The prerequisite is a valid username and password the attacker already has, usually from phishing, an infostealer log, or a credential-stuffing hit. With that pair in hand, the attacker signs in repeatedly, and each attempt triggers the identity provider to push a real MFA prompt to the legitimate user's phone: a Duo Push, an Okta Verify tap-to-approve, or a Microsoft Authenticator notification. No malware runs and no MFA mechanism is broken; the attacker is simply generating the exact request the platform is designed to send.
Two things usually happen next. Either the attacker fires prompts back-to-back for minutes, betting that an annoyed or half-asleep user taps Approve just to make the buzzing stop, or the attacker slows down and adds a human layer: a WhatsApp message, an SMS, or a phone call posing as IT support, telling the target the only way to clear the notifications is to accept one. The second pattern is more deliberate and considerably harder to catch on volume alone, since the push count can be low.
Some identity platforms also expose self-service password reset (SSPR) and MFA re-enrollment flows that an attacker can abuse the same way: trigger the reset, then generate the confirmation prompt or code request until the target (or a help-desk agent acting on their behalf) completes it. Once one prompt is approved, the attacker inherits a fully authenticated session and typically moves straight into T1078 (Valid Accounts) territory: mailbox access, SSO into downstream SaaS, or VPN.