Egidio
Report · 2026

When antivirus isn't enough anymore

Today's phishing doesn't always look like a badly spelled email with a sketchy link. Two documented techniques specifically bypass automated defenses — one gets around two-factor authentication, the other slips past spam filters.

Protect my phone with Egidio Free for calls · 100% on your phone · no account needed

🕵️Post-authentication session theft (AiTM)

Rather than stealing a password, this technique intercepts the session right after the victim validates their two-factor code — the attacker positions themselves as an invisible intermediary between the victim and the real service. The result: two-factor authentication did happen, but it accomplished nothing. In October 2025 alone, Microsoft blocked more than 13 million malicious emails linked to a single one of these kits ("Tycoon 2FA"), used against Microsoft 365 accounts worldwide.

Microsoft Defender for Office 365, October 2025

☎️Telephone-oriented attack delivery (TOAD) phishing

An email with no link or attachment: just a number to call back about a suspicious invoice or a subscription to confirm. With no URL to scan or file to analyze, classic automated filters catch nothing — the scam plays out entirely on the phone, where a fake advisor walks the victim through installing remote-access software or handing over credentials. Research firm Trustwave measured a 140% rise in these campaigns between July and September 2024, with Microsoft, Norton, PayPal and DocuSign among the most impersonated brands.

Trustwave, 2024-2025

The common thread: bypassing automation, not attention

Neither technique exploits a technical flaw in the classic sense — they exploit a structural limit of automated detection tools, by removing the very element those tools know how to analyze (a link, an attachment). What's left is a human interaction built to look legitimate: a login page identical to the real one, or a reassuring voice on the phone. That's exactly the kind of pattern a multi-channel protection needs to learn to recognize rather than scan.

🔒 A callback number in a suspicious email, or a login page asking again for a code you already entered: two signals a classic filter can miss, but that an engine connecting the channels together can cross-reference. See how Medusa works.

Frequently asked questions

Does two-factor authentication still protect against phishing?

It's still useful against simple password theft, but not against an "adversary-in-the-middle" attack: the attacker intercepts the session right after the victim validates their code, so two-factor authentication has already happened — uselessly.

What is telephone-oriented attack delivery (TOAD) phishing?

An email with no link or attachment, just a phone number to call back for a credible reason (an invoice, a subscription). Once on the phone, a fake advisor walks the victim through installing software or handing over credentials.

Why do these techniques slip past automated filters?

Because they often contain neither a suspicious link nor a malicious attachment to scan — the scam plays out in human interaction, on the phone or on a page that perfectly mimics the real one.

Other markets we cover

These techniques don't respect borders — national cyber agencies and researchers document the same AiTM and callback mechanisms hitting other markets, with their own numbers.

🇦🇺Australia — attackers pivot beyond AiTM to dodge defenses

ASD publicly warned Microsoft 365 users in May 2026 about "device code phishing" — a technique researchers say the operators behind the AiTM kit Tycoon 2FA began selling after a February 2026 disruption to their infrastructure. ASD said it had received multiple reports of Australian users being actively targeted.

Australian Signals Directorate, public advisory, May 2026; Proofpoint research.

🇬🇧United Kingdom — one kit's reach grew from 184 to 290 targets in three weeks

UK researchers tracked an AiTM phishing kit first detected on 27 February 2025, hitting mostly construction, manufacturing, engineering and energy firms in the UK. It used lookalike pages mimicking Adobe and Gamma App, with tracked instances growing from 184 to 290 in under a month.

JUMPSEC, "UK Industrial Sector AiTM Phishing Campaign," March 2025.

🇨🇦Canada — 100+ AiTM campaigns against one sign-in system alone

Canada's national cyber centre detected more than 100 distinct AiTM campaigns targeting Canadian organizations' Microsoft Entra sign-in systems between 2023 and early 2025. Separately, Microsoft documented "Storm-2755," a campaign that hijacks Microsoft 365 sessions specifically to redirect Canadian employees' salary deposits.

Canadian Centre for Cyber Security, ITSM.30.031, 2025; Microsoft Threat Intelligence.

🇮🇳India — credential theft overtakes hacking as the way in

The Digital Threat Report 2025–26, a joint effort of India's CERT-In, the financial-sector CSIRT-Fin and forensics firm SISA, found that credential theft and session hijacking — the mechanism behind AiTM phishing — have become the primary way attackers gain initial access to the country's financial systems, alongside an intensified wave of Business Email Compromise.

CERT-In, CSIRT-Fin & SISA, Digital Threat Report 2025–26, July 2026.

Go further

Cite this page Egidio — The Threat Laboratory, "Emerging phishing techniques: when antivirus isn't enough anymore", egidio.app/en/laboratoire/emerging-phishing-techniques/. Licensed CC BY 4.0.

Free to reuse, including commercially, with attribution. Reuse terms.