AiTM phishing
2 posts
Article
TOTP fixes the channel, not the credential
TOTP kills SMS interception and SIM-swap OTP theft, but AiTM phishing still steals the session token. What TOTP secures and what it doesn't.
Article
MFA protects the login, not the session.
Fastpotify mints unbound session cookies that survive MFA. Stolen via AiTM or infostealer, they replay as full sessions. The telemetry that catches it.