Open cardosec

Case 61A66E · Malware & intel · L3 Applied

Phishing kits and AiTM

Practise as: Explain it · Interview

Interview questionHow do adversary-in-the-middle phishing kits bypass MFA, and what actually stops them?

  1. 01 What is it?
  2. 02 How is it abused?
  3. 03 How do you stop it?
What a strong answer covers

Try it out loud first. Then check yourself:

  1. Kits like Evilginx, EvilProxy and Tycoon 2FA reverse-proxy the real login page between victim and IdP
  2. The victim completes real MFA; the proxy steals the resulting session cookie and replays it
  3. Push, SMS and TOTP MFA are all bypassed because the token is relayed in real time
  4. FIDO2/passkeys stop it: the credential is bound to the origin, so a lookalike domain gets no valid signature
  5. Also: conditional access with compliant-device checks, token binding, and alerting on impossible travel

If the interviewer pushes back

  • What post-compromise actions typically follow a stolen M365 session, e.g. inbox rules for BEC?

Go deeper

cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.