IronToll: Rapid cross-location OTP/MFA validation indicating live SIM/session hijack

Detects rapid, successive successful interactive sign-ins for the same user account that each satisfy MFA requirements, but originate from geographically and technically distinct environments (different IP locations, ASNs, and device IDs) within a 2-minute window. This behavior is indicative of session hijacking via Adversary-in-the-Middle (AiTM) or Phishing-as-a-Service (PhaaS) frameworks.