logo

Mirage2FA Hijacks Companies’ Microsoft 365 Sessions, with Over 4K Victims in the US

ID: 8e11dc88-c712-576f-b98e-7c04eefa5b93

STIX ID: report--8e11dc88-c712-576f-b98e-7c04eefa5b93

Feed Name: ANY.RUN's Cybersecurity Blog

Threat Score
78/100

Date Published: 2026-08-18

Date Updated: 2026-08-18

Author: ShiFu and raptur3

...
...

Mirage2FA is an active phishing-as-a-service (PhaaS) toolkit that uses browser-delivered stagers and an Adversary-in-the-Middle WebSocket proxy to capture Microsoft 365 credentials, 2FA codes, and authenticated session cookies—effectively bypassing conventional MFA; the report documents observed activity from 2024–2026, ~9,332 compromise events (4,561 cookie thefts), ~4,532 impacted unique victims (63.7% in the US), detailed IOCs and loader patterns (/xls/*.js), operator markers attributed to “LinX Coders,” and recommended mitigations including phishing-resistant MFA, behavioral detections, and session revocation procedures.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.