What is adversary-in-the-middle authentication theft?¶
It is an authentication attack where an attacker-controlled service sits between the victim and the genuine service, relaying the sign-in while capturing useful authentication or session material.
The victim may believe they are signing in normally.
The attack can relay MFA rather than defeat it¶
A typical sequence is:
The MFA mechanism may have worked exactly as designed while the victim approved the wrong transaction context.
Preserve each stage¶
Useful evidence may include:
- phishing message;
- fake/relay page;
- browser history;
- DNS/proxy/network records;
- near-simultaneous authentication events;
- MFA challenge/approval;
- session creation;
- rapid session use from different infrastructure.
The timing relationship can be particularly useful.
Approval is not proof of informed authorisation¶
A provider record may correctly show that the victim approved an MFA prompt.
That does not automatically mean they knowingly authorised the attacker.
Record what the prompt displayed and what the victim believed they were doing.
Keep the operator question separate¶
The relay infrastructure may identify hosting or an account, not necessarily the human operator.
Likewise, the later session user may be different from the person who set up the phishing infrastructure.
The practical point is: where phishing, MFA approval and rapid remote session use align, preserve the website, authentication and token/session lifecycle as one staged sequence.