| attack-chain |
AiTM / Phishing Kit Attack Chain |
AiTM kits bypass MFA by stealing session tokens - the same chokepoints regardless of kit or lure. |
2026-04-14 |
/attack-chains/aitm/ |
true |
aitm_ttp_overlap |
| id |
label |
detection_status |
attacker_action |
systems |
detection_signals |
chokepoint_links |
| lure_delivery |
Lure Delivery |
detected |
Phishing link / device code email |
Email GW · Endpoint · Browser |
| Link to newly registered domain (<30 days) delivered via email or Teams message |
| Redirect chain ending at a lookalike Microsoft / Google login page |
| Device code authentication request from unexpected IP or user-agent |
| Browser navigating to domain mimicking login.microsoftonline.com or accounts.google.com |
|
| label |
slug |
| ClickFix Techniques |
clickfix-techniques |
|
|
|
| id |
label |
detection_status |
attacker_action |
systems |
detection_signals |
| proxy_interception |
Proxy Interception |
exploited |
Reverse proxy relays real IdP traffic |
Network · IdP · Browser |
| MFA prompt satisfied from IP that issued no prior authentication request to IdP |
| Authentication token issued to a domain that is not a registered app redirect URI |
| TLS certificate on login page issued to non-Microsoft/Google CA for IdP lookalike domain |
| Concurrent authentication sessions for same account from two geographically distinct IPs |
|
|
| id |
label |
detection_status |
attacker_action |
systems |
detection_signals |
chokepoint_links |
| token_harvest |
Token Harvest |
exploited |
Session cookie / OAuth token extracted at proxy |
IdP · Browser |
| Session cookie replayed from IP different from original authentication IP |
| OAuth refresh token exchange from unfamiliar device fingerprint or user-agent |
| Access token issued for broad Microsoft Graph scopes (Mail.Read, Files.ReadWrite) to unrecognized app |
| Device code token grant without matching device registration in Entra ID |
|
| label |
slug |
| Browser Credential Theft |
browser-credential-theft |
|
|
|
| id |
label |
detection_status |
attacker_action |
systems |
detection_signals |
| account_takeover |
Account Takeover |
exploited |
Token replay from new IP/device without re-auth challenge |
SaaS · M365 · Google Workspace |
| Impossible travel: session re-used from country different from prior authentication within minutes |
| Sign-in from new ASN or hosting provider with no prior user activity |
| CAE (Continuous Access Evaluation) token re-use after IP change without re-authentication |
| First-time access to sensitive mailbox folders (e.g., Sent Items, Inbox search) from session token |
|
|
| id |
label |
detection_status |
attacker_action |
systems |
detection_signals |
| persistence_objectives |
Persistence & Objectives |
detected |
OAuth app consent · email rules · device registration |
M365 · Entra ID · Google Workspace |
| New OAuth application consent granted with Mail.Read or Files.ReadWrite permissions |
| Inbox rule created to forward or delete mail containing keywords (invoice, payment, wire) |
| New device registered to Entra ID from unfamiliar IP immediately after session token use |
| Admin role assigned to recently-created or newly-compromised account |
| Service principal credential added outside normal provisioning workflow |
|
|
|
| name |
status |
lure_delivery |
proxy_interception |
token_harvest |
account_takeover |
persistence_objectives |
| Tycoon 2FA |
Active |
Mass-phishing email with O365 / M365 login lure link; targets org domains at scale |
JavaScript-heavy Cloudflare-fronted reverse proxy relays real Microsoft IdP |
Captures session cookie in real time; strips MFA token from relay stream |
Replays harvested cookie from attacker infrastructure; no re-auth required |
Inbox forwarding rules; OAuth app consent for persistent mail access |
|
| name |
status |
lure_delivery |
proxy_interception |
token_harvest |
account_takeover |
persistence_objectives |
| Evilginx |
Active |
Targeted spearphishing link; operator configures phishlet per IdP target |
Open-source Go-based reverse proxy; intercepts full session including MFA |
Extracts session cookies and tokens from proxied responses via phishlets |
Exports cookie for direct browser import; used by operator in targeted campaigns |
Operator-driven post-access: OAuth consent, new credentials, lateral phishing |
|
| name |
status |
lure_delivery |
proxy_interception |
token_harvest |
account_takeover |
persistence_objectives |
| EvilProxy |
Active |
Phishing-as-a-service platform; delivers links via email or Telegram bot |
Commercial reverse proxy service; supports Microsoft, Google, Apple IdPs |
Real-time cookie interception; dashboard shows captured tokens per campaign |
Automated token replay; BEC-focused buyer use cases |
Email hiding rules; exfiltration of financial email content for BEC fraud |
|
| name |
status |
lure_delivery |
proxy_interception |
token_harvest |
account_takeover |
persistence_objectives |
| Sneaky 2FA |
Active |
Phishing kit with dark-themed Microsoft 365 lure pages; targets enterprise users |
Kit-based AiTM with partial relay approach. Less automated than EvilProxy. |
Session cookie capture from proxied Microsoft authentication flow |
Manual or semi-automated token replay; operator-controlled timing |
Inbox rules for BEC follow-on; selective data access for financial fraud |
|
| name |
status |
lure_delivery |
proxy_interception |
token_harvest |
account_takeover |
persistence_objectives |
| Device Code Flow |
Active |
Email delivers device code with social engineering (IT helpdesk, Teams invite) |
No reverse proxy. Victim authenticates to real IdP. Device code polling captures the token. |
OAuth refresh token obtained via device authorization grant; long-lived access |
Refresh token used for persistent API-level access to M365 Graph endpoints |
Service principal or app registration with delegated permissions; sustained access |
|
|
| lure_delivery |
proxy_interception |
token_harvest |
account_takeover |
persistence_objectives |
| Victim clicks a link or opens an attachment that initiates an authentication flow to an attacker-controlled endpoint |
Active session passes through adversary-controlled infrastructure OR device code is presented to victim |
Session token or OAuth access/refresh token extracted before or after MFA completion |
Token replayed from unfamiliar IP/device without triggering re-authentication challenge |
Attacker holds an authenticated session with sufficient privilege to modify account configuration |
|