Join our Newsletter — 33% off our NHI Course
Home› Glossary› Threats, Abuse & Incident Response› Attacker In The Middle
Threats, Abuse & Incident Response

Attacker In The Middle

← Back to Glossary
By NHI Mgmt Group Updated September 29, 2026 Domain: Threats, Abuse & Incident Response

Attacker in the middle is a phishing technique where the criminal positions themselves between the user and the real service during login. Instead of stealing a password alone, the attacker relays traffic and captures session material, making the compromise harder to detect and more useful for follow-on access.

How attacker-in-the-middle phishing works

Attacker-in-the-middle phishing is not just credential theft, it is a live interception pattern. The attacker sits between the user and the legitimate service, forwards the login flow, and can capture session material that is more useful than a password alone.

The technique succeeds because the user still appears to be signing into the real service. That makes the deception harder to notice, especially when the attacker relays pages, tokens, or MFA prompts in real time rather than harvesting a static password.

Why it is dangerous

The main security issue is session capture. Once the attacker has a valid session, they may bypass the need to know the original password and continue access after the initial phishing event has ended.

This also changes the defender’s problem: detection must look for anomalous session use, unusual relay behavior, and post-login activity that does not match the normal user pattern. The compromise can be subtle because the login itself may succeed normally from the user’s perspective.

Common attack path and abuse pattern

Attacker-in-the-middle phishing often begins with a convincing lure that drives the victim to a fake but interactive login page. The page proxies the real authentication flow so the attacker can observe or relay the session as it is created.

In practice, the attacker is not only trying to capture a secret, but to preserve the authenticated state long enough to use it for mailbox access, SaaS access, or other downstream actions. That is why it is often associated with follow-on compromise rather than a one-time credential theft.

For identity-led intrusion paths, The 52 NHI Breaches Report is a useful compendium of real compromise patterns involving stolen credentials, secrets, and lateral movement.

Defensive controls and detection signals

Phishing-resistant authentication, sender and domain verification, and step-up controls reduce the chances that a relayed login can be reused. Strong session binding and anomaly detection matter because the attacker’s value comes from turning a successful login into durable access.

Monitoring should focus on unusual sign-in geography, device changes, impossible travel, token replay indicators, and unexpected downstream actions immediately after authentication. A relay attack may leave very little noise at the password stage, so the session and post-authentication layers are where defenders often get their first clues.

For broader threat context, CISA cyber threat advisories remain a strong reference point for current attack tradecraft, and NIST SP 800-63 Digital Identity Guidelines provide the identity assurance concepts that underlie phishing-resistant authentication.

Risk and Threat Considerations

Attacker-in-the-middle phishing is dangerous because it can defeat password-only thinking and turn a single login into a live, reusable session. The risk is not limited to account access, it extends to whatever the authenticated session can reach after compromise.

Failure mechanism: The attacker intercepts the authentication flow, captures the active session artifact, and reuses it before the victim or defender notices the session is compromised.

Impact: The attacker can bypass the original password, persist inside the account, and use the trusted session for data theft, internal access, or further impersonation.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK addresses the attack and risk surface, while NIST SP 800-63 and CIS Controls v8 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST SP 800-63Digital Identity GuidelinesDefines phishing-resistant authentication and identity assurance for login flows.
Recommendation — Use phishing-resistant authenticators and validate session handling against relay attacks.
MITRE ATT&CKT1557 — Adversary-in-the-MiddleDirectly describes the adversary technique used to intercept and relay authentication traffic.
Recommendation — Map detections to adversary-in-the-middle behavior and hunt for relay-based session capture.
CIS Controls v8CIS-6 — Access Control ManagementCovers managing and limiting access paths that session theft can abuse.
Recommendation — Revoke and review access paths that could be reused after session compromise.

Practitioner Guidance

Why practitioners should care: Treat this as a session security problem, not only a password problem. If your controls only stop credential guessing, they may still allow a relayed login to succeed.

What to watch for: Focus on phishing-resistant authentication, session telemetry, and post-login anomalies that indicate the user and the active session are no longer behaving as one. A successful login is not proof of trust if the session was brokered by an attacker.

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on September 29, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org