The wall, and the crack in it
The kits that matter now are adversary-in-the-middle proxies. Rather than serve a fake login page, they relay the victim’s traffic to the real Microsoft sign-in service in real time, hand the real responses back and harvest the credentials and the session token as they pass through. The victim sees a genuine page, completes a genuine multi-factor prompt, and the attacker walks away with a live session. Microsoft documented a single campaign of this shape that reached more than 10,000 organizations, and the model has only become more commoditized since.
Put one behind a content delivery network and the server disappears. That is what I ran into last month. Certificate transparency showed me the network’s certificate, not the origin’s. Passive DNS showed the domain had never resolved anywhere else. The internet-wide scanning platforms came back empty, which I initially read as absence and later understood as refusal: the origin dropped any connection that did not present the exact hostname it expected, in under half a second, without serving a byte.
That distinction is worth a moment, because it is a mistake I have watched capable analysts make. A null result from a scanning platform against a hostname-gated server does not mean nothing is there. It means you knocked in the wrong language. Treating those two things as the same is how a hunt ends prematurely with everyone satisfied.


