Adversary-in-the-Middle Phishing Hits 10,000 Organizations (July 2022): MFA Bypassed at Scale
Retrospective: this article looks back at events from July 2022, written in 2026 with the benefit of hindsight.
On July 12, 2022, Microsoft published research on a large-scale adversary-in-the-middle (AiTM) phishing campaign that had targeted more than 10,000 organizations since September 2021. The campaign bypassed multi-factor authentication by stealing session cookies.
How AiTM phishing works
- The victim receives a phishing email and clicks a link.
- The link leads to a proxy server controlled by the attacker, which relays the real Microsoft sign-in page.
- The victim enters their password and completes MFA — on the real Microsoft service, through the proxy.
- The proxy captures the session cookie issued after successful sign-in.
- The attacker uses that cookie to access the victim's mailbox without needing the password or MFA again.
Open-source toolkits such as Evilginx, Modlishka and Muraena made this technique accessible.
What happened next
In the campaign Microsoft described, attackers used stolen sessions to access mailboxes and run business email compromise — finding ongoing invoice conversations and inserting fraudulent payment instructions, sometimes within minutes. They created inbox rules to hide replies.
Why it mattered
AiTM proved that standard MFA — push notifications, SMS, authenticator codes — doesn't stop phishing on its own. The industry shifted toward:
- Phishing-resistant MFA (FIDO2, passkeys, Windows Hello, certificate-based authentication), which binds sign-in to the real site and can't be relayed.
- Device-based Conditional Access (requiring managed, compliant devices), so stolen cookies can't be used from attacker machines.
- Token protection and session anomaly detection.
In hindsight
AiTM kits evolved into phishing-as-a-service platforms. By 2026, device code phishing kits such as EvilTokens and Kali365 were the next iteration of the same idea: get the user to complete MFA on the attacker's behalf.
- How to Defeat AiTM Phishing With Compliant-Device and Phishing-Resistant MFA Policies How-To & Hardening
- Detecting AiTM Session Cookie Theft: Defender XDR and Sentinel Hunting Queries Detection & Response
- CIO Brief: Why Standard MFA No Longer Stops Phishing CIO Briefings