Skip to content
Skip to main content
Cyber Incidents & Offender Methods Technical Explainer

What is adversary-in-the-middle authentication theft?

It is an authentication attack where an attacker-controlled service sits between the victim and the genuine service, relaying the sign-in while capturing useful authentication or session material.

The victim may believe they are signing in normally.

The attack can relay MFA rather than defeat it

A typical sequence is:

VictimVisits convincing sign-in pageCredentials are entered.
RelayAttacker-controlled service forwards authenticationGenuine service receives the attempt.
MFAVictim approves genuine challengeThe service may consider authentication valid.
SessionSession material is captured/reusedLater access may appear without another prompt.

The MFA mechanism may have worked exactly as designed while the victim approved the wrong transaction context.

Preserve each stage

Useful evidence may include:

  • phishing message;
  • fake/relay page;
  • browser history;
  • DNS/proxy/network records;
  • near-simultaneous authentication events;
  • MFA challenge/approval;
  • session creation;
  • rapid session use from different infrastructure.

The timing relationship can be particularly useful.

Approval is not proof of informed authorisation

A provider record may correctly show that the victim approved an MFA prompt.

That does not automatically mean they knowingly authorised the attacker.

Record what the prompt displayed and what the victim believed they were doing.

Keep the operator question separate

The relay infrastructure may identify hosting or an account, not necessarily the human operator.

Likewise, the later session user may be different from the person who set up the phishing infrastructure.

The practical point is: where phishing, MFA approval and rapid remote session use align, preserve the website, authentication and token/session lifecycle as one staged sequence.

Reference: CIM-055Cyber Incidents & Offender Methods