{"id":6518,"date":"2025-08-29T10:03:38","date_gmt":"2025-08-29T10:03:38","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/08\/29\/how-adversary-in-the-middle-aitm-attack-bypasses-mfa-and-edr\/"},"modified":"2025-08-29T10:03:38","modified_gmt":"2025-08-29T10:03:38","slug":"how-adversary-in-the-middle-aitm-attack-bypasses-mfa-and-edr","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/08\/29\/how-adversary-in-the-middle-aitm-attack-bypasses-mfa-and-edr\/","title":{"rendered":"How Adversary-In-The-Middle (AiTM) Attack Bypasses MFA and EDR?"},"content":{"rendered":"<p>    How Adversary-In-The-Middle (AiTM) Attack Bypasses MFA and EDR?<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>Adversary-in-the-Middle (AiTM) attacks are among the most sophisticated and dangerous phishing techniques in the modern cybersecurity landscape.<\/p>\n<p>Unlike traditional phishing attacks that merely collect static credentials, AiTM attacks actively intercept and manipulate communications between users and legitimate services in real-time, enabling attackers to bypass <a href=\"https:\/\/cybersecuritynews.com\/microsoft-multi-factor-authentication-issue\/\" target=\"_blank\" rel=\"noreferrer noopener\">multi-factor authentication<\/a> (MFA) and evade <a href=\"https:\/\/cybersecuritynews.com\/best-edr-tools\/\" target=\"_blank\" rel=\"noreferrer noopener\">endpoint detection and response (EDR)<\/a> systems.<\/p>\n<p>These attacks have surged in popularity as organizations increasingly adopt MFA protections, with Microsoft reporting that AiTM phishing campaigns have targeted over 10,000 organizations globally. <\/p>\n<p>The emergence of <a href=\"https:\/\/cybersecuritynews.com\/phishing-as-a-service-the-rise-of-subscription-based-cybercrime\/\" target=\"_blank\" rel=\"noreferrer noopener\">phishing-as-a-service <\/a>(PhaaS) platforms like Tycoon 2FA and Evilginx2 has industrialized these attacks, lowering the technical barrier for cybercriminals and making sophisticated AiTM capabilities accessible through subscription models starting at just $120.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhwSo-yNEEULo1MLcM9V4L92HSnKbuEKcyRttVHCpA1eUwQvgfVbKuFja_AVT2_Xx5rH3ZvuVqiD0FQCndQZxLLzidokIywgK2e4Oo00CeyETdxqIbn2dTp10zLk-18kTj97P6FP40DtdkUChWO6cpx0NhUjkmZTZOdxP64Q4_txl31-r_KutHL_cDcAD04\/s16000\/4ca60139.webp?ssl=1\" alt=\"AiTM Attack Flow Process.\"><figcaption class=\"wp-element-caption\">AiTM Attack Flow Process.<\/figcaption><\/figure>\n<\/div>\n<h2 class=\"wp-block-heading\" id=\"introduction-to-aitm-attacks\"><strong>Introduction to AiTM Attacks<\/strong><\/h2>\n<p>Adversary-in-the-Middle attacks fundamentally differ from traditional <a href=\"https:\/\/cybersecuritynews.com\/blast-radius-man-in-the-middle-attack\/\" target=\"_blank\" rel=\"noreferrer noopener\">man-in-the-middle<\/a> (MitM) attacks through their active manipulation and sophisticated orchestration of authentication processes. <\/p>\n<p>While traditional MitM attacks often focus on passive eavesdropping, AiTM attacks involve attackers positioning themselves as active intermediaries between victims and legitimate services, using reverse proxy servers to create seamless, real-time communication channels.<a href=\"https:\/\/www.sentinelone.com\/cybersecurity-101\/threat-intelligence\/what-is-an-adversary-in-the-middle-aitm-attack\/\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a><\/p>\n<p>The technical foundation of <a href=\"https:\/\/cybersecuritynews.com\/passkeys-via-aitm-phishing-attacks\/\" target=\"_blank\" rel=\"noreferrer noopener\">AiTM attacks<\/a> relies on reverse proxy architecture, where attackers deploy servers that act as intermediaries between victims and legitimate authentication portals. <\/p>\n<p>This approach allows attackers to present users with authentic-looking login pages that are actually legitimate pages served through the malicious proxy, making detection extremely difficult.<a href=\"https:\/\/blog.talosintelligence.com\/state-of-the-art-phishing-mfa-bypass\/\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a><\/p>\n<p>Modern AiTM toolkits leverage sophisticated technologies, including WebSocket connections for real-time bidirectional communication, automated SSL certificate generation through services like Let\u2019s Encrypt, and advanced cloaking mechanisms using tokenized URLs to evade detection.<\/p>\n<p>When a victim attempts to access a service like <a href=\"https:\/\/cybersecuritynews.com\/microsoft-365-outage\/\" target=\"_blank\" rel=\"noreferrer noopener\">Microsoft 365<\/a> or Gmail, the AiTM proxy intercepts the request, forwards it to the legitimate service, captures the response, and relays it back to the victim while simultaneously harvesting all authentication data in transit. <\/p>\n<p>The most prominent open-source AiTM frameworks include <a href=\"https:\/\/cybersecuritynews.com\/new-attack-targeting-screenconnect-cloud-administrators\/\" target=\"_blank\" rel=\"noreferrer noopener\">Evilginx2<\/a>, Muraena, and Modlishka, each offering unique capabilities for credential harvesting and session hijacking.<\/p>\n<p>These tools have evolved to include features such as multi-domain hosting, custom branding integration, and advanced evasion techniques that make them particularly effective against modern security measures.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEg3gmnzhFixQU_ITJTA1zDUKhuyuJ6W5YnsNxCT6D46kVtaUdLrROwXXqDBrP4MpX4I1wO90jHRnw3I-X6f2x264ILAdOPWNj3lNwKd-wso9csIk7LuTJoyyoGopmV4frp6vcb5LDPlE17ZLUVh8yIQLsk0nBJ396PNTpdUC02NZEyetakavhDS6A0ctxLs\/s16000\/215569d3.webp?ssl=1\" alt=\"AiTM Attack Architecture.\"><figcaption class=\"wp-element-caption\">AiTM Attack Architecture.<\/figcaption><\/figure>\n<\/div>\n<h2 class=\"wp-block-heading\" id=\"h-the-role-of-mfa-in-modern-security\">\n<a href=\"https:\/\/www.zscaler.com\/blogs\/security-research\/large-scale-aitm-attack-targeting-enterprise-users-microsoft-email-services\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a><strong>The Role of MFA in Modern Security<\/strong><br \/>\n<\/h2>\n<p>Multi-factor authentication has become the cornerstone of modern cybersecurity strategies, with Microsoft blocking over 7,000 password attacks per second, representing a 75% year-over-year increase. <\/p>\n<p>MFA implementations typically require users to provide something they know (password), something they have (mobile device or hardware token), or something they are (biometric data). <\/p>\n<p>Traditional MFA methods include SMS codes, push notifications, authenticator apps generating time-based one-time passwords (TOTP), and hardware security keys.<\/p>\n<figure class=\"wp-block-table\">\n<table class=\"has-fixed-layout\">\n<thead>\n<tr>\n<th>MFA Method<\/th>\n<th>Authentication Factor<\/th>\n<th>Adoption Rate<\/th>\n<th>AiTM Vulnerability<\/th>\n<th>Traditional Security Level<\/th>\n<th>Common Bypass Methods<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>SMS Codes (SMS OTP)<\/td>\n<td>Something you have<\/td>\n<td>High (60%+)<\/td>\n<td>High \u2013 Easily intercepted<\/td>\n<td>Low<\/td>\n<td>SIM swapping, SS7 attacks<\/td>\n<\/tr>\n<tr>\n<td>Push Notifications<\/td>\n<td>Something you have<\/td>\n<td>High (50%+)<\/td>\n<td>High \u2013 Tokens stolen post-auth<\/td>\n<td>Medium-High<\/td>\n<td>Push fatigue, device compromise<\/td>\n<\/tr>\n<tr>\n<td>Authenticator Apps (TOTP)<\/td>\n<td>Something you have<\/td>\n<td>Medium (35%+)<\/td>\n<td>High \u2013 Codes relayed in real-time<\/td>\n<td>High<\/td>\n<td>Device compromise, phishing<\/td>\n<\/tr>\n<tr>\n<td>Hardware Security Keys (FIDO2)<\/td>\n<td>Something you have<\/td>\n<td>Low (15%+)<\/td>\n<td>Medium \u2013 Session tokens still stolen<\/td>\n<td>Very High<\/td>\n<td>Session token theft (AiTM only)<\/td>\n<\/tr>\n<tr>\n<td>Voice Calls<\/td>\n<td>Something you have<\/td>\n<td>Medium (25%+)<\/td>\n<td>High \u2013 Codes intercepted<\/td>\n<td>Low<\/td>\n<td>Voice phishing, call forwarding<\/td>\n<\/tr>\n<tr>\n<td>Email OTP<\/td>\n<td>Something you have<\/td>\n<td>Medium (30%+)<\/td>\n<td>High \u2013 Easily intercepted<\/td>\n<td>Low-Medium<\/td>\n<td>Email compromise, phishing<\/td>\n<\/tr>\n<tr>\n<td>Biometric Authentication<\/td>\n<td>Something you are<\/td>\n<td>Growing (20%+)<\/td>\n<td>Medium \u2013 Session tokens stolen<\/td>\n<td>Very High<\/td>\n<td>Session token theft<\/td>\n<\/tr>\n<tr>\n<td>Certificate-based Authentication<\/td>\n<td>Something you have<\/td>\n<td>Low (10%+)<\/td>\n<td>Medium \u2013 Certificates bypassed<\/td>\n<td>Very High<\/td>\n<td>Session token theft, cert theft<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/figure>\n<p><a href=\"https:\/\/securitybrief.com.au\/story\/phishing-campaign-uses-fake-microsoft-apps-to-bypass-mfa\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a>The security model of MFA relies on the assumption that compromising multiple authentication factors simultaneously is significantly more difficult than bypassing a single password. <\/p>\n<p>However, this assumption breaks down in the face of AiTM attacks, which don\u2019t need to compromise individual factors but instead exploit the trust relationship established after successful authentication. <\/p>\n<p>When users complete the MFA challenge through an AiTM proxy, they unknowingly provide attackers with both their credentials and the session tokens issued by the legitimate service.<a href=\"https:\/\/blog.talosintelligence.com\/state-of-the-art-phishing-mfa-bypass\/\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a><\/p>\n<h2 class=\"wp-block-heading\" id=\"how-aitm-attack-bypasses-mfa-and-edr\"><strong>How AiTM Attack Bypasses MFA and EDR<\/strong><\/h2>\n<p>The MFA bypass mechanism in AiTM attacks operates through session token theft rather than authentication factor compromise. When victims interact with an AiTM phishing page, they complete the entire authentication process, including MFA challenges, but all communications pass through the attacker\u2019s proxy server.<\/p>\n<p>The <a href=\"https:\/\/cybersecuritynews.com\/proxy-networks-for-business\/\" target=\"_blank\" rel=\"noreferrer noopener\">proxy<\/a> forwards the user\u2019s credentials and MFA responses to the legitimate service, which then issues session cookies and authentication tokens back through the proxy. <\/p>\n<p>The attacker captures these tokens while allowing the authentication to complete successfully, creating a scenario where the victim believes they\u2019ve securely logged in while the attacker has gained persistent access to their account.<a href=\"https:\/\/blog.talosintelligence.com\/state-of-the-art-phishing-mfa-bypass\/\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a><\/p>\n<p>Session tokens, particularly Primary Refresh Tokens (PRTs) in Microsoft environments, can provide extended access lasting 30 days or more if kept active. <\/p>\n<p>These tokens contain cryptographic proof of successful authentication and can be replayed by attackers to access accounts without triggering additional MFA challenges. <\/p>\n<p>The sophistication of modern AiTM kits like <a href=\"https:\/\/cybersecuritynews.com\/tycoon-2fa-phish-kit\/\" target=\"_blank\" rel=\"noreferrer noopener\">Tycoon 2FA<\/a> includes features for session token management, automatic token refresh, and persistence mechanisms that allow attackers to maintain access even after password changes.<a href=\"https:\/\/blogs.chapman.edu\/information-systems\/2025\/01\/06\/understanding-aitm-phishing-attacks\/\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a><\/p>\n<p>EDR evasion in AiTM attacks occurs through several mechanisms that exploit fundamental limitations in endpoint monitoring. Traditional EDR solutions focus on detecting malicious processes, file modifications, and network connections originating from the endpoint itself. <\/p>\n<p>However, AiTM attacks primarily occur server-side, where the malicious proxy operates independently of the victim\u2019s endpoint. The victim\u2019s device only interacts with what appears to be legitimate web traffic to authentic domains, making the malicious activity invisible to endpoint-based detection systems.<a href=\"https:\/\/attack.mitre.org\/techniques\/T1557\/\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a><\/p>\n<p>Advanced AiTM campaigns employ sophisticated evasion techniques, including code obfuscation using Base64 encoding, dynamic code generation that alters signatures with each execution, and<a href=\"https:\/\/cybersecuritynews.com\/qwerty-anti-debugging-techniques\/\" target=\"_blank\" rel=\"noreferrer noopener\"> anti-debugging<\/a> mechanisms designed to frustrate automated analysis.<\/p>\n<p>These techniques specifically target the static and behavioral analysis capabilities of EDR systems. Additionally, attackers abuse legitimate services like CodeSandbox, Glitch, and Notion as redirect mechanisms, leveraging the trust these domains have with security systems to bypass URL filtering and reputation-based blocking.<a href=\"https:\/\/www.claranet.com\/uk\/blog\/how-attackers-can-bypass-mfa-using-aitm-and-how-defend-against-it\/\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a><\/p>\n<p>The use of living-off-the-land techniques further complicates <a href=\"https:\/\/cybersecuritynews.com\/edr-vs-mdr\/\" target=\"_blank\" rel=\"noreferrer noopener\">EDR<\/a> detection, as AiTM attacks often rely on standard web protocols and legitimate authentication flows.<\/p>\n<p>Attackers may also implement EDR communication blocking techniques, using tools like Windows Filtering Platform (WFP) to prevent EDR agents from communicating with their cloud infrastructure, effectively blinding the security solution to ongoing malicious activities.<a href=\"https:\/\/www.pentestpartners.com\/security-blog\/bec-ware-the-phish-part-1-investigating-incidents-in-m365\/\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a><\/p>\n<h2 class=\"wp-block-heading\" id=\"indicators-of-aitm-attacks\"><strong>Indicators of AiTM Attacks<\/strong><\/h2>\n<p>Authentication log analysis reveals several key indicators of AiTM activity, with impossible travel being among the most reliable signals. When attackers use stolen session tokens, they often authenticate from geographic locations that would be impossible for the legitimate user to reach within the observed timeframe. <\/p>\n<p>Microsoft\u2019s delayed logging can complicate this analysis, as some authentication events may take up to 20 hours to appear in audit logs, making real-time detection challenging.<\/p>\n<p> Multiple rapid sign-ins from different locations within short timeframes, particularly when accompanied by successful MFA completion, often indicate session token replay attacks.<\/p>\n<figure class=\"wp-block-table\">\n<table class=\"has-fixed-layout\">\n<thead>\n<tr>\n<th>Category<\/th>\n<th>Indicator<\/th>\n<th>Description<\/th>\n<th>MITRE_ATT&amp;CK<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>Authentication Logs<\/td>\n<td>Impossible Travel<\/td>\n<td>User authentication from geographically impossible locations within short timeframes<\/td>\n<td>T1078.004<\/td>\n<\/tr>\n<tr>\n<td>Authentication Logs<\/td>\n<td>Multiple Rapid Sign-ins<\/td>\n<td>Multiple successful authentications from different locations in rapid succession<\/td>\n<td>T1078.004<\/td>\n<\/tr>\n<tr>\n<td>Authentication Logs<\/td>\n<td>Session Token Anomalies<\/td>\n<td>Authentication without password entry or MFA prompts in logs<\/td>\n<td>T1078.004<\/td>\n<\/tr>\n<tr>\n<td>Network Indicators<\/td>\n<td>Unknown IP Addresses<\/td>\n<td>Sign-ins from previously unseen IP addresses or suspicious ASNs<\/td>\n<td>T1557<\/td>\n<\/tr>\n<tr>\n<td>Network Indicators<\/td>\n<td>Suspicious Domains<\/td>\n<td>Connections to domains mimicking legitimate services or suspicious TLDs<\/td>\n<td>T1557<\/td>\n<\/tr>\n<tr>\n<td>User Behavior<\/td>\n<td>Mailbox Rule Creation<\/td>\n<td>Creation of inbox rules to hide or redirect emails, especially with random names<\/td>\n<td>T1564.008<\/td>\n<\/tr>\n<tr>\n<td>User Behavior<\/td>\n<td>Email Forwarding Rules<\/td>\n<td>New forwarding rules redirecting emails to external addresses<\/td>\n<td>T1114.003<\/td>\n<\/tr>\n<tr>\n<td>Email Indicators<\/td>\n<td>Phishing Email Patterns<\/td>\n<td>Emails from trusted senders with suspicious links or urgent language<\/td>\n<td>T1566.002<\/td>\n<\/tr>\n<tr>\n<td>Email Indicators<\/td>\n<td>Legitimate Service Abuse<\/td>\n<td>Abuse of legitimate services like CodeSandbox, Glitch, or Notion for redirection<\/td>\n<td>T1566.002<\/td>\n<\/tr>\n<tr>\n<td>Technical Artifacts<\/td>\n<td>Reverse Proxy Artifacts<\/td>\n<td>WebSocket connections, specific HTTP headers, or proxy-related network signatures<\/td>\n<td>T1557<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/figure>\n<p>The evolution of AiTM attacks from simple credential harvesting to sophisticated, service-oriented attack platforms represents a fundamental shift in the threat landscape that requires equally sophisticated defense strategies. <\/p>\n<p>Organizations must recognize that traditional perimeter defenses and even MFA are insufficient against these advanced persistent threats, necessitating comprehensive security architectures that include behavioral analytics, session token protection, and continuous authentication mechanisms to counter this growing menace effectively.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(135deg,rgb(238,238,238) 100%,rgb(169,184,195) 100%)\"><strong>Find this Story Interesting! Follow us on\u00a0<a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener\">LinkedIn<\/a>\u00a0and\u00a0<a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener\">X<\/a>\u00a0to Get More Instant Updates<\/strong>.<\/p>\n<p><a href=\"https:\/\/www.zscaler.com\/blogs\/security-research\/large-scale-aitm-attack-targeting-enterprise-users-microsoft-email-services\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/adversary-in-the-middle-aitm-attack\/\">How Adversary-In-The-Middle (AiTM) Attack Bypasses MFA and EDR?<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Guru Baran<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/adversary-in-the-middle-aitm-attack\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>How Adversary-In-The-Middle (AiTM) Attack Bypasses MFA and EDR? Adversary-in-the-Middle (AiTM) attacks are among the most sophisticated and dangerous phishing techniques in the modern cybersecurity landscape. Unlike traditional phishing attacks that merely collect static credentials, AiTM attacks actively intercept and manipulate communications between users and legitimate services in real-time, enabling attackers to bypass multi-factor authentication (MFA) [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1768,129,63,1499,705],"tags":[130],"class_list":["post-6518","post","type-post","status-publish","format-standard","hentry","category-aitm-attack","category-cyber-security","category-cyber-security-news","category-cybersecurity-research","category-edr","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/6518"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=6518"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/6518\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=6518"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=6518"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=6518"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}