All resources

31 August 2026 · Threat Spotlight · CyberSec360 Australia

Threat Spotlight: Adversary-in-the-Middle Kits — the Phishing That Beats Basic MFA

For years the advice was simple: turn on MFA and most phishing dies. Attackers responded with adversary-in-the-middle (AiTM) phishing — kits like the open-source Evilginx and a wave of commercial “phishing-as-a-service” platforms that don’t fake the login page so much as relay the real one. Microsoft and others have documented large AiTM campaigns against businesses of every size since 2022, precisely because the technique works where old phishing now fails.

How a proxy phish works

  • The victim clicks a lure and lands on the attacker’s server — which live-proxies the genuine Microsoft 365 login page, pixel for pixel, over a lookalike domain.
  • The victim types their password and approves the MFA prompt — everything is real, just flowing through the attacker’s middlebox.
  • The kit captures the resulting session cookie — the token that says “this browser is signed in”.
  • The attacker imports that cookie and is simply… logged in. No password needed again, MFA already satisfied.

Why phishing-as-a-service changes the economics

These kits are rented like software subscriptions, with dashboards, templates and support. That means AiTM capability is no longer limited to skilled operators — the same technique that once marked sophisticated crews is now available to anyone with cryptocurrency, and it gets pointed at small businesses because that’s where basic code-and-prompt MFA is most common.

What actually defends against it

  • Phishing-resistant MFA: passkeys and FIDO2 security keys bind the login to the real domain — a proxy on a lookalike domain simply fails. Prioritise them for email, admins and finance.
  • Conditional access: require compliant or known devices for sign-in, so a stolen session from an attacker’s machine is refused.
  • Watch the sessions, not just the passwords: alerts on impossible-travel sign-ins and new inbox rules catch the intrusion’s first minutes.
  • Keep training current: the visible tell is the address bar, not the page — bookmarks for the front doors beat inspecting pixels.

MFA is still essential — AiTM is a reason to upgrade it, not abandon it. Move the accounts that matter to passkeys and the whole kit economy loses its product.

Want help with this in your business?

Book a free security check with our Sydney team — plain-English advice, no obligation.

Get a Free Security Check