AiTM and the Future of MFA Bypass: How Attackers Are Exploiting Weaknesses in Authentication Systems

In December 2025, a new phishing and MFA bypass attack, called Adversary-in-the-Middle (AiTM), started targeting Microsoft 365 and Okta users. This attack is extremely dangerous because it bypasses Multi-Factor Authentication (MFA)—the very security features many organizations depend on to protect their accounts. This guide will break down the attack in simple terms, provide a real-world example, and share ways you can defend yourself.

What is AiTM and MFA Bypass?

Imagine you’re logging into your work account, typing in your password, and then entering a code sent to your phone for MFA. MFA is supposed to be an extra layer of security that ensures you are who you say you are. But with this new Adversary-in-the-Middle (AiTM) attack, hackers can steal both your password and MFA code without you even realizing it.

How? The attacker positions themselves between you and the legitimate login page, allowing them to steal your session token (the key that says “you’re logged in”) in real-time. This means they can bypass MFA and access your account without needing the second factor.

What Makes AiTM So Dangerous?

The Adversary-in-the-Middle (AiTM) attack intercepts and hijacks the login flow, allowing the attacker to bypass MFA protections. Unlike traditional phishing attacks that steal just your password, AiTM attacks steal live session tokens as well, which are used to keep you logged in. This enables the attacker to gain access to your account without ever needing to enter your MFA code, effectively bypassing your two-factor authentication.

How the AiTM Attack Works: A Step-by-Step Breakdown

  1. The Phishing Email (The Lure)
  • The attack begins with a phishing email that appears legitimate. These emails often use convincing themes, such as payroll changes, year-end bonus notifications, or HR-related alerts.
  • Some campaigns use compromised corporate email accounts or bulk delivery infrastructure (e.g., Amazon SES) to evade detection systems and make the email seem credible.
  • The email typically includes shortened links that appear legitimate, tricking users into thinking they are opening Microsoft 365 or Okta’s real sign-in page.
  1. Lookalike Domains

Once you click the link, you are taken to a fake login page that looks identical to the legitimate Microsoft 365 or Okta login portal. However, these pages use lookalike domains designed to deceive you into believing you are on the official website. Examples include:

  • sso.okta-secure[.]io
  • sso.okta-cloud[.]com
  • secure-hr-portal[.]com
  • benefitsfactor[.]com
  • office365-signin[.]com

These domains proxy the real sign-in flow between you and the legitimate Okta or Microsoft site, making it difficult for the user to detect the fraudulent site.

  1. JavaScript Injection & Session Hijacking

On the fake login page, malicious JavaScript is injected into the form, capturing your username, password, and session token as you type them. This is more sophisticated than traditional phishing attacks because it intercepts your login credentials in real time.

  • The script captures both the credentials and the session tokens generated by MFA. As a result, MFA is rendered ineffective because the attacker has the session token and doesn’t need the MFA code to access your account.
  1. Bypassing MFA

After capturing the session token, the attacker can reuse the token to log in without needing the MFA code. This completely bypasses MFA, rendering it useless in this scenario. The attacker can now access your corporate resources, such as email, files, and sensitive data, as if they are you.

Example:

Here’s a real-world scenario showing how this attack might happen:

Step 1: Phishing Email

You receive an email that looks like it’s from your HR department, telling you to review your payroll or benefits details. It contains a link to “click here” to access your account. The email looks legitimate because it’s from a trusted source and seems urgent.

Step 2: Fake Login Page

You click the link and are taken to a fake login page. The page looks almost identical to the Microsoft 365 or Okta login page you use every day, and it even contains your company’s logo.

You think you’re logging in to your work account, so you enter your username and password.

Step 3: Credential and Session Token Theft

While you enter your information, the attacker relays your credentials to the real Microsoft or Okta login page. But as you enter your username and password, the attacker captures both your password and the session token (the key to your logged-in status).

They also capture any MFA code you enter, but they don’t need it because they already have the session token!

Step 4: Session Hijacking

Now, the attacker uses the stolen session token to log into your account. Since they have the token, they don’t need the MFA code. They can act as if they are you, accessing your email, files, or sensitive company data.

Step 5: The Attackers Are In

With your account in their hands, the attackers can do anything they want—steal sensitive data, send malicious emails, or even move around the network to compromise more accounts.

Indicators of Compromise (IoCs): How to Spot the Fake Sites

The hackers behind this attack create fake websites to capture your login credentials. Here are some examples of fake domains they might use, which are designed to look like legitimate login pages:

  • benefitssecureportal[.]com
  • mybenefits-portal[.]com
  • office365mailsecurity[.]com
  • secure-hr-portal[.]com
  • okta‑access[.]com
  • okta‑cloud[.]com
  • sso.okta‑secure[.]io
  • sso.okta-cloud[.]com

These domains are crafted to look similar to official login pages for Microsoft 365 or Okta. They may appear genuine, but they are designed to trick you into entering your credentials.

Why MFA is Bypassed

MFA is supposed to protect you by requiring two factors: something you know (password) and something you have (MFA code). However, in the AiTM attack, the session token is captured in real time, allowing the attacker to reuse the token to log into your account without needing the MFA code. This is what makes AiTM attacks so effective and dangerous—MFA is bypassed without ever triggering the second factor.

The Attack Infrastructure: How It’s Set Up

To make this attack harder to detect and more resilient, attackers use advanced techniques to build their phishing infrastructure:

  • Cloudflare hosting: Many of the lookalike domains are hosted on Cloudflare, which makes them harder to shut down or block.
  • Compromised legitimate accounts: Some phishing emails may come from compromised corporate mailboxes, making the email more believable and less likely to be flagged as phishing by email defenses.

Impact and Severity

This campaign is considered medium to high severity because it:

  • Bypasses MFA, which many organizations rely on as their last line of defense.
  • Steals both login credentials and session tokens, allowing attackers to access corporate resources.
  • Targets widely-used enterprise platforms such as Microsoft 365 and Okta, which are crucial for daily business operations.
  • If left unchecked, this attack could scale across many organizations globally, compromising sensitive data and systems.

MITRE ATT&CK Framework: Breaking Down the Attack

The MITRE ATT&CK framework is a widely used method for understanding and classifying cyberattack tactics and techniques. Here’s how this MFA bypass attack fits into that framework:

Detecting the Attack: What to Look For

If you suspect you’ve been targeted or compromised, here are some red flags you should look out for:

Email Indicators

  • Suspicious sender email addresses: Watch out for email addresses from strange or newly registered domains (e.g., okta-cloud.com, office365mailsecurity.com).
  • Phishing email content: The email may look legitimate at first but double-check the links and sender information.

Login Activity Indicators

  • Unusual login locations: Logins from unexpected locations or new devices that you don’t recognize. If your account is accessed from a different country or device, it could be a sign of a hijacked session.
  • Multiple logins in a short time: This could indicate that the attacker is reusing stolen credentials across multiple accounts.

MFA Bypass

  • Even though you have MFA enabled, unusual login sessions can occur where the attacker uses the session token without needing your MFA code. This is one of the telltale signs of an AiTM attack.

Defending Against This Attack: How to Protect Your Organization

To protect yourself and your organization from this MFA bypass attack, here are some key defense measures:

  1. Implement Stronger MFA
  • Use hardware-based MFA (e.g., FIDO2 keys, Yubikey) instead of SMS or app-based MFA. These methods are harder to bypass because they require physical devices.
  1. Educate Your Employees
  • Train employees to recognize phishing emails and fake login pages. Make sure they know how to verify URLs and avoid clicking on suspicious links.
  1. Monitor Login Activity
  • Monitor login logs for suspicious behavior, like logins from new locations, unrecognized devices, or unusual times. Use tools to alert you about these events in real time.
  1. Use Anti-Phishing Technology
  • Deploy anti-phishing filters on your email servers to detect and block malicious emails before they even reach your users. Implement domain-based email authentication (DMARC, DKIM, SPF) to help prevent spoofed emails.
  1. Block Suspicious Domains
  • Block or monitor lookalike domains like okta-cloud.com and office365mailsecurity.com on your network to prevent users from accessing malicious sites.

Conclusion: Protecting Against MFA Bypass Attacks

This AiTM MFA Bypass attack is one of the most dangerous and sophisticated phishing attacks we’ve seen, because it bypasses MFA, which is often the last line of defense for many organizations. Attackers can gain full access to your account by stealing your session token in real-time, without needing the MFA code.

To protect your organization:

  • Switch to stronger MFA methods like hardware tokens or FIDO2 keys.
  • Train employees to spot phishing attempts and verify suspicious emails.
  • Monitor login activity for signs of unusual behavior and session hijacking.
  • Use anti-phishing technology and block malicious domains associated with this attack.

Aegiron

Backed by 11+ years in cybersecurity and incident response, we decode the latest threats shaping today’s digital battlefield. This blog cuts through the noise with clear insights on vulnerabilities, emerging exploits, and the cyber news defenders can’t afford to miss.