logo

Mirage2FA: The Phishing Service Turning a Stolen Microsoft 365 Cookie Into Full Account Takeover 

ID: 0a1ea346-44ca-56cb-ac6a-991702c39b2e

STIX ID: report--0a1ea346-44ca-56cb-ac6a-991702c39b2e

Feed Name: Cyber Press

Threat Score
78/100

Date Published: 2026-08-27

Date Updated: 2026-08-27

Author: Balaji

...
...

Mirage2FA is a phishing-as-a-service AiTM proxy sold by a group calling itself LinX Coders that captures live Microsoft session cookies (bypassing passwords and 2FA), with ANY.RUN telemetry linking the kit to 9,332 compromise events across 94 countries; the report details HTML/XHTML/SVG loaders, WebSocket C2, obfuscation methods (XOR 0xAD + Base64 + eval, obfuscator.io), infrastructure (notably 185.174.100.224 and multiple domains), IOCs, and recommended defenses including blocking HTML attachments, phishing-resistant MFA (FIDO2/WebAuthn), session revocation, and detection signatures.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.