what do you think about this idea ? Dns spoofing + Rouge AP to achieve a perfect timed splash/captive portal mimc page that pops up instantly whenever a user tries to open an app , then it phishes them for the creds + 2FA if required getting them convinced that the pop is/from the real app.