GlossarySecurity awareness

Adversary in the middle

Short answer

An adversary in the middle (AitM) attack places the attacker between a user and the service they are using, so the attacker can read, alter or steal what passes between them. Today it is most often used in phishing kits that steal session cookies and bypass MFA.

On the network

The classic form intercepts traffic on a network the attacker controls or can manipulate: a fake WiFi hotspot named after a café or hotel, a compromised router, or techniques such as ARP spoofing on a local network. Encryption with TLS (HTTPS) has made reading traffic much harder, which is why attackers have moved to other methods.

In phishing

Modern phishing kits act as a reverse proxy: the victim sees the real login page of Microsoft 365 or Google, relayed through the attacker's server. The victim enters the password and completes MFA normally, and the attacker captures the session cookie created after login. With that cookie, the attacker can access the account without the password or the second factor, which leads to account takeover.

Defences

MFA that resists phishing, such as passkeys or FIDO2 security keys, is bound to the real website and does not work through a proxy. Conditional access policies can require managed devices or trusted locations and shorten session lifetimes. Alerts on sign ins from unusual infrastructure help detect stolen sessions, and revoking sessions should be part of the response to any suspected compromise.

Everyday precautions

Avoid untrusted public WiFi for work or use a VPN, keep browsers and devices updated, and teach users that a correct looking login page is not proof that it is legitimate. Checking the address bar is still useful, and security awareness training should cover this technique.

Related terms

Keep reading on this topic

Turning employees into an active line of defence: awareness training, phishing simulation, device and identity hygiene, and SaaS access control.

Go to the topic hub