Mirage2FA: The Phishing Service Turning a Stolen Microsoft 365 Cookie Into Full Account Takeover
ID: 0a1ea346-44ca-56cb-ac6a-991702c39b2e
STIX ID: report--0a1ea346-44ca-56cb-ac6a-991702c39b2e
Feed Name: Cyber Press
Mirage2FA is a phishing-as-a-service AiTM proxy sold by a group calling itself LinX Coders that captures live Microsoft session cookies (bypassing passwords and 2FA), with ANY.RUN telemetry linking the kit to 9,332 compromise events across 94 countries; the report details HTML/XHTML/SVG loaders, WebSocket C2, obfuscation methods (XOR 0xAD + Base64 + eval, obfuscator.io), infrastructure (notably 185.174.100.224 and multiple domains), IOCs, and recommended defenses including blocking HTML attachments, phishing-resistant MFA (FIDO2/WebAuthn), session revocation, and detection signatures.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
