VYPR
advisoryPublished Aug 4, 2026· 1 source

AI-Powered Phishing Exploits Browser Tokens, Bypassing MFA and Gateways

Attackers are leveraging Generative AI and Adversary-in-the-Middle (AiTM) kits to bypass multi-factor authentication and traditional email gateways, with users falling victim in seconds.

Phishing remains a primary initial access vector for cyberattacks, contributing to 16% of breaches and costing an average of $4.8 million. The latest wave of attacks sees threat actors employing Generative AI and sophisticated Adversary-in-the-Middle (AiTM) kits to circumvent multi-factor authentication (MFA) and bypass traditional Secure Email Gateways (SEGs). This new breed of phishing is alarmingly effective, with users clicking malicious links in a median time of just 21 seconds, rendering conventional defenses insufficient.

Traditional email security solutions often rely on domain reputation, a method that is proving increasingly ineffective against these advanced threats. Attackers exploit this by embedding links to trusted services like Google or Microsoft within their phishing emails. Email gateways, recognizing the clean domain, mark the email as safe, inadvertently overlooking the chain of compromised redirects that lie hidden behind the initial link. Once a user clicks through, they are directed to a phishing page where AiTM kits are deployed.

These AiTM kits are designed to steal live session tokens directly from the user's browser. By capturing these active tokens, attackers can effectively hijack legitimate user sessions, bypassing MFA entirely as the traffic appears to be authentic. This technique blends seamlessly with normal web browsing activity, making it exceptionally difficult for security systems to distinguish malicious traffic from legitimate user interactions.

Adding another layer of evasion, these phishing pages frequently employ anti-analysis techniques. These can include geofencing, which restricts access to specific geographic locations, or single-use tokens that invalidate the link after a single click. Such measures are specifically designed to serve the malicious payload only to the intended target while presenting a benign or error page to automated security scanners and analysis tools. This dynamic approach renders static analysis and reputation-based filtering obsolete.

In response to these evolving threats, leading Security Operations Centers (SOCs) are shifting their strategies from static artifact analysis to real-time behavioral detonation. This involves observing attack execution directly within isolated environments. Interactive sandboxes, such as ANY.RUN's offering, provide complete browser visibility, allowing analysts to witness the attack unfold live. This includes exposing hidden login forms and demonstrating session hijacking techniques that standard security tools often miss.

Interactive sandboxes are crucial for neutralizing anti-analysis tricks. By mimicking realistic human interaction within a live, isolated environment, these tools can bypass evasion tactics like geofencing, bot checks, and single-use tokens. This allows security analysts to instantly validate malicious intent by seeing exactly what the victim would experience, significantly speeding up incident response times and reducing the manual effort required for threat reconstruction.

While interactive sandboxes are vital for in-depth analysis, scaling this approach to cover every suspicious URL is impractical due to resource constraints. To address this, top SOCs are integrating global threat intelligence feeds. These feeds, like those provided by ANY.RUN, deliver actionable indicators of compromise (IOCs) derived from thousands of real-world investigations. By continuously ingesting high-fidelity IOCs such as malicious IPs, domains, and URLs, organizations can proactively block campaign infrastructure before phishing emails even reach end-users.

This combination of real-time behavioral analysis and automated threat intelligence allows SOCs to move beyond reactive defenses. It enables them to detect and stop sophisticated AI-driven phishing campaigns at scale, protecting their organizations without overwhelming their security teams. The shift is from guessing based on static data to directly observing and blocking dynamic attack behaviors.

Synthesized by Vypr AI