logo

Inside Adversary-in-the-Middle Attacks | Huntress

ID: 0d8c7b40-9ea7-5551-9534-85004a543299

STIX ID: report--0d8c7b40-9ea7-5551-9534-85004a543299

Feed Name: Huntress Blog

Date Published: 2024-10-15

Date Updated: 2026-04-28

...
...

This article explains how **Adversary-in-the-Middle (AiTM)** attacks enable attackers to intercept authentication flows and hijack session tokens, effectively bypassing MFA by relaying legitimate login pages via transparent proxies (e.g., Evilginx and PhaaS services). It distinguishes active (proxy-based “pickpocketing”) from passive (“dumpster diving”) token theft, outlines the difficulty of visually detecting AiTM pages, and stresses that phishing-resistant MFA can mitigate token replay. The piece urges a layered defense—user awareness, rapid session invalidation and credential rotation, and deployment of EDR/ITDR—while promoting security awareness training to reduce initial access risk.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.