2026 Critical Cloud Identity Detection: Refresh Token/PRT Replay from Anomalous Device or Network (AiTM)

Detects anomalous use of an OAuth2/OIDC refresh token or Primary Refresh Token (PRT) where the originating device, IP, ASN, or country differs from the initial interactive sign-in within a short timeframe. This behavior is a strong indicator of adversary-in-the-middle (AiTM) attacks, such as Evilginx or Modlishka, where session cookies and tokens are stolen to bypass MFA.