TL;DR: An AiTM phishing-as-a-service kit paired with cloaking can steal session cookies, bypass MFA, and make automated URL analysis return clean but misleading results, according to Abnormal AI’s analysis of Blacksite; the service is sold with pricing, capacity slots, and buyer reviews, which lowers the attacker skill bar. Clean scanner verdicts must now be treated as inconclusive, not safe.
Editorial analysis by NHI Mgmt Group, based on content published by Abnormal AI: “Blacksite: New AiTM Phishing Kit Evades URL Scanners via Cloaked.gg”.
Key questions
Q: What breaks when URL scans are treated as a safe verdict for phishing links?
A: Clean URL scans fail when the attacker serves different content to scanners and people.
Q: Why do AiTM phishing kits still succeed against MFA?
A: AiTM kits succeed because they capture the authenticated session, not just the password.
Q: How can security teams spot cloaking before a suspicious link is clicked?
A: Teams should look for mismatches between link reputation, destination behaviour, and infrastructure signals such as ASN filtering, fingerprint-based blocks, and decoy content.
Practitioner guidance
- Harden post-authentication session controls Bind sessions more tightly to device, browser, and contextual signals so a stolen cookie is harder to replay outside the original login context.
- Treat clean URL scans as inconclusive Do not clear suspicious links solely because automated analysis returns a benign result when cloaking, ASN filtering, or fingerprint checks may be present.
- Prioritise identity-aware detection after login Watch for unusual session reuse, impossible travel, fresh browser fingerprints, and account activity that follows a normal-looking authentication event.
Bottom line: Blacksite shows that an AiTM kit plus cloaking can turn a benign-looking URL into a fully working phishing operation for the intended victim.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Clean URL verdicts are now a weak control when attackers can shape the analysis path. Abnormal AI’s analysis shows that cloaking services can serve decoy pages to scanners while exposing the real payload only to intended victims. That means the defensive question is no longer whether a link looks benign in a sandbox, but whether the sandbox ever saw the same content a user would see. Practitioners should treat automated URL verdicts as one signal among several, not as a safety decision.
A few things that frame the scale:
- Tycoon 2FA alone accounted for 62% of phishing detected by Microsoft and over 64,000 confirmed incidents.
A question worth separating out:
Q: What should identity teams do after a suspicious session is established?
A: They should focus on session containment, not just password resets. That means revoking active sessions, checking for anomalous reuse, reviewing device and location context, and looking for downstream access that occurred after the initial login. If the session cookie was captured, the account may remain exposed even after credentials are changed.
👉 Read our full editorial: Blacksite shows why clean URL verdicts can still hide AiTM phishing