Focus on durable indicators rather than the current domain name. File hashes, panel assets, backend endpoints, and the live MFA relay behavior are more stable than hosting and branding. If those artifacts recur across domains, the threat is a kit lineage with persistence, not a one-off site, so hunting and takedown efforts should pivot on the shared build.
Why This Matters for Security Teams
A disposable phishing domain is usually a short-lived delivery point. A reusable AiTM kit is different: it is a repeatable capability that can be redeployed with new branding, new infrastructure, and new victims. That distinction matters because takedowns aimed only at the domain often miss the underlying build pipeline, operator tooling, and relay logic that keep the campaign alive. The right question is not whether a site looks new, but whether the artifacts behind it look familiar.
This is why teams should separate incident triage from threat lineage analysis. The former may confirm malicious activity; the latter determines whether defenders are dealing with a single host or an adaptable toolkit. Current guidance aligns with control thinking in the NIST Cybersecurity Framework 2.0, where identification, detection, and response depend on durable signals rather than superficial indicators. In practice, many security teams encounter the reusable kit only after the first wave of token theft has already been weaponised across fresh domains, rather than through intentional lineage hunting.
How It Works in Practice
Security teams distinguish the two by comparing stable technical indicators across campaigns, not by trusting the visible site name, logo, or registration data. Disposable phishing domains often change everything except the tactic. Reusable AiTM kits, by contrast, tend to preserve backend structure, phishing panel code, replay endpoints, asset fingerprints, and the behavior of the MFA interception flow.
Useful checks include:
- Comparing file hashes for HTML, JavaScript, images, and packaged panel components.
- Looking for repeated backend paths, API routes, and panel naming patterns.
- Correlating TLS certificate traits, hosting conventions, and redirect chains with known campaigns.
- Inspecting whether the kit relays credentials, cookies, or session tokens in the same sequence after MFA completion.
- Matching infrastructure reuse with threat intel and detection content from sources such as MITRE ATT&CK, which is useful for mapping valid-account abuse and initial access tradecraft.
Teams should also preserve evidence from live interaction, because AiTM behavior often becomes clearer only when the victim completes the login flow. That includes the order of prompts, POST parameters, token handoff timing, and any downstream redirects to legitimate services. If these artifacts recur across different domains, the campaign is likely sharing a build or operator template, even if the branding changes.
Operationally, this means detection engineering should focus on reusable patterns in email lures, web assets, and authentication telemetry, while threat intel should cluster domains into campaigns or kit families. Where possible, defenders should enrich alerts with sandboxed render captures, reverse-proxy logs, and source-code comparisons. These controls tend to break down when the kit is heavily server-side rendered or dynamically assembled per victim, because superficial code differences can hide the same relay workflow.
Common Variations and Edge Cases
Tighter lineage analysis often increases investigation time, requiring organisations to balance faster takedowns against deeper attribution and reuse tracking. That tradeoff matters because some phishing infrastructure is genuinely disposable, while some operators intentionally rotate every visible layer to frustrate correlation.
There is no universal standard for this yet, but best practice is evolving toward a confidence model: treat repeated kit artifacts, relay behavior, and backend reuse as stronger evidence than domain age or registrar detail alone. This becomes especially important when campaigns use compromised websites, fast-flux hosting, or per-target personalization. In those cases, branding changes are expected and do not signal a new threat family.
The edge case to watch is an AiTM framework that is customized enough to alter hashes but still preserves the same login interception sequence and session replay mechanics. In that situation, teams should rely on server-side telemetry, redirect behavior, and observed post-authentication actions rather than visual similarity. For broader control mapping, OWASP guidance on attack surface analysis and CISA alerting and reporting practices can help mature response workflows, even though the exact phishing kit may not be publicly catalogued. When relays are delivered through short-lived infrastructure with minimal logging, attribution becomes fragmentary and teams must move from certainty to probability-based clustering.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
MITRE ATT&CK and OWASP Agentic AI Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST AI RMF and NIST AI 600-1 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | DE.CM-1 | Continuous monitoring helps correlate repeated phishing artifacts across domains. |
| MITRE ATT&CK | T1111 | AiTM kits often intercept MFA codes and session tokens during authentication. |
| OWASP Agentic AI Top 10 | Agentic tooling can automate phishing kit reuse, branding, and deployment steps. | |
| NIST AI RMF | Pattern-based judgment on reused artifacts supports structured risk decisions. | |
| NIST AI 600-1 | GenAI may accelerate phishing kit variation and content generation. |
Use telemetry and detections to cluster related phishing activity beyond single-domain alerts.
Related resources from NHI Mgmt Group
- How should security teams contain an account compromise when a phishing kit can enroll a new passkey during an active session?
- What do security teams get wrong about kit-based phishing detection?
- How should security teams handle AiTM phishing that targets business accounts?
- How should security teams defend against malvertising that leads to AiTM phishing?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on August 24, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org