Glossary
Adversary-in-the-middle (AiTM) phishing
Phishing through a reverse proxy that relays the real sign-in page, capturing the password, the 2SV step and the resulting session.
Adversary-in-the-middle (AiTM) phishing puts a reverse proxy between the victim and the real Google sign-in page. The victim sees the genuine page, types the password and completes 2-step verification. The proxy relays everything and keeps the authenticated session for the attacker.
In the Login log, the tell is a successful sign-in, often with a passed 2SV challenge, from the proxy's server. That is usually a hosting ASN rather than the user's network. Only phishing-resistant methods (security keys, passkeys) resist it. MITRE: T1557.