Most work now happens inside a browser tab — email, SaaS apps, internal tools, even code repositories. Attackers have noticed. Instead of breaching networks, a growing share of intrusions start with hijacking the session already open in an employee's browser, sidestepping MFA and endpoint defenses built for a different era.
What's changing
Six techniques stand out as the backbone of this shift:
- Adversary-in-the-middle (AiTM) phishing. Modern phishing kits relay credentials and session tokens in real time, capturing the authenticated session rather than just a password — defeating traditional MFA.
- "ClickFix" — malicious copy-paste. Victims are tricked by a fake CAPTCHA or verification prompt into pasting and running a malicious command themselves. It's now one of the most common initial access vectors tracked across recent incident data, overtaking phishing attachments and drive-by downloads.
- Authorization phishing. Rather than stealing a password, attackers abuse OAuth consent screens and device-code login flows to obtain a valid, long-lived token directly from the identity provider — no credentials needed, no MFA prompt triggered.
- Malicious browser extensions. A large share of extension permission combinations in active use amount to near-total browser takeover, and the average employee now runs more extensions than most security teams can inventory, let alone monitor.
- Credential stuffing and "ghost logins." Legacy and orphaned logins that sit outside SSO remain a quiet, persistent way in — old accounts nobody remembered to retire, protected by weak or reused passwords and rarely covered by MFA.
- Session hijacking. Once a session token is stolen — via malware, a malicious extension, or a ClickFix-style lure — it can be replayed to walk straight past login, MFA, and conditional access, because the "login" already happened.
Why it matters
These techniques share a pattern: they don't try to defeat MFA, they try to make MFA irrelevant, by stealing the thing MFA is protecting — the authenticated session — after the fact. Unmanaged devices, personal browser profiles, and the sheer number of SaaS apps an average employee touches all widen the surface for this kind of attack, and traditional network and endpoint tooling has limited visibility into what happens inside the browser itself.
What to do
- Treat the browser as a managed asset. Extend visibility and policy enforcement into the browser layer, not just the endpoint and network.
- Audit and restrict extensions. Inventory what's installed org-wide, and remove anything with excessive permissions that isn't business-critical.
- Bind sessions to devices where possible. Token binding and continuous session verification blunt session-hijacking and AiTM relay attacks even after a token is stolen.
- Clean up orphaned accounts. Regularly audit and decommission logins that sit outside SSO/IdP control — these "ghost logins" are exactly the kind of soft target credential stuffing thrives on.
- Train for ClickFix-style lures specifically. Standard phishing awareness training often doesn't cover "paste this command to verify you're human" — make sure yours does.
4tify's assessments map exactly this kind of exposure — from session and identity flows to the browser extensions and shadow logins traditional scans miss — so you know where you stand before an attacker does.
