The playbookAiTM · MitM phishing · reverse proxy phishing

Adversary-in-the-middle phishing

A phishing page that proxies the real login instead of imitating it. The victim authenticates against the genuine site through the attacker's server, completes multi-factor as normal, and the attacker keeps the resulting session cookie.

Why it matters to you

This is the technique that makes "we have MFA" an incomplete answer. The second factor is satisfied honestly and the stolen artefact is the session, not the password, so a password reset closes nothing. Revoke sessions and bind tokens to a device or a client certificate. In the logs the shape to look for is a genuine authentication from a hosting range followed immediately by activity from somewhere else on the same token.

Where we meet it

Kits are sold ready made, with per target templates traded as separate items, so an operator needs no understanding of the technique to run it. That is what moves this from a specialist attack to a commodity one.

Where this term stops being vocabulary

Sherlog is where you watch it happen to you

Knowing the word is the cheap half. The platform is the half where the term arrives attached to your domain, with a timestamp and the source it came from.