After Bots — a new book by our founder on classifying AI agents. Now available

Get Your Free Copy
← Back to resources
Brief

MFA Compromise

Discover how Arkose Phishing Protection effectively thwarts reverse proxy assaults in real time.

OTP Code Theft: A Weakness in MFA Defense

Adversary-in-the-middle (AITM) reverse-proxy phishing attacks cost more than $2 billion each year globally, plus untold losses in diminished consumer trust. An AITM reverse-proxy phishing attack, also known as MFA compromise, involves software that acts as an intermediary between the user and the target site. Even multi-factor authentication (MFA) can't stop these attacks because bad actors bypass MFA safeguards.

In this type of attack, a user clicks on a malicious URL and is directed to a phishing site that functions as a reverse proxy, capturing traffic to the legitimate target site. When the user enters their credentials, including MFA/2FA tokens, the reverse proxy captures and harvests these tokens for malicious use. The software accesses the target site programmatically, rewrites the traffic and enters the stolen data without human involvement — completing the transaction on the target site and effectively bypassing MFA protections.

Safeguard your consumer experience and revenue-generating activities with an advanced threat detection system. Arkose Phishing Protection, a component of the Arkose Titan platform, effectively thwarts advanced phishing attacks: it detects attacks as they happen, deters credential theft, stops MFA/2FA code interception, prevents stolen authentication tokens from being used and warns users with customized alerts.

Why Arkose Phishing Protection

Stop Attacks Before Credentials Are Compromised

Block phishing attempts at authentication with token validation that attackers cannot replicate — preventing account takeover before damage occurs.

Stronger Detection Than Traditional Tools

Traditional phishing detection missed 96% of sophisticated attacks in our analysis. Arkose Phishing Protection catches what others miss through real-time domain intelligence and behavioral signatures.

Unified Platform, Not Point Solution

The solution is integrated with Arkose Titan to correlate phishing indicators with device fingerprinting, AI agent detection and fraud patterns across your entire user journey.

No Additional Burden on Security Teams

Our 24/7/365 SOC monitors emerging phishing techniques and tunes detection rules — extending your capabilities without adding headcount.

Real-Time Attack Detection Across the Full Session

Client- and server-side signatures, managed phishing detection rulesets, hostname allow and deny lists, and configurable end-user warning messages work together, with support for both active interception and monitor-only modes plus in-depth visibility and detailed reporting.

Platform Capabilities

Arkose Bot Manager icon
Arkose Bot Manager
Advanced bot detection and mitigation
Arkose Email Intelligence icon
Arkose Email Intelligence
Real-time email authenticity validation
Arkose Device ID icon
Arkose Device ID
AI-enhanced device identification
Arkose Scraping Protection icon
Arkose Scraping Protection
Comprehensive defense against unauthorized scraping
Arkose Edge icon
Arkose Edge
Lightweight server-side API security
Arkose Labs

The Arkose Labs Advantage

225+ risk signals and assessments shared
Intelligence to enrich and tune your decisioning.
Financial warranties
Best efforts aren't good enough. We back our platform with million-dollar warranties and SLAs.
Arkose Global Intelligence Network
Benefit from global risk signals and mitigation intel shared across our customer network.
Trusted by the most recognizable brands
Built for enterprises, our technology, support, certifications and architecture meet your scalability requirements.
Global, proactive support
24/7/365 real-time SOC support with proactive incident response vs "on call."
Harnessing AI to stop evolving threat vectors
We're leveraging AI to defend against AI-driven bots.

ACTIR and the Arkose Labs SOC

Arkose Labs operates as an extension of your team, rapidly countering attacks and providing actionable insights without overburdening your internal resources. The Arkose Cyber Threat Intelligence Research (ACTIR) unit conducts proactive threat hunting, risk intelligence gathering and other counterintelligence methods to provide vital, fresh intelligence. Meanwhile, the 24/7/365 Security Operations Center (SOC) team focuses on identifying and stopping large-scale attacks immediately.

Arkose Phishing Protection Takes On EvilProxy

EvilProxy is a sophisticated and widely used phishing-as-a-service kit that allows attackers to bypass MFA. Traditional phishing detection tools miss a majority of EvilProxy attacks, but Arkose Labs snares them. The proof: an analysis of requests on three login endpoints found that of 250 suspicious domains, 96% would have slipped past a traditional phishing detection method.

  • Traditional detection method: 10 of 250 total suspicious domains detected
  • 49 domains less than 60 days old, indicating they were likely created for the attack
  • 191 short-lived URLs, indicating they served their attack purpose and soon disappeared

Take Action Now

Ready to shut down MFA bypass attacks? To see how Arkose Labs can protect your company from reverse-proxy phishing, schedule a call with an expert today.