, the real site issues a session cookie, which the proxy captures. Open-source frameworks and phishing kits automate this, so the technique defeats most MFA except phishing-resistant methods.

A real example

CISA and partners said in December 2023 that Star Blizzard used the open-source framework EvilGinx in its spearphishing activity to harvest credentials and session cookies and bypass two-factor authentication.

Source: Russian FSB Cyber Actor Star Blizzard Continues Worldwide Spearphishing Campaigns (AA23-341A) — Cybersecurity and Infrastructure Security Agency (CISA), 2023-12-07

The Identity Attack Ledger holds 1 cited incident for mfa bypass in California breach filings (January 1, 2023 – August 14, 2026), each quoted from its filed letter.

How to stop it

Passkeys and FIDO2 security keys check the site's real domain, so they will not complete a login through a proxy. Bind sessions to the device to limit cookie replay.

Related terms

Threat actors that use it

Sources

  1. Russian FSB Cyber Actor Star Blizzard Continues Worldwide Spearphishing Campaigns (AA23-341A) — Cybersecurity and Infrastructure Security Agency (CISA), 2023-12-07

Last reviewed Oct 2, 2026