Mirage2FA Surge Hits 4,500 US and EU Companies, Abusing Microsoft 365 Login Flows
ID: d2e3da0f-8df8-59e6-b9ee-94db31b18e04
STIX ID: report--d2e3da0f-8df8-59e6-b9ee-94db31b18e04
Feed Name: The Hacker News
Mirage2FA is a commercial phishing-as-a-service campaign (2024–2026) that targets Microsoft 365 accounts by abusing legitimate login flows and stealing passwords and session cookies to bypass MFA (AiTM). ANY.RUN’s research attributes thousands of affected organizations—notably ~4,532 unique organization domains and >9,000 potential compromise events—with a majority in the US; the campaign enables session hijacking, SSO abuse, and broad follow-on access. The report recommends phishing-resistant authentication, session controls, behavioral detections, sandboxing, and treating session theft as an identity incident to reduce impact.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
