Contacts
Book a Meet
Close

Contacts

Bulgaria, Kavarna
Saudi Arabia, Riyadh

+359 875 328030

sales@diamatix.com

Contacts

Bulgaria, Kavarna
Saudi Arabia, Riyadh

+359 875 328030

sales@diamatix.com

274258

Evilginx AiTM Campaigns Show How Attackers Bypass MFA by Stealing Active Sessions

Overview

Recent phishing campaigns targeting Microsoft accounts highlight the continued risk of Adversary-in-the-Middle (AiTM) attacks. In this model, attacker-controlled infrastructure sits between the user and the legitimate login page, relaying traffic in real time while capturing credentials, MFA approvals, and authenticated session cookies.

One of the best-known tools used for this type of attack is Evilginx. Rather than presenting a static fake page, it proxies the real login flow through attacker-controlled infrastructure. This allows attackers to capture a valid authenticated session after the victim enters a password and completes MFA.

These techniques are well documented by Microsoft and other researchers. In May 2026, Microsoft reported a large AiTM campaign targeting more than 35,000 users across over 13,000 organizations, where attackers used multi-stage social engineering to compromise authentication tokens.

How the Attack Works

In traditional phishing, the victim enters credentials into a fake page. In an AiTM attack, the process is more dangerous because the victim is interacting with the real service, but through attacker-controlled infrastructure.

A typical chain looks like this:

  • the user receives a phishing link to a lookalike domain;
  • the page proxies the Microsoft login flow through attacker-controlled infrastructure;
  • the user enters their username and password;
  • the user approves the MFA prompt;
  • the attacker captures the session cookie or token;
  • the attacker reuses the valid session without needing the password or another MFA code.

This is why standard MFA is not sufficient in this scenario. The user successfully completes MFA, but the attacker captures the result of that successful authentication.

Why This Matters

Many organizations assume that enabling multi-factor authentication is enough to protect against account takeover. AiTM attacks show that this assumption is no longer reliable.

The core risk is not only stolen credentials. It is stolen authenticated sessions. If an attacker obtains a session cookie or refresh token, they may access cloud services without the user seeing another sign-in prompt or MFA challenge.

This is especially critical in Microsoft 365 environments, where one compromised account may expose:

  • email;
  • Teams communication;
  • OneDrive and SharePoint files;
  • calendars and contacts;
  • internal documents;
  • connected SaaS applications;
  • follow-on phishing from a trusted account.

Why Evilginx Is Hard to Spot

Evilginx and similar tools are effective because they use the real login flow. The user sees a familiar Microsoft interface, goes through expected steps, and may not see a clear visual sign that anything is wrong.

These campaigns often combine:

  • lookalike domains;
  • well-crafted email lures;
  • role-specific social engineering;
  • realistic pretexts involving documents, policies, urgent internal issues, or partner communication;
  • rapid reuse of stolen sessions before detection.

User awareness remains important, but it cannot be the only line of defense.

Recommended Actions

Organizations should move from standard MFA toward stronger identity and session protection.

Priority actions include:

  • deploy phishing-resistant MFA, such as FIDO2 security keys or passkeys;
  • enforce Conditional Access policies;
  • enable Token Protection in Microsoft Entra ID where applicable;
  • monitor sessions used from new devices, countries, or IP addresses;
  • revoke suspicious tokens and terminate active sessions;
  • restrict critical application access to managed devices;
  • monitor OAuth grants and post-login behavior;
  • treat external links leading to Microsoft login flows with increased scrutiny.

Microsoft recommends phishing-resistant authentication strength in Entra ID Conditional Access, while passkeys and FIDO2 use origin-bound cryptography that helps prevent classic proxy-based phishing.

DIAMATIX Perspective

This type of attack shows that identity protection can no longer be viewed as only a password-plus-MFA problem.

Risk is shifting toward:

  • active session theft;
  • token abuse;
  • access from unfamiliar devices;
  • normal-looking activity after sign-in;
  • legitimate cloud applications used as part of the attack.

For DIAMATIX, the key lesson is that protection must cover the full identity lifecycle: sign-in, session, device, behavior, application access, and response to anomalies.

MFA remains important, but it is not a standalone defense against every phishing scenario.

CISO Analysis

From a CISO perspective, Evilginx-style AiTM attacks are a risk to identity, sessions, and cloud access.

Key questions include:

  • Are administrators and critical roles protected with phishing-resistant MFA?
  • Can we detect a session used from a different device or unusual location?
  • Do we have a process to quickly revoke tokens and terminate sessions?
  • Are we relying on MFA as a final control without post-login monitoring?
  • Is access to sensitive applications restricted to managed devices?
  • Is the SOC monitoring for signs of AiTM phishing and session hijacking?

With this type of attack, a successful sign-in does not automatically mean legitimate access. Organizations must monitor what happens after authentication.

What This Means for Your Environment

  • This type of attack relies on capturing a valid session after successful MFA approval, not only stealing a password.
  • Detection depends on visibility into sessions, tokens, devices, locations, and post-login behavior.
  • Response requires phishing-resistant MFA, Conditional Access, token revocation, session termination, and Microsoft 365 activity monitoring.

Could you detect a compromised Microsoft 365 session if the user successfully completed MFA?

Do you have a process to rapidly terminate sessions and revoke tokens when AiTM activity is suspected?

See how identity-focused attacks are investigated and handled in real operational

Contact DIAMATIX
Trusted · Innovative · Vigilant


Sources

  • Microsoft Security. Multi-stage phishing campaign leading to AiTM token compromise.
  • Microsoft Learn. Passkeys and FIDO2 authentication in Microsoft Entra ID.
  • Microsoft Learn. Conditional Access authentication strengths.
  • NetSPI / public reporting on Evilginx AiTM scenarios.

This article is based on publicly available technical information and analysis as of June 2026.

  • B available information and analysis as of June 2026.

Subscribe for latest updates & insights

Please enable JavaScript in your browser to complete this form.