AI-Generated Phishing Shifts to Malware-Free In-Browser AiTM Session Theft — Threadlinqs Intelligence
As of 2026-08-01, AI-Generated Phishing Shifts to Malware-Free In-Browser AiTM Session Theft is a high-severity phishing threat attributed to Multiple (Phishing-as-a-Service ecosystem, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 25 indicators of compromise.
Threat ID: TL-2026-1811 · Severity: HIGH · Status: ACTIVE · Category: PHISHING
Attribution: Multiple (Phishing-as-a-Service ecosystem · FINANCIAL
Phishing campaigns are moving away from malware delivery toward adversary-in-the-middle (AiTM) techniques that operate entirely inside the victim's browser, using AI-crafted lures, multi-stage
Security researchers are documenting a decisive shift in phishing tradecraft: attackers are abandoning malware-based credential theft in favor of adversary-in-the-middle (AiTM) techniques that operate entirely inside the victim's browser, using AI-generated lures and dynamically rendered DOM content to make the interception layer indistinguishable from the legitimate service being spoofed.
The modern kill chain begins with a trusted-looking email or message -- increasingly authored or refined with generative AI, per ENISA's finding that AI-supported content represented over 80% of observed social-engineering activity in early 2025 -- that routes the victim through a multi-stage redirect chain, often bouncing through a legitimate SaaS platform before landing on the AiTM proxy. In Microsoft's documented Storm-1167 campaign, victims were routed through a legitimate Canva page before arriving at a Tencent-Cloud-hosted fake Microsoft sign-in page. Reverse-proxy toolkits such as Evilginx2, EvilProxy, Modlishka, and Muraena, and their commercialized Phishing-as-a-Service (PhaaS) descendants -- Tycoon 2FA (operated by Storm-1747, ~76% of PhaaS traffic), Sneaky2FA, Rockstar 2FA, Mamba 2FA, Greatness, Kratos, Kali365, and EvilTokens -- sit between the victim and the real identity provider (Microsoft 365/Entra ID, Google Workspace, Okta), relaying the login form in real time so the victim's password AND completed MFA challenge both transit the attacker's infrastructure. The proxy captures the resulting session cookie/token rather than the password alone, which is why the technique defeats password- and TOTP-based MFA without cryptographically breaking it -- it simply steals the already-authenticated session.
The DOM-manipulation layer that gives this trend its 'malware-free' character includes dynamically injected scripts, hidden form fields, fake CAPTCHA gates used to filter out security scanners and sandboxes, and anti-bot IP/User-Agent filtering, all executed client-side inside an encrypted HTTPS session -- which is why traditional network and endpoint tooling (no dropped executable, no anomalous process) misses it. Analysts (ANY.RUN, Cisco Talos) recommend recovering this visibility via in-browser SSL/TLS session-key extraction from process memory rather than certificate-replacing MITM interception.
Once a session cookie is captured, documented post-compromise behavior from Microsoft's Storm-1167 disclosure includes replaying the cookie from a new IP to sign in without a fresh MFA prompt, silently adding a secondary MFA method (a OneWaySMS number, observed with an Iranian country code) to preserve access after the original token expires, creating inbox rules to archive and mark security notifications as read, and using the compromised mailbox to launch large-scale follow-on phishing (16,000+ emails in the observed case) against the victim's own contacts -- converting a single AiTM compromise into a self-propagating BEC campaign.
Industry telemetry frames the scale of the shift: Microsoft's Digital Defense Report 2025 attributes 80% of MFA-bypass compromises to stolen session tokens and found token theft accounted for 31% of Microsoft 365 breaches; infostealers alone exposed an estimated 1.8 billion credentials and billions of session cookies in 2025, frequently targeting the Entra ID ESTSAUTHPERSISTENT persistent-session cookie specifically. AiTM incident volume is reported up 146% year-over-year with close to 40,000 daily incidents detected. FBI IC3 attributes $3.05 billion in annual losses to Business Email Compromise, the downstream monetization path for many AiTM compromises.
Weaknesses (CWE)
CWE-294, CWE-290
Target sectors: financial services, banking, professional services, cross-sector enterprise saas and cloud-identity users
Target regions: Global, North America, Europe
Detections & IOCs
As of 2026-08-08, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 25 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
PHISHING, HIGH, threat intelligence, cybersecurity, T1583, T1583, T1608, T1586, T1566, T1199, T1078, T1204, T1556, T1098