Mirage2FA Hijacks Companies’ Microsoft 365 Sessions, with Over 4K Victims in the US
ID: 8e11dc88-c712-576f-b98e-7c04eefa5b93
STIX ID: report--8e11dc88-c712-576f-b98e-7c04eefa5b93
Feed Name: ANY.RUN's Cybersecurity Blog
Mirage2FA is an active phishing-as-a-service (PhaaS) toolkit that uses browser-delivered stagers and an Adversary-in-the-Middle WebSocket proxy to capture Microsoft 365 credentials, 2FA codes, and authenticated session cookies—effectively bypassing conventional MFA; the report documents observed activity from 2024–2026, ~9,332 compromise events (4,561 cookie thefts), ~4,532 impacted unique victims (63.7% in the US), detailed IOCs and loader patterns (/xls/*.js), operator markers attributed to “LinX Coders,” and recommended mitigations including phishing-resistant MFA, behavioral detections, and session revocation procedures.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
