# Adversary-in-the-middle (AiTM)

A cybersecurity technique in which an adversary positions itself between networked devices to intercept or manipulate traffic and support credential access or other follow-on actions.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## Behind the console: An AiTM phishing kit harvesting AWS console credentials and beyond

DevFeed: [Behind the console: An AiTM phishing kit harvesting AWS console credentials and beyond](<https://devfeed.tech/articles/behind-the-console-an-aitm-phishing-kit-harvesting-aws-console-credentials-and-beyond-8279.md>)

Original publisher: [Read original article](<https://securitylabs.datadoghq.com/articles/behind-the-console-aws-aitm-phishing-kit-and-beyond/>)

Author: Datadog

Published: 2026-06-24T00:00:00Z

Content type: article

Language: en

Sources: [Datadog Security Labs](<https://devfeed.tech/sources/datadog-security-labs.md>)

Topics: [Adversary-in-the-middle (AiTM)](<https://devfeed.tech/topics/adversary-in-the-middle-aitm.md>), [Amazon Web Services](<https://devfeed.tech/topics/aws.md>), [Security](<https://devfeed.tech/topics/security.md>), [MFA](<https://devfeed.tech/topics/mfa.md>), [Cloudflare](<https://devfeed.tech/topics/cloudflare.md>), [JavaScript](<https://devfeed.tech/topics/javascript.md>), [VirusTotal](<https://devfeed.tech/topics/virustotal.md>), [Batch file](<https://devfeed.tech/topics/batch-file.md>), [cURL](<https://devfeed.tech/topics/curl.md>), [Amazon Route 53](<https://devfeed.tech/topics/amazon-route-53.md>)

Tags: [adversary-in-the-middle-aitm](<https://devfeed.tech/tags/adversary-in-the-middle-aitm.md>), [aws](<https://devfeed.tech/tags/aws.md>), [batch](<https://devfeed.tech/tags/batch.md>), [cloudflare](<https://devfeed.tech/tags/cloudflare.md>), [dns](<https://devfeed.tech/tags/dns.md>), [javascript](<https://devfeed.tech/tags/javascript.md>), [mfa](<https://devfeed.tech/tags/mfa.md>), [security](<https://devfeed.tech/tags/security.md>), [virustotal](<https://devfeed.tech/tags/virustotal.md>)

### AI overview

Datadog Security Research analyzes a June 2026 campaign using cloned AWS console login pages and adversary-in-the-middle techniques to harvest credentials and MFA codes. The article details the phishing infrastructure, delivery methods, VirusTotal artifact, and JavaScript-based credential-harvesting flow.

### Source excerpt

Datadog Security Research investigates a June 2026 adversary-in-the-middle phishing campaign that cloned the AWS console login page to harvest victim credentials and multi-factor authentication codes.