Skip to content

Delivery technique · MITRE ATT&CK T1557

Adversary-in-the-middle phishing

Phishing pages that relay the real login in real time, capturing the session cookie and defeating one-time codes and push MFA.

How it works

  1. The victim lands on a proxy that mirrors the real sign-in page.
  2. The proxy forwards the password and MFA code to the real service.
  3. The attacker keeps the authenticated session cookie.

Defenses

Reference: MITRE ATT&CK T1557 Adversary-in-the-Middle

Scams that use it