Module 2 · Phishing — AiTM, MFA Bypass, and the 2026 Defender Stack

Manish Garg
Manish Garg Associate of (ISC)² · RingSafe
May 14, 2026
4 min read
Read as
100% Free

No signup. No paywall. No catch. One of our 10 most-requested practitioner modules — published in full so anyone can learn for free. We earn through consulting, not by gating knowledge.

See all 10 free modules →

Why this module exists. Phishing remains the entry point for the majority of Indian enterprise breaches. This module covers the attacker’s modern playbook (AiTM proxies, reverse-proxy phishing kits, MFA bypass via session-cookie theft) and the defender’s stack: DMARC, anti-phishing platforms, FIDO2, and behavioural training that actually works.

Why this module exists. Email-borne phishing is no longer “click this link, enter password.” Modern kits proxy the entire login flow, capture session cookies post-MFA, and let the attacker step into the authenticated session. The defender’s playbook has evolved correspondingly. This module is the current state.

The 2026 attacker playbook

The modern phishing kit is not a static credential-harvest form. It is an Adversary-in-the-Middle (AiTM) reverse proxy:

  1. Victim clicks the phishing link.
  2. The phishing kit fetches the real login page from Microsoft, Google, or the target SaaS.
  3. Victim sees the real page rendered through the kit’s proxy.
  4. Victim enters credentials. Kit forwards to the real provider, captures the credential.
  5. Provider sends MFA challenge. Victim completes it through the kit.
  6. Provider returns a session cookie. Kit captures the cookie and forwards a success page to the victim.
  7. Attacker now has a valid session cookie. MFA is bypassed without ever breaking it.

EvilGinx, Modlishka, and Muraena are the open-source toolkits. Commercial phishing-kits-as-a-service sell pre-configured AiTM templates for $50-200/month per target brand.

Want this for your team?

Custom team training + practitioner advisory

Beyond the free academy — we run private workshops, vCISO advisory, and red-team exercises tailored to your stack. For Indian SMBs scaling past their first hire.

Book team training call Replies in 4 working hrs · India-only · Senior consultants