Mirage2FA phishing kit hits 4,500 Microsoft 365 orgs

A commercial phishing-as-a-service platform known as Mirage2FA has enabled attackers to hijack Microsoft 365 sessions at more than 4,500 organizations across the United States and Europe, bypassing multi-factor authentication by abusing legitimate login flows.[2][4][9][12][15] Researchers say the campaign has been active since late 2024 and remains ongoing in mid-2026, with a majority of victims located in the US but a growing footprint among European tenants.[2][7][9][12]

Mirage2FA is built around an adversary-in-the-middle architecture that proxies the entire Microsoft 365 or Entra ID authentication sequence, capturing not only usernames and passwords but also one-time 2FA codes and the authenticated session cookies issued after successful login.[1][4][7][15] Instead of exploiting a software vulnerability, the kit positions itself transparently between user and cloud service, relaying traffic to Microsoft in real time while siphoning off the tokens that grant persistent access to email and other workloads.[3][6][9][15]

Telemetry shared by researchers indicates the operation has targeted at least 9,426 Microsoft 365 accounts across 3,518 corporate domains, with roughly 63.7% of affected organizations based in the United States and the rest spanning European and other regions.[9][12][15] ANY.RUN’s analysis suggests that nearly half of the targeted email addresses—about 48%—show signs of potential compromise, underscoring how often Mirage2FA’s lures translate into real account takeovers.[4][9][12] Victims cluster in technology, manufacturing, education, finance, healthcare and telecommunications, reflecting attackers’ focus on data-rich, cloud-dependent sectors.[9][12][15]

Attack chains typically begin with phishing emails that deliver obfuscated HTML, XHTML or SVG attachments masquerading as HR notices, invoices or other business documents, a technique often described as HTML smuggling.[1][4][6][10][13] When opened in a browser, these short-lived loaders assemble and execute JavaScript that reaches out to attacker infrastructure, presents a pixel-perfect Microsoft 365 login page behind a CAPTCHA gate and establishes WebSocket channels to relay credentials and tokens in real time.[1][4][10][14] Analysts note that Mirage2FA is sold as a multi-tenant service, with a core operator group—tracked as LinX Coders—providing the platform and affiliates running their own phishing campaigns on top of it.[3][5][7][8][9]

Because Mirage2FA steals authenticated session cookies, attackers can continue accessing mailboxes and other resources even after a victim changes their password, and they can repeatedly re-use the hijacked sessions until they expire or are revoked.[3][4][7][9] Compromised accounts have reportedly been used to read and exfiltrate sensitive correspondence, set up forwarding rules, and launch follow-on business email compromise schemes against partners and customers.[4][6][9][12] The identity-layer nature of the attack means traditional endpoint antivirus tools may see no malware at all, while the threat actor operates entirely from the cloud side of the victim’s environment.[3][6][7][9]

Defenders are being urged to tighten controls around HTML and SVG attachments, scrutinize Microsoft 365 sign-in logs for signs of adversary-in-the-middle activity such as impossible travel or unusual user agent and IP combinations, and aggressively revoke active sessions after suspected phishing incidents.[4][6][9][15] Security teams are also encouraged to accelerate adoption of phishing-resistant authentication methods such as FIDO2/WebAuthn security keys and smart cards, enforce conditional access policies that bind tokens to specific devices, and educate users to be wary of login prompts launched from unexpected attachments or links, even when they appear to come from trusted brands.[4][7][9][15]

References

  1. Mirage2FA: Obfuscated HTML Loader Delivers Microsoft 365 MFA …
  2. Mirage2FA : un PhaaS AiTM cible Microsoft 365 avec plus de 4 500 victimes
  3. Mirage2FA AitM Phishing-as-a-Service: Microsoft 365 …
  4. Mirage2FA: A Phishing Threat to US Companies with 4K Victims
  5. ‘Mirage2FA’ (LinXcoded) Phishing-as-a-Service Platform …
  6. Hackers Let Microsoft 365 Users Complete MFA, Then Steal Logged-In Sessions
  7. Mirage2FA Phishing-as-a-Service Bypasses MFA and …
  8. Mirage2FA AiTM PhaaS + CopyCop/Storm-1516 Influence …
  9. PhantomStealer Injector + Mirage2FA AitM PhaaS: OTX Pulse Analysis — Credential Theft Detection Pack
  10. Help Net Security: Mirage2FA phishing kit uses HTML …
  11. Entra ID RCE, Claude Code Ransomware, T-Mobile Cable, …
  12. Mirage2FA phishing kit steals Microsoft 365 credentials – LinkedIn
  13. Inside Mirage2FA — Reverse-Engineering – f4n6
  14. Tag: session-theft · cyfar.ca

Comments

No comments yet. Why don’t you start the discussion?

Leave a Reply