Cybersecurity teams have spent years getting better at spotting phishing emails before somebody clicks. Cybercriminals, on the other hand, have spent those same years getting better at making the click matter less.
Today’s proxy phishing, also called an adversary-in-the-middle (AiTM) attack, can put the attacker between the user and a legitimate authentication service. Here’s how it goes: the employee enters the password, MFA works, the user successfully authenticates, and the attacker walks away with the authenticated session.
Microsoft reports that Tycoon2FA alone grew into one of the most widespread phishing-as-a-service (PhaaS) platforms, enabling campaigns reaching more than 500,000 organizations each month before its infrastructure was disrupted. That is a lot!
But the more interesting question may be: What are the criminals doing after they get inside?
Hey, Rocky the Raptor here, RPost’s cybersecurity product evangelist. Recently, I’ve been looking less at the phishing hook and more at what the cybercriminal does with the account once they have control of the account.
The smartest cybercriminals aren’t immediately sending a fake invoice; they’re waiting, reading, and watching. They search old email threads, identify executives, learn which counsel works on which matter, which employee handles payroll, which customer normally pays which supplier, who approves a wire transfer, who sends contracts, which documents matter, and when everyone normally communicates.
In other words, the compromised email account becomes a reconnaissance post. This changes how defenders should think about email account compromise now, as the objective isn't always simply to steal an account. Sometimes the account is where the criminal goes to learn the target.
Proxy-phishing technology is no longer reserved for highly sophisticated attackers building their own infrastructure. There is a complete ecosystem. Phishing-as-a-service platforms package reverse proxies, authentication interception, templates, domain infrastructure, campaign management, victim tracking, and other components into something that resembles a cybercriminal SaaS application.
And there can be a compounding effect. One successful proxy phish can create one compromised account, while that trusted account can help create ten more. Those ten become new places to observe conversations, relationships, transactions, documents, suppliers, customers, and financial workflows. Suddenly this begins looking less like isolated phishing and more like a distributed reconnaissance network.
This is where cyber counterintelligence enters the story. Among thousands or millions of seemingly unrelated content interactions, one unusual IP address or one unexpected browser language means very little. A VPN endpoint in Moscow does not make someone Russian, and an AWS instance in Virginia does not make someone American. A geography mismatch might be an employee traveling, a strange access time might be somebody working late, and a cloud-hosted IP might simply be a security scanner.
But what if combinations of protocol-level signals begin repeating? For example, similar browser artifacts, network behavior, language sequencing, access patterns, infrastructure characteristics, or similar behavior against unrelated recipients, companies, matters, or documents.
Now the question changes. It is no longer: “Is this particular access suspicious?” It becomes: “Have we seen this watcher before?”
RPost’s RAPTOR™ AI is designed to analyze forensic breadcrumbs produced when protected email, documents, file shares, and other content are accessed beyond the sender’s traditional endpoints, then connect suspicious observations across related interactions. We call it creating intelligence from the adversary’s interaction with protected content rather than relying only on previously known indicators.
And this raises a bigger counterintelligence question: what if these aren't isolated compromised accounts? When the same behavioral fingerprints begin appearing across unrelated organizations, recipients, and infrastructure, they may point to shared tooling, operators, or cybercriminal service ecosystems conducting reconnaissance at scale. What initially looks like many separate account compromises may instead be pieces of a larger operation.
That is also why attribution cannot simply be based on geography. When recurring fingerprints intersect with Russian-linked, West African, rented, proxy-routed, or otherwise geo-masked infrastructure, the more important question is whether the same behavioral and infrastructure patterns keep appearing elsewhere.
An IP address tells you where an interaction appears to originate. A recurring fingerprint may tell you who—or what—you have seen before.
Most enterprise cybersecurity has one understandable obsession: protecting the enterprise. Security teams watch what enters the network, what executes on the endpoint, who authenticates, which identities are active, and which applications are being used.
All of that is essential. But businesses do not operate entirely inside their own security perimeter. Sensitive information travels to law firms, brokers, customers, suppliers, contractors, and thousands of other third parties.
If the adversary is sitting inside someone else’s trusted account, your endpoint security may never see them. Cyber counterintelligence creates another opportunity to spot the watcher and connect their behavior to suspicious activity elsewhere. No hacking back. Just denying cybercriminals the context early enough that you may preempt the attack it was going to build.
August 07, 2026
July 24, 2026
July 17, 2026
July 10, 2026
July 03, 2026