TL;DR: An AiTM phishing-as-a-service kit paired with cloaking can steal session cookies, bypass MFA, and make automated URL analysis return clean but misleading results, according to Abnormal AI’s analysis of Blacksite; the service is sold with pricing, capacity slots, and buyer reviews, which lowers the attacker skill bar. Clean scanner verdicts must now be treated as inconclusive, not safe.
At a glance
What this is: Abnormal AI’s analysis shows that Blacksite combines AiTM phishing with cloaking to hide real phishing pages from automated scanners while still capturing session cookies and enabling account takeover.
Why it matters: IAM and SOC teams should treat clean URL scans as an incomplete signal, because session hijacking can succeed even when MFA is present and automated analysis sees only decoy content.
Context
Clean URL analysis can fail when attackers control what scanners see. In this case, the security gap is not the phishing lure alone but the split between machine-facing decoy content and user-facing credential theft, which breaks the assumption that a benign verdict means a safe destination.
An adversary-in-the-middle kit changes the identity problem because it intercepts the authenticated session, not just the password. That makes the issue relevant to NHI and human IAM together: the user authenticates normally, but the attacker leaves with a valid session cookie that can be reused outside the original login flow.
Abnormal AI’s findings also show how commercialisation lowers the barrier to entry. When phishing and cloaking are packaged as separate services, defenders are no longer dealing with opportunistic fraud alone but with repeatable infrastructure designed to evade URL-based analysis.
Key questions
Q: What breaks when URL scans are treated as a safe verdict for phishing links?
A: Clean URL scans fail when the attacker serves different content to scanners and people. Cloaking can block cloud-based analysis, show a harmless page to automated tools, and still send a real victim to the phishing flow. Security teams should treat the scan result as one input, not a clearance decision, especially when account-login pages are involved.
Q: Why do AiTM phishing kits still succeed against MFA?
A: AiTM kits succeed because they capture the authenticated session, not just the password. If the attacker can intercept the one-time code and the session cookie during login, MFA has already done its job and the cookie becomes the reusable credential. Defenders therefore need controls that watch for session replay and token abuse after sign-in.
Q: How can security teams spot cloaking before a suspicious link is clicked?
A: Teams should look for mismatches between link reputation, destination behaviour, and infrastructure signals such as ASN filtering, fingerprint-based blocks, and decoy content. If a page behaves differently for scanners than for normal browsers, the URL should stay under suspicion. The practical test is whether the same content is visible across analysis paths.
Q: What should identity teams do after a suspicious session is established?
A: They should focus on session containment, not just password resets. That means revoking active sessions, checking for anomalous reuse, reviewing device and location context, and looking for downstream access that occurred after the initial login. If the session cookie was captured, the account may remain exposed even after credentials are changed.
Technical breakdown
How AiTM reverse proxies steal the session, not just the password
An adversary-in-the-middle phishing kit sits between the user and the real site, relaying traffic in real time so the login appears normal while the attacker captures tokens, one-time codes, and session cookies. The cookie matters most because it represents an already authenticated browser session, which can be replayed without re-running the original MFA step. That is why AiTM campaigns are so effective against logins that rely on a second factor but still trust the resulting session blindly. The attack is not about breaking encryption. It is about placing the attacker inside the authentication path long enough to inherit the session.
Practical implication: Treat session binding and post-authentication controls as part of MFA design, not a separate concern.
How cloaking services create split-view URLs for scanners and users
Cloaking services classify incoming traffic by ASN, IP reputation, browser fingerprint, and request patterns, then choose whether to block, divert, or serve a benign page. In the Blacksite case, suspected scanners could be shown AI-generated decoy content while intended victims were routed to the live phishing flow. That means the same URL can produce two different outcomes depending on who is asking. For defenders, this breaks the assumption that sandbox detonation and reputation checks provide a definitive verdict. A URL can look inert in analysis and still be fully operational for a human target on a residential connection.
Practical implication: Assume URL reputation is provisional when traffic shaping is in play and validate suspicious links outside automated-only workflows.
Why commercial AiTM services reduce attacker friction
Blacksite’s pricing, capacity slots, buyer reviews, and bundled cloaking layer show how phishing has become productized. That matters because the operator no longer needs to build the reverse proxy, the session capture workflow, and the anti-detection logic independently. The result is lower skill requirement, faster deployment, and more repeatable campaigns. The defender’s problem changes accordingly: the threat is no longer a bespoke phishing page but a service model designed to be bought, scaled, and re-used across lures. In practice, that increases the likelihood that ordinary users and standard controls will encounter the same attack pattern repeatedly.
Practical implication: Model AiTM phishing as an operating service with reuse and scale, not as a one-off lure.
NHI Mgmt Group analysis
Clean URL verdicts are now a weak control when attackers can shape the analysis path. Abnormal AI’s analysis shows that cloaking services can serve decoy pages to scanners while exposing the real payload only to intended victims. That means the defensive question is no longer whether a link looks benign in a sandbox, but whether the sandbox ever saw the same content a user would see. Practitioners should treat automated URL verdicts as one signal among several, not as a safety decision.
Session cookies are the real asset in modern AiTM phishing, not the password. The article makes clear that Blacksite succeeds because it captures authenticated session material in real time. Once that cookie exists, MFA has already done its job at the login step and still fails at the session layer. That shifts the governance problem from initial authentication to session control, which is where many identity programmes remain underweighted.
Commercialised phishing lowers the barrier to identity compromise across the enterprise stack. When reverse proxies and cloaking are sold as separate services, the threat becomes modular and repeatable. This is not just a phishing problem for email security teams. It is a human identity issue, an access-control issue, and a detection issue that spans the entire authentication journey from lure to session reuse.
Identity telemetry has to be evaluated after authentication, not only before it. A clean URL scan can coexist with an actively hijacked session if the control model stops at reputation and delivery time. That is why identity behaviour after login, especially session persistence and unusual reuse patterns, becomes the decisive evidence trail. Security teams that stop at pre-click analysis are blind to the part of the attack that actually grants access.
Identity and access governance should treat cloaking as an evasion layer, not a content layer. The same URL can present different realities to different requesters, so governance built only around link classification will miss the operational target. The concept to name here is split-view phishing: one destination for scanners, another for humans. Practitioners should design controls around the probability of divergent content, not around the assumption of a single page view.
From our research library:
- Tycoon 2FA alone accounted for 62% of phishing detected by Microsoft and over 64,000 confirmed incidents.
What this signals
Split-view phishing is the operational pattern defenders need to name here. When a phishing service can present one page to scanners and another to the target, automated verdicts stop being authoritative and become simply incomplete. That changes the control objective from URL classification to path validation across analysis and user-facing contexts.
For identity programmes, the important lesson is that authentication success does not equal access safety. If session cookies are stolen during a live proxy exchange, post-authentication telemetry becomes the only dependable place to spot compromise. Teams should therefore align detection, IAM, and SOC workflows around the behaviour of the session, not just the reputation of the link.
For practitioners
- Harden post-authentication session controls Bind sessions more tightly to device, browser, and contextual signals so a stolen cookie is harder to replay outside the original login context.
- Treat clean URL scans as inconclusive Do not clear suspicious links solely because automated analysis returns a benign result when cloaking, ASN filtering, or fingerprint checks may be present.
- Prioritise identity-aware detection after login Watch for unusual session reuse, impossible travel, fresh browser fingerprints, and account activity that follows a normal-looking authentication event.
- Add human review for suspicious high-risk links Route links with account-login intent, short URLs, or brand impersonation through manual verification when scanner confidence is low or inconsistent.
Key takeaways
- Blacksite shows that an AiTM kit plus cloaking can turn a benign-looking URL into a fully working phishing operation for the intended victim.
- The operational risk sits in the session layer, because stolen cookies and tokens can preserve access even after MFA has been completed.
- Defenders should stop treating a clean scanner result as proof of safety and instead verify suspicious links and sessions through identity-aware controls.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST SP 800-63 sets the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-02 — Secret Leakage | The campaign captures session cookies and one-time codes during live authentication. |
| NHI-04 — Insecure Authentication | AiTM proxying defeats MFA by reusing the resulting authenticated session. | |
| NHI-10 — Human Use of NHI | Stolen session cookies let human-targeted phishing abuse bearer access. | |
| Recommendation — Reduce exposure of session-bearing secrets and revoke any captured tokens immediately. Strengthen authentication paths so live proxy capture cannot yield reusable sessions. Limit human exposure to bearer sessions and monitor for abnormal session reuse. | ||
| NIST SP 800-63 | SP 800-63B — Authentication | The article shows why authentication alone does not protect against session hijacking. |
| Recommendation — Apply phishing-resistant authentication and bind sessions to reduce replay risk. | ||
| MITRE ATT&CK | TA0006;TA0008 — Credential Access; Lateral Movement | The campaign harvests live credentials and then reuses the session to move into accounts. |
| Recommendation — Map AiTM phishing telemetry to credential access and lateral movement hunt paths. | ||
Key terms
- Adversary-in-the-middle phishing: A phishing method that places an attacker between the user and the real identity provider so the attacker can intercept or relay the authenticated session. It often preserves the user experience, which is why it can evade awareness and some detection paths while still producing usable session tokens.
- Cloaking Infrastructure: A detection-evasion layer that shows different content depending on who visits the site. It can block cloud scanners, fingerprint security tools, and serve benign decoy pages while allowing real users through, which makes reputation-based verdicts unreliable when used alone.
- Persistent Cookie: A persistent cookie is a session cookie that remains valid after the browser closes until it expires or is explicitly removed. In remote access designs, it can improve usability, but it also increases the chance that a reused session becomes standing access if the organisation does not enforce compensating controls.
- Split-view phishing: A phishing pattern in which the same URL presents different content to scanners and real users. This creates a governance blind spot because automated analysis may report the link as benign while the victim is routed to the live malicious destination.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
Published by the NHIMG editorial team on June 27, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org