Files
iimp0ster-detection-chokepo…/attack-chains/aitm.md
T
imposterandClaude Opus 4.8 a7451bc79a feat(attack-chains): interactive TTP graph view
D3-based TTP graph (graph/list toggle, actor filtering, zoom/pan) on attack-chain pages, with supporting diagram/flow include updates and chain content.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-11 08:13:49 -06:00

7.2 KiB

layout, title, subtitle, last_updated, permalink, show_ttp_overlap, ttp_data_key, stages, actors, chokepoints
layout title subtitle last_updated permalink show_ttp_overlap ttp_data_key stages actors chokepoints
attack-chain AiTM / Phishing Kit Attack Chain AiTM kits bypass MFA by stealing session tokens - the same chokepoints regardless of kit or lure. 2026-04-14 /attack-chains/aitm/ true aitm_ttp_overlap
id label detection_status attacker_action systems detection_signals chokepoint_links
lure_delivery Lure Delivery detected Phishing link / device code email Email GW · Endpoint · Browser
Link to newly registered domain (<30 days) delivered via email or Teams message
Redirect chain ending at a lookalike Microsoft / Google login page
Device code authentication request from unexpected IP or user-agent
Browser navigating to domain mimicking login.microsoftonline.com or accounts.google.com
label slug
ClickFix Techniques clickfix-techniques
id label detection_status attacker_action systems detection_signals
proxy_interception Proxy Interception exploited Reverse proxy relays real IdP traffic Network · IdP · Browser
MFA prompt satisfied from IP that issued no prior authentication request to IdP
Authentication token issued to a domain that is not a registered app redirect URI
TLS certificate on login page issued to non-Microsoft/Google CA for IdP lookalike domain
Concurrent authentication sessions for same account from two geographically distinct IPs
id label detection_status attacker_action systems detection_signals chokepoint_links
token_harvest Token Harvest exploited Session cookie / OAuth token extracted at proxy IdP · Browser
Session cookie replayed from IP different from original authentication IP
OAuth refresh token exchange from unfamiliar device fingerprint or user-agent
Access token issued for broad Microsoft Graph scopes (Mail.Read, Files.ReadWrite) to unrecognized app
Device code token grant without matching device registration in Entra ID
label slug
Browser Credential Theft browser-credential-theft
id label detection_status attacker_action systems detection_signals
account_takeover Account Takeover exploited Token replay from new IP/device without re-auth challenge SaaS · M365 · Google Workspace
Impossible travel: session re-used from country different from prior authentication within minutes
Sign-in from new ASN or hosting provider with no prior user activity
CAE (Continuous Access Evaluation) token re-use after IP change without re-authentication
First-time access to sensitive mailbox folders (e.g., Sent Items, Inbox search) from session token
id label detection_status attacker_action systems detection_signals
persistence_objectives Persistence & Objectives detected OAuth app consent · email rules · device registration M365 · Entra ID · Google Workspace
New OAuth application consent granted with Mail.Read or Files.ReadWrite permissions
Inbox rule created to forward or delete mail containing keywords (invoice, payment, wire)
New device registered to Entra ID from unfamiliar IP immediately after session token use
Admin role assigned to recently-created or newly-compromised account
Service principal credential added outside normal provisioning workflow
name status lure_delivery proxy_interception token_harvest account_takeover persistence_objectives
Tycoon 2FA Active Mass-phishing email with O365 / M365 login lure link; targets org domains at scale JavaScript-heavy Cloudflare-fronted reverse proxy relays real Microsoft IdP Captures session cookie in real time; strips MFA token from relay stream Replays harvested cookie from attacker infrastructure; no re-auth required Inbox forwarding rules; OAuth app consent for persistent mail access
name status lure_delivery proxy_interception token_harvest account_takeover persistence_objectives
Evilginx Active Targeted spearphishing link; operator configures phishlet per IdP target Open-source Go-based reverse proxy; intercepts full session including MFA Extracts session cookies and tokens from proxied responses via phishlets Exports cookie for direct browser import; used by operator in targeted campaigns Operator-driven post-access: OAuth consent, new credentials, lateral phishing
name status lure_delivery proxy_interception token_harvest account_takeover persistence_objectives
EvilProxy Active Phishing-as-a-service platform; delivers links via email or Telegram bot Commercial reverse proxy service; supports Microsoft, Google, Apple IdPs Real-time cookie interception; dashboard shows captured tokens per campaign Automated token replay; BEC-focused buyer use cases Email hiding rules; exfiltration of financial email content for BEC fraud
name status lure_delivery proxy_interception token_harvest account_takeover persistence_objectives
Sneaky 2FA Active Phishing kit with dark-themed Microsoft 365 lure pages; targets enterprise users Kit-based AiTM with partial relay approach. Less automated than EvilProxy. Session cookie capture from proxied Microsoft authentication flow Manual or semi-automated token replay; operator-controlled timing Inbox rules for BEC follow-on; selective data access for financial fraud
name status lure_delivery proxy_interception token_harvest account_takeover persistence_objectives
Device Code Flow Active Email delivers device code with social engineering (IT helpdesk, Teams invite) No reverse proxy. Victim authenticates to real IdP. Device code polling captures the token. OAuth refresh token obtained via device authorization grant; long-lived access Refresh token used for persistent API-level access to M365 Graph endpoints Service principal or app registration with delegated permissions; sustained access
lure_delivery proxy_interception token_harvest account_takeover persistence_objectives
Victim clicks a link or opens an attachment that initiates an authentication flow to an attacker-controlled endpoint Active session passes through adversary-controlled infrastructure OR device code is presented to victim Session token or OAuth access/refresh token extracted before or after MFA completion Token replayed from unfamiliar IP/device without triggering re-authentication challenge Attacker holds an authenticated session with sufficient privilege to modify account configuration

Research Methodology

Source: Kitsune pipeline over ORKL + vendor reports - 11 reports / 5 AiTM kit families. Convergent techniques only.

  • [Infostealers]({{ '/attack-chains/infostealers/' | relative_url }}) - Harvested credentials are often used as AiTM lure pre-text
  • [Ransomware]({{ '/attack-chains/ransomware/' | relative_url }}) - AiTM-compromised accounts are sold to ransomware initial access brokers