← All posts
Client-Side Security

Browser-in-the-Middle (BitM) Attacks: How Cybercriminals Are Bypassing MFA

For years, organizations have encouraged employees and customers to enable Multi-Factor Authentication (MFA) as one of the most effective defenses against account compromise.

While MFA continues to significantly reduce the risk of credential theft, attackers have adapted. Modern phishing campaigns no longer focus solely on stealing usernames and passwords—they increasingly target authenticated sessions.

One of the fastest-growing techniques is the Browser-in-the-Middle (BitM) attack.

Unlike traditional phishing attacks, BitM proxies the entire login process in real time, allowing attackers to capture authentication cookies and session tokens after MFA has been successfully completed.

The result? An attacker may gain access to an account without needing to know the user’s password or bypass MFA directly.

What Is a Browser-in-the-Middle Attack?

A Browser-in-the-Middle (BitM) attack is an advanced phishing technique in which an attacker places a malicious proxy browser between the victim and the legitimate website.

Instead of communicating directly with the real application, the victim unknowingly interacts with the attacker’s browser.

Every request passes through the attacker.

This allows the attacker to capture:

  • Usernames
  • Passwords
  • MFA responses
  • Session cookies
  • OAuth tokens
  • Authentication headers

Once authentication succeeds, the attacker can reuse the authenticated session.

How BitM Works

A typical Browser-in-the-Middle attack follows these steps:

Step 1: Phishing Lure

The attacker sends a phishing email or message directing the victim to a fake login page that closely resembles the legitimate service.

Step 2: Proxy Connection

Instead of hosting a fake login page, the attacker proxies the legitimate website in real time.

The victim believes they are interacting with the genuine application.

Step 3: User Authentication

The victim enters:

  • Username
  • Password
  • MFA code

The attacker forwards these credentials to the legitimate website.

Step 4: Session Capture

After successful authentication, the legitimate website issues session cookies or authentication tokens.

The attacker intercepts these values before passing them to the victim.

Step 5: Account Takeover

The attacker reuses the captured session token to access the account without needing the victim’s password or MFA code again.

Why MFA Alone Isn’t Enough

Traditional MFA protects against stolen passwords.

It does not always protect against stolen authenticated sessions.

If an attacker captures:

  • Session cookies
  • OAuth access tokens
  • Refresh tokens

they may be able to impersonate the user until the session expires or is revoked.

This highlights the importance of securing the entire authentication lifecycle—not just the login process.

Common Targets

Browser-in-the-Middle attacks frequently target:

  • Microsoft 365
  • Google Workspace
  • Salesforce
  • Banking portals
  • Cryptocurrency exchanges
  • Cloud administration consoles
  • VPN portals
  • HR platforms
  • Customer support systems

Any web application that relies on browser-based authentication may be a potential target.

Warning Signs

Indicators of a BitM campaign include:

  • Login pages hosted on unfamiliar domains
  • Unexpected browser certificate warnings
  • Suspicious URLs resembling trusted brands
  • Requests to reauthenticate unexpectedly
  • Login prompts received through unsolicited emails or messages

Security awareness remains an important layer of defense.

Best Practices to Reduce Risk

Adopt Phishing-Resistant Authentication

Use authentication methods that are resistant to phishing attacks, such as hardware-backed passkeys or security keys based on FIDO2/WebAuthn.

Strengthen Session Security

Protect authenticated sessions by implementing:

  • Short session lifetimes
  • Secure cookie attributes
  • Session binding where supported
  • Continuous session validation

Monitor Authentication Activity

Detect unusual login behavior, including:

  • Impossible travel
  • New devices
  • Unrecognized locations
  • Abnormal session activity

Implement Conditional Access

Apply risk-based access policies that consider:

  • Device posture
  • Geographic location
  • User behavior
  • Network reputation

before granting access.

Train Employees

Educate users about modern phishing techniques that go beyond credential theft and emphasize verifying URLs before authenticating.

Browser-in-the-Middle vs Traditional Phishing

Traditional PhishingBrowser-in-the-Middle
Steals usernames and passwordsProxies the entire authentication session
Often blocked by MFACan capture authenticated sessions after MFA
Uses fake login pagesUses a live proxy to the legitimate site
Relies on credential reuseRelies on stolen session cookies and tokens
Easier to detectMore convincing and difficult to identify

How BreachFin Helps

Modern identity attacks extend beyond passwords. Organizations need continuous visibility into authentication behavior, browser interactions, APIs, and client-side activity.

BreachFin helps security teams reduce exposure through continuous monitoring across modern digital environments.

Client-Side Monitoring

Detect unauthorized browser activity, suspicious scripts, and client-side anomalies that may indicate phishing or session hijacking attempts.

API Security

Monitor authentication APIs, token usage, and abnormal API behavior that could indicate compromised sessions.

Threat Intelligence

Identify malicious domains, phishing infrastructure, and brand impersonation attempts targeting employees and customers.

Continuous Monitoring

Correlate authentication events, cloud activity, browser telemetry, and infrastructure changes to identify suspicious behavior early.

Compliance Support

Provide continuous visibility that supports PCI DSS 4.0.1, NIST CSF, ISO/IEC 27001, and SOC 2 monitoring requirements.

Looking Ahead

Identity has become the new security perimeter, and attackers are increasingly targeting authenticated sessions instead of passwords.

Organizations that rely solely on passwords and traditional MFA may overlook risks associated with session hijacking and advanced phishing.

Strengthening identity security now requires a combination of phishing-resistant authentication, continuous monitoring, secure session management, and user awareness.

Conclusion

Browser-in-the-Middle attacks demonstrate that cybercriminals are evolving beyond traditional phishing techniques. Rather than attempting to bypass Multi-Factor Authentication directly, they exploit authenticated sessions to gain unauthorized access.

Organizations should complement MFA with phishing-resistant authentication, continuous monitoring, and proactive threat detection to reduce the risk of session hijacking.

At BreachFin, we help organizations secure their digital ecosystem by continuously monitoring cloud infrastructure, APIs, authentication systems, client-side applications, and digital assets. Our goal is to help businesses detect emerging threats earlier, reduce cyber risk, and maintain trust in an increasingly sophisticated threat landscape.

Protect your payment pages in real time

See how BreachFin inventories every script, catches tampering, and proves PCI DSS 4.0 compliance.

Get a demo

Related articles