
An aitm attack, short for Adversary-in-the-Middle, is a live interception of an authentication flow. The attacker relays traffic between the victim and the legitimate service, capturing credentials and, more importantly, the session token that lets them impersonate the user afterward. It is the modern successor to classic phishing, and it is the reason so many multi-factor-protected accounts still get taken over.
How Adversary-in-the-Middle works in the wild
The attacker stands up a reverse proxy that mimics a target service, whether that is a banking portal, an enterprise identity provider, or a cloud productivity suite. A phishing lure sends the victim to the proxy. The victim sees the real login page, complete with real branding, because the proxy pulls it from the legitimate site in real time. The victim enters credentials. The proxy forwards them to the real service. The real service prompts for a second factor. The victim completes it. The real service issues a session token. The attacker keeps a copy.
From that moment, the attacker holds a valid authenticated session for the victim account. They can log in, change settings, initiate transactions, or set up persistent access without needing the credentials or the second factor again. Standard multi-factor authentication does not stop this because it validates the login event, not the ongoing session.
Why traditional defenses miss it
Endpoint detection sees a user visiting a website. Email gateways see a message with a link that may or may not be flagged depending on freshness. Multi-factor authentication logs show a successful challenge on the victim device. The identity provider sees a login from an IP that increasingly matches residential ranges the attacker rents specifically to look normal.
Nothing in that sequence looks obviously wrong until the attacker starts acting on the session. Bank transfers get initiated. Payroll details get changed. Wire instructions get updated. Data exports get triggered. And even then, if the attacker moves patiently, the pattern can look like a slightly distracted employee for days.
Where fraud teams see the impact first
AITM operations feed directly into account takeover fraud. Financial institutions, e-commerce platforms, and crypto exchanges are the first to see the downstream loss. Stolen sessions turn into unauthorized transactions, refund fraud, mule funding, and gift card purchases. The customer complaint arrives days later. The forensic trail rarely leads back cleanly to the initial phishing event.
Because AITM produces valid tokens rather than raw credentials, brute force detection and password reset alerts do not fire. Fraud teams that rely solely on transaction rules catch the loss after it happens. The teams that pair transaction monitoring with session risk analysis catch it as it develops.
How Group-IB Fraud Protection stops the chain
Group-IB Fraud Protection watches the authenticated session, not just the login event. Device fingerprinting profiles each device that touches a customer account, so a session token replayed from an unknown device gets flagged even when the login logs look clean. Behavioral biometrics analyze typing rhythm, mouse movement, and interaction patterns to detect impersonation of the legitimate user.
Adaptive authentication steps up challenges only when risk warrants. That means real customers stay unfriction while impersonated sessions get challenged before they can complete a high-value action. The step-up itself uses methods resistant to AITM interception, which closes the loop on the technique that produced the compromise in the first place.
Behind the scenes, Group-IB Threat Intelligence Platform feeds indicators of active AITM infrastructure into the detection engine. When a phishing kit or reverse proxy framework becomes active against a customer brand, alerts include the observed indicators, so downstream session controls can catch impersonation attempts tied to that specific campaign.
For enterprises that need to take the phishing infrastructure off the internet, Group-IB Digital Risk Protection handles discovery and takedown of lookalike domains, spoofed applications, and impersonation sites. Removing the front-end proxy cuts off the campaign at the source and reduces the volume of AITM sessions that reach downstream defenses at all.
What good AITM defense looks like end to end
Layered defense against AITM starts with phishing-resistant authentication for everyone with access to money or sensitive data. Passkeys and hardware-backed FIDO2 tokens resist proxy interception because the cryptographic proof is bound to the legitimate origin. When those are in place, the volume of successful AITM sessions drops dramatically.
For everything else, continuous session risk evaluation catches impersonation after login. Device intelligence, behavioral analytics, and transaction risk scoring combine into a picture that says whether the current session belongs to the legitimate user, regardless of what the login event looked like.
Anti-phishing infrastructure completes the picture. Continuous monitoring for lookalike domains, credential harvesting sites, and coordinated campaigns targeting the brand shortens the window in which an active AITM operation can produce valid sessions in the first place.
Practical priorities
Baseline your account takeover rate and correlate against periods of active phishing pressure. If the numbers move together, your session controls are trailing the front-end problem, and there is measurable upside from investing in behavioral session analytics.
Test your controls against real AITM techniques. Group-IB Penetration Testing and Red Teaming include realistic phishing and session interception scenarios, and the output tells you which of your controls hold up and which need reinforcement.
Communicate with customers before campaigns land. Fraud teams that publish clear guidance on how the brand contacts customers, what an authentic login flow looks like, and how to verify unusual requests reduce the click rate on hostile lures. That protection stacks with technical controls and lowers the volume everything else has to handle.
AITM is not a passing trend. It is the current form of phishing, and every quarter it gets easier for attackers to deploy. The organizations that treat it as a full-stack problem, spanning identity, session, transaction, and brand infrastructure, are the ones that keep account takeover losses flat while the rest of the market watches them climb.