logo

Mirage2FA phishing kit uses HTML smuggling to steal Microsoft 365 credentials

ID: 96407baa-2420-53a1-947f-89290fdcd225

STIX ID: report--96407baa-2420-53a1-947f-89290fdcd225

Feed Name: Help Net Security

Threat Score
65/100

Date Published: 2026-06-26

Date Updated: 2026-06-26

Author: Sinisa Markovic

...
...

Fortra researchers analyzed a Mirage2FA phishing campaign that uses short-lived HTML smuggling and obfuscated JavaScript loaders to deliver staged fake Microsoft 365 login pages (including MFA prompts) to harvest credentials and potentially bypass MFA; observed indicators include cheacker.store and user.cheacker.store along with associated IPs and JavaScript resources, and recommended remediation steps include password resets, session/token revocation, MFA review, mailbox rule inspection, and OAuth grant checks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.