Skip to content

This tool is not affiliated with, endorsed by or sponsored by Google LLC. Google Workspace, Gmail and Google Drive are trademarks of Google LLC. Other names are trademarks of their respective owners.

Glossary

Adversary-in-the-middle (AiTM) phishing

Phishing through a reverse proxy that relays the real sign-in page, capturing the password, the 2SV step and the resulting session.

Adversary-in-the-middle (AiTM) phishing puts a reverse proxy between the victim and the real Google sign-in page. The victim sees the genuine page, types the password and completes 2-step verification. The proxy relays everything and keeps the authenticated session for the attacker.

In the Login log, the tell is a successful sign-in, often with a passed 2SV challenge, from the proxy's server. That is usually a hosting ASN rather than the user's network. Only phishing-resistant methods (security keys, passkeys) resist it. MITRE: T1557.

See: suspicious logins and 2SV changes.

This tool is not affiliated with, endorsed by or sponsored by Google LLC. Google Workspace, Gmail and Google Drive are trademarks of Google LLC. Other names are trademarks of their respective owners.