Top 2026 2FA & AiTM Detection: Session Cookie Replay After Successful MFA (Impos
Detects the reuse of a single authenticated session or refresh token from multiple distinct IP addresses or ASN origins within a short timeframe following a successful MFA event. This pattern is indicative of session hijacking, where an adversary uses an Adversary-in-the-Middle (AiTM) toolkit (e.g., Evilginx) to capture a valid session cookie from a victim and replay it from their own infrastructure to bypass authentication.
Sigma

