# The Attack That Looks Exactly Like a Legitimate Login — And the Fake AI That Wants Your Traffic


Two stories this week share a single uncomfortable premise: the things you've been trained to trust are exactly what's being weaponized against you.


---


## Poison Claude: When "90% Off" Is the Red Flag


Somebody, somewhere, is pitching cheap access to Anthropic's Claude AI. Ninety percent off. Same powerful model, same capabilities — just redirect your traffic through an intermediary called "Poison Claude" and start saving immediately.


The pitch writes itself. AI API costs are real and they sting. Startups burn through tokens fast. Developers hunting for cheaper inference costs are a genuine, large market. So an offer like this — technically plausible enough to fool the hopeful — lands in all the right places.


The problem is it's fraud. The service is operated by bad actors, and "redirect your traffic" is doing an enormous amount of heavy lifting in that sales pitch.


When you pipe your API calls through a third-party intermediary to access a model like Claude, you're not just saving money. You're handing every prompt, every response, and potentially every document, file, or system query you run through that pipeline directly to whoever built the proxy. If you're using AI to process customer data, legal documents, internal code, proprietary research, or anything you'd hesitate to paste into a stranger's chat window — it's now flowing through infrastructure controlled by people who opened with a lie.


The threat model here is obvious in retrospect but easy to miss when you're focused on the invoice. Credential theft, prompt injection, data exfiltration, and supply chain poisoning are all on the table. And because the responses look correct — because the model downstream might genuinely be Claude, just with a man-in-the-middle skimming everything — users may not notice until significant damage is done.


The lesson is old, but the context is new. Price-based social engineering has always worked. Now it's working on engineering teams.


---


## The Phishing Attack That Doesn't Need a Fake URL


The "Greatness" phishing-as-a-service platform has been around in various forms for a while. But their latest technique is worth isolating because it breaks some of the most common defenses organizations think are protecting them.


Here's what defenders have been telling users for years: check the URL before you enter your credentials. Look for subtle misspellings in the domain. If the login page looks weird or the address bar shows something that isn't microsoft.com, stop. Don't type your password.


Greatness makes that advice useless.


The attack doesn't use a fake website. It doesn't use a suspicious URL. The Microsoft login page the victim sees is the *actual* Microsoft login page. They're entering their credentials into the genuine authentication flow. Multi-factor authentication prompts? Real. The MFA push notification to their phone? Real. They complete the entire login sequence correctly, on real Microsoft infrastructure, and get taken to wherever they expected to go.


What they don't see is the adversary-in-the-middle proxy sitting between their browser and Microsoft's servers throughout that entire process.


This is AiTM phishing — Adversary-in-the-Middle — and it's been maturing rapidly as a technique. The mechanics: the attacker sets up a reverse proxy that transparently forwards traffic to and from Microsoft's legitimate servers. The victim authenticates for real, MFA fires for real, and Microsoft issues a session token. But the proxy captures that token before it reaches the victim's browser. The attacker now holds a valid, authenticated session cookie that grants access to everything — email, files, the full Microsoft 365 environment — without ever knowing the user's password and without triggering another MFA prompt.


The victim's account is compromised. No malware. No password stolen. No fake URL to catch in the browser bar.


What makes Greatness particularly effective as a service is that it commoditizes this sophistication. You don't need to understand reverse proxies or cookie theft to run this attack. You need a subscription and a target list. The platform handles the infrastructure. This is the industrialization of advanced phishing — turning a technique that used to require serious technical skill into a product that anyone can operate.


The delivery mechanism is typically a phishing email that directs the victim to a link — and here's the small seam of hope — that link does go somewhere. It's usually a slightly obfuscated URL or a legitimate-looking redirect. That initial link is one of the few places in the kill chain where conventional detection might fire. Once the victim clicks through, however, they're on real Microsoft infrastructure and conventional signals go quiet.


---


## Two Attacks, One Mental Model


These two stories aren't just coincidentally landing in the same news cycle. They reflect a single strategic shift that's been accelerating across the threat landscape: attackers have gotten sophisticated enough to operate *inside* the things you trust.


The fake AI service doesn't impersonate something legitimate — it redirects you to the real thing while sitting in the middle. The Greatness platform doesn't fake Microsoft's login — it makes you actually use it while intercepting the output. In both cases, the attack surface isn't a forged replica. It's the genuine article, with something malicious inserted into the flow.


This creates a specific kind of cognitive problem for defenders and users alike. The mental shortcuts that protect us — does this look right? is the URL correct? did MFA fire? — are fully satisfied. The attack passes every heuristic check by design.


---


## HackWire Analysis


The Greatness AiTM technique deserves more attention than it typically gets in broad security coverage, which tends to treat phishing as a solved problem and MFA as the answer. It isn't and it isn't.


Token theft has been on the rise since at least 2022, when Microsoft itself documented an AiTM campaign that bypassed MFA protections to compromise over 10,000 organizations. Since then, this class of attack has appeared in Lapsus$ operations, in attacks against financial services, and in commodity phishing kits sold on criminal forums. Greatness is in that same lineage — platform-ized, scalable, and demonstrably effective against organizations that consider MFA a complete answer to phishing risk.


The specific gap: FIDO2/passkeys. Hardware security keys and passkey-based authentication are resistant to AiTM attacks in a way that TOTP, SMS, and authenticator-push MFA are not, because the cryptographic proof is bound to the origin domain. A reverse proxy can't forge that binding. Organizations that have deployed phishing-resistant MFA across the board have genuinely closed this attack vector. But most haven't — the rollout is expensive, complex, and runs into user friction. So the gap stays open.


For Microsoft 365 environments specifically: Conditional Access policies with token protection enabled can detect and block sessions where the token is being replayed from an unexpected context. It's not foolproof, but it narrows the window. Monitoring for sign-ins from unexpected ASNs post-successful MFA is also worth building into detection logic.


On the Poison Claude side: organizations using AI APIs should have a sanctioned list of approved services and proxies enforced at the network layer, not just in policy documents. If an API call to an AI provider is going somewhere that isn't on the approved list, that should fire an alert. The discount AI story sounds almost funny until you realize how much sensitive data is flowing through AI pipelines right now and how little visibility most organizations have into where exactly it's going.


The threat that passes every check is the one that kills you. Both of these attacks are built on that insight.


— HackWire Editorial


---


## Related Coverage


  • Read more in our [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) coverage
  • Cross-reference with [Breaches](https://www.hackwire.news/category/breaches) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)