AiTM Phishing Scales by Filtering Out Bots

The break is not the lure. It is the conversion funnel. This campaign used authenticated-looking messages, CAPTCHA gates, and staging pages to separate real users from automated defenses, then pushed the survivors into an AiTM flow that could steal session tokens even when MFA was in place. Microsoft says the campaign hit tens of thousands of users, mostly in the United States. The messages used polished, enterprise-style HTML and legitimate email services to make attacker-controlled domains look like internal code-of-conduct notices, then led victims through multiple legitimacy checks before the final sign-in page. The forward risk is that stronger-looking phishing can now be used to concentrate successful token theft on fewer, higher-value targets. That makes session compromise more likely even in environments that already rely on non-phishing-resistant MFA.

Part of the PlainSec briefing for 2026-05-04

Sources