What is adversary-in-the-middle?
Adversary-in-the-middle attack - a type of attack aimed at intercepting legitimate users' authentication credentials and sessions
Azərbaycanca: Orta adam hücumu (adversary-in-the-middle) - qanuni istifadəçilərin autentifikasiya məlumatlarını və sessiyalarını ələ keçirməyə yönəlmiş hücum növü
How it works
In this type of attack, the threat actor acts as an intermediary between the user and the legitimate service, intercepting users' login credentials and authentication sessions. It is carried out through Phishing-as-a-service (PhaaS) platforms and Adversary-in-the-Middle (AiTM) attacks.
Defense checklist5
- 01
Implement Multi-Factor Authentication (MFA)
- 02
Train users to increase security awareness
- 03
Use EDR solutions to monitor suspicious activities
- 04
Use encryption
- 05
Conduct regular security audits
Real-world evidence
Mirage2FA and Greatness PhaaS platforms have carried out AiTM attacks targeting Microsoft 365 accounts, resulting in over 4,000 organizations being affected. (See:,)
Sources
- Welcome to BlackFile: Inside a Vishing Extortion Operationmandiant
- Phishing service spoofs RingCentral to steal Microsoft 365 accountsbleepingcomputer
- Mirage2FA Hijacks Companies’ Microsoft 365 Sessions, with Over 4K Victims in the USanyrun
Other attack types
See also6
This guide is AI-written from the real incident sources skopnix collected — the examples above are drawn from those cited items, nothing is invented.