Because the value of the campaign sits in credential and session capture, not in the domain itself. Once the kit can recreate the sign-in flow and proxy authentication, it can harvest valid tokens from new infrastructure almost immediately. Takedowns disrupt logistics, but they do not remove the operator’s ability to recreate the access path.
Why domain takedowns do not end AiTM abuse
An AiTM kit is dangerous because it controls the interaction between the victim and the real service. The attacker can swap domains, infrastructure, and hosting without changing the core technique: capture credentials, intercept the authentication flow, and relay or steal the resulting session material. The domain is only the delivery surface.
The practical implication is that seizure disrupts the current campaign, but it does not neutralize the operator’s playbook. If the phishing flow, reverse proxy, or token capture logic survives, the same access path can be rebuilt quickly on new infrastructure and pointed at fresh victims.
That is why defenders should treat AiTM as an access-control problem as much as a phishing problem. The important question is whether the authentication process can be protected against relay, session theft, and token replay, not whether a single malicious domain is offline.
What actually makes the campaign persist
AiTM campaigns remain effective when the attacker can reproduce the login sequence well enough to sit in the middle of the trust relationship. That usually means the victim still sees a believable sign-in page, the real identity provider still receives a valid authentication attempt, and the attacker gets a reusable artifact such as a session cookie, bearer token, or authenticated browser state.
Once those artifacts are captured, the attacker often no longer needs the original domain. They can move to a new domain, a fresh reverse proxy, or another compromised host and continue harvesting valid access. The abuse scales with the quality of the access path, not the lifetime of the phishing infrastructure.
For a deeper look at how session theft and token handling remain the real problem, the Identity Provider and SSO Security Guide is useful because it focuses on token security, federation monitoring, and recovery controls rather than just the phishing landing page.
Phishing-resistant authentication changes the attacker’s economics because it removes or sharply limits what can be relayed. When users rely on weaker factors or reusable sessions, takedown speed matters less than the attacker’s ability to recreate the sign-in path faster than the victim can detect it.
Why defenders should focus on tokens, sessions, and recovery paths
In an AiTM scenario, the exposed asset is often the session, not the password. That means post-seizure risk depends on whether the attacker already has valid access material, whether the session can be replayed elsewhere, and whether the identity provider or application can detect abnormal token use after the original phishing site disappears.
Controls that harden the sign-in flow, shorten the useful life of captured material, and force reauthentication for sensitive actions reduce the attacker’s window. Workforce Identity Security Guide is relevant here because it covers phishing-resistant MFA, passkeys, federation, account recovery, and session theft as one problem set.
The operational lesson is that incident response must include credential and session invalidation, not only domain takedown. If the attacker can still present a valid token, the campaign remains live even after the phishing site is gone.
Teams should also understand the role of user recovery channels. Help desk resets, fallback MFA methods, and weak re-enrollment steps can become the next access path after the first domain is removed.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST SP 800-53 Rev 5, NIST Zero Trust (SP 800-207) and NIST SP 800-63 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-02 — Secret Leakage | AiTM campaigns often steal session material and tokens. |
| NHI-04 — Insecure Authentication | The attack abuses relayable sign-in flows and weak auth factors. | |
| NHI-07 — Long-Lived Secrets | Persisting tokens and sessions keep the campaign dangerous after takedown. | |
| Recommendation — Rotate or revoke captured secrets and sessions immediately after compromise. Replace relayable factors with phishing-resistant authentication. Shorten token lifetimes and enforce rapid revocation. | ||
| NIST SP 800-53 Rev 5 | IA-2 — Identification and Authentication (Organizational Users) | User authentication is the control point AiTM targets. |
| IA-5 — Authenticator Management | Token and session handling determines whether captured access remains usable. | |
| Recommendation — Require strong user authentication that resists relay attacks. Manage, rotate, and revoke authenticators and session material promptly. | ||
| NIST Zero Trust (SP 800-207) | Zero Trust Architecture | Trust should not persist just because a login succeeded once. |
| Recommendation — Continuously verify access and reauthorize sensitive requests. | ||
| MITRE ATT&CK | T1566 — Phishing | AiTM is a phishing technique that delivers credential capture and relay. |
| T1528 — Steal Application Access Token | The campaign stays dangerous because stolen tokens remain usable. | |
| T1111 — Multi-Factor Authentication Interception | AiTM commonly intercepts MFA in transit to obtain valid access. | |
| Recommendation — Map phishing telemetry to detect delivery, lures, and landing-page infrastructure. Hunt for token theft and session replay after phishing activity. Detect MFA relay patterns and unusual authentication handoff behavior. | ||
| NIST SP 800-63 | Digital Identity Guidelines | Phishing-resistant authenticators and authenticator assurance are central to resisting AiTM. |
| Recommendation — Adopt phishing-resistant authenticators for sensitive access paths. | ||
Practitioner Guidance
What to prioritize: Prioritize the parts of the authentication stack that survive domain takedown, especially session tokens, refresh tokens, federation trust, and account recovery. If the attacker has already captured a usable token, the immediate question is containment of that token, not shutdown of the phishing host.
What to verify: Verify whether your IdP, SSO flow, and downstream applications can revoke or invalidate sessions quickly enough to matter. Also verify whether suspicious authentication can be tied to device state, location, or reauthentication triggers so stolen material is less reusable.
Common mistake: Treating the seizure of a phishing domain as proof that the campaign is over. In practice, that only removes one staging point; it does not undo successful token capture, which is the real source of compromise.
Practitioner takeaway: AiTM resilience depends on shrinking the value of a captured session, because the attacker’s infrastructure is replaceable but the stolen authentication state is what enables continued access.
Related resources from NHI Mgmt Group
Deepen Your Knowledge
Free weekly newsletter
Subscribe to the NHI & AI Identity Journal
The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.
Bonus 33% off our NHI Course when you subscribe.
Reviewed and updated by the NHIMG editorial team on October 8, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org