> For the complete documentation index, see [llms.txt](https://red.infiltr8.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://red.infiltr8.io/redteam/delivery/phishing/phishing-via-proxy/adversary-in-the-middle-aitm-phishing.md).

# Adversary in the Middle (AitM) Phishing

## Theory

AitM phishing is a technique that uses dedicated tooling to act as a proxy between the target and a legitimate login portal for an application, principally to make it easier to **defeat MFA protection**.

Adversaries may attempt to proxy multi-domain destination traffic (both TLS and non-TLS) over a single domain, without a requirement of installing any additional certificate on the client.

<figure><img src="/files/AZqwLGOQeM2Mdku9JWnj" alt=""><figcaption></figcaption></figure>

## Practice

## Resources

{% embed url="<https://attack.mitre.org/techniques/T1557/>" %}

{% embed url="<https://pushsecurity.com/blog/phishing-2-0-how-phishing-toolkits-are-evolving-with-aitm/>" %}
