A fake Okta page went live less than 40 minutes after its domain was registered, and within a minute at least 76 employees had a text message pointing at it. Three of them typed their passwords. The page was never the prize. The live relay behind it was.
Adversary-in-the-middle (AiTM) phishing steals MFA login sessions by sitting between an employee and the real sign-in service. The kit relays the password and the one-time code or push approval as the employee enters them, completes the real login, and keeps the session the identity provider issues. Microsoft's Storm-1167 investigation and Barracuda's Whisper 2FA analysis document that relay in detail. Cloudflare and Reddit show what it looks like from the victim's side.
This page is the rolling "what happened" hub for AiTM at login. The full incident write-ups stay where they are: Cloudflare's SMS phishing near miss, Reddit's employee phishing breach, Storm-1167's session theft, and the Whisper 2FA kit. Helpdesk resets and coached phone calls live on the workforce vishing hub.
How a relay kit turns one login into an attacker session
According to Microsoft Threat Intelligence on 8 June 2023, a multi-stage AiTM and business email compromise campaign against banking and financial services organizations started from a compromised trusted vendor. The email carried a seven-digit code as its subject and a link to a "fax document". The link led to a Canva-hosted page showing a fake OneDrive preview, then to a spoofed Microsoft sign-in page on Tencent cloud. The kit belonged to a developer Microsoft tracks as Storm-1167.
The target typed a password. The attacker used it in its own authentication session with the real service. When the real service asked for MFA, the kit switched the phishing page to a forged MFA prompt. The target completed it, and the session token went to the attacker. Microsoft calls this an indirect proxy because, unlike reverse-proxy kits such as EvilProxy, no HTTP traffic is passed straight through. The result is the same. A few hours later the attacker signed in with the stolen cookie from a US IP address and read email and cloud documents.
Barracuda describes the same idea sold as a service. Its analysts have tracked Whisper 2FA since July 2025, counted close to a million attacks in a single month, and rank it the third most common phishing-as-a-service platform after Tycoon and EvilProxy. When an account wants an SMS or authenticator code, the kit shows a code field, and the attacker tries each code on the real login at once. A wrong or expired code just gets the victim asked again, with unlimited retries. It can also wait for a push approval instead. That is documented kit capability, not a named victim breach.
What the session cookie bought after the MFA prompt
Storm-1167's operator did not stop at reading mail. According to Microsoft, the attacker added a phone-based one-time password method (OneWaySMS, with an Iranian country code number) to the victim's account, and adding a method did not require re-authentication by default. Then came an inbox rule that moved incoming mail to the Archive folder, and more than 16,000 phishing emails to the victim's contacts and distribution lists. Internal recipients who clicked were hit by a second AiTM round. Microsoft says a password reset does not fix this. Responders have to revoke session cookies and roll back the attacker's MFA changes.
Reddit's findings post of 9 February 2023 is shorter. Reddit became aware on 5 February of a phishing campaign targeting employees. After obtaining one employee's credentials, the attacker reached some internal documents, limited code, and limited contact and advertiser information. Production systems, including Reddit Ads, were not impacted, and the employee self-reported. Public reporting in Reddit's post does not establish whether a second factor was captured or relayed.
| Case | What is confirmed | What it shows |
|---|---|---|
| Storm-1167 (Microsoft, 2023) | Session cookies stolen, mailboxes used for BEC | Completed MFA still handed over the session |
| Whisper 2FA (Barracuda, 2025) | Kit capability, close to a million attacks a month | Retries until a code works |
| Reddit (2023) | One employee's credentials, internal documents reached | Role of MFA not stated |
| Cloudflare (2022) | Three passwords entered, no systems compromised | Security keys refused the relayed login |
Why Cloudflare's three typed passwords went nowhere
Cloudflare logged the first texts at 22:50 UTC on 20 July 2022. At least 76 employees got them in under a minute, on personal and work phones, and some family members did too. The texts pointed at cloudflare-okta.com, registered less than 40 minutes earlier. The page copied the Okta login, relayed credentials to the attacker over Telegram in real time, and then asked for a TOTP code.
Three employees entered credentials. It did not matter. Cloudflare does not use TOTP codes and requires a FIDO2 security key for every employee. The attacker tried the stolen passwords and could not get past the hardware key requirement. According to Cloudflare, Twilio was compromised by an attack with very similar characteristics around the same time.
That contrast is the lesson of this hub. A password, a six-digit code, or a push tap is something a person can hand to the wrong page, and the relay carries it to the right one. Legacy MFA built on those factors fails exactly here, at the moment the employee believes the login is real. A fix exists for that moment, and it does not depend on employees spotting a lookalike domain.
If you want to skip the attack details and go straight to what can stop this, read the related article on mfa2point0.com: phishing-proof MFA stops AiTM session theft.
FAQ
How does AiTM phishing steal an MFA-protected login session?
AiTM phishing steals an MFA-protected session by relaying the employee's password and second factor to the real sign-in service while the employee is still on the fake page. In the Storm-1167 campaign Microsoft documented in June 2023, the target completed MFA on a forged prompt and the session token went to the attacker, who later signed in with the stolen cookie without the password or MFA.
Was the Reddit February 2023 breach an AiTM attack?
Reddit's own disclosure confirms a phishing campaign that obtained one employee's credentials, not a specific AiTM mechanism. According to Reddit's 9 February 2023 post, the attacker reached some internal documents, limited code, and limited contact and advertiser information. Public reporting in Reddit's post does not establish whether a second factor was captured or relayed.
Why did the July 2022 SMS phishing attack on Cloudflare fail after employees entered passwords?
The July 2022 SMS phishing attack on Cloudflare failed because Cloudflare requires a FIDO2 security key for every employee instead of one-time codes. Three employees entered credentials on the fake Okta page, but the attacker could not get past the hardware key requirement, and Cloudflare confirmed no systems were compromised.
Does a password reset end an AiTM compromise?
A password reset does not end an AiTM compromise on its own, according to Microsoft's Storm-1167 investigation. The attacker already holds a valid session and may have added its own MFA method, so responders also have to revoke session cookies and roll back those MFA changes. Closing the phishable login stops this path upstream. Malware after a legitimate login is a harder, separate problem.
Updates
2025-10-15: Kit disclosure
Barracuda documented Whisper 2FA, a phishing kit that loops victims through unlimited code retries while the attacker tests each Microsoft 365 MFA code on the real login, and counted close to a million attacks in one month.
Source: Barracuda Blog, Whisper 2FA threat spotlight
2023-06-08: Vendor campaign write-up
Microsoft documented a Storm-1167 kit campaign that captured session tokens after targets completed MFA on a forged page, then added an attacker phone OTP method and sent more than 16,000 follow-on phishing emails.
Source: Microsoft Security Blog, Storm-1167 AiTM phishing and BEC
2023-02-05: Named victim disclosure
Reddit disclosed that a phishing campaign targeting employees obtained one employee's credentials and reached some internal documents, limited code, and limited contact and advertiser information, without impacting production systems.
Source: Reddit, Sharing our findings around a data security incident
2022-07-20: Named victim contrast
Cloudflare documented an SMS phishing wave to a fake Okta page that relayed credentials in real time and asked for TOTP codes, where three employees entered passwords and FIDO2 security keys blocked every login attempt.