logo

BitM Up! Session Stealing in Seconds Using the Browser-in-the-Middle Technique

ID: b3fce9ea-e6de-55c5-b215-0b2ae380659b

STIX ID: report--b3fce9ea-e6de-55c5-b215-0b2ae380659b

Feed Name: Google Cloud Threat Intelligence

Threat Score
60/100

Date Published: 2025-03-17

Date Updated: 2026-04-27

Author: Mandiant

...
...

This report explains Browser-in-the-Middle (BitM) attacks that enable adversaries to host a browser controlled by the attacker to capture session tokens and bypass MFA across web applications, describing tools and red-team use cases (e.g., Evilginx2, Mandiant's Delusion) and recommending stronger defenses like hardware MFA, client certificates, and FIDO2.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.