AI Security AI安全 3h ago Updated 2h ago 更新于 2小时前 41

Mirage2FA Surge Hits 4,500 US and EU Companies, Abusing Microsoft 365 Login Flows Mirage2FA攻击激增,波及4500家美欧企业,滥用微软365登录流程

The Mirage2FA phishing-as-a-service campaign (2024–2026) has targeted 4,532 unique organization email domains across the US and EU, with 48% of targeted email addresses potentially compromised. Attackers exploit AI-typical (AiTM) phishing techniques to steal passwords and session cookies from Microsoft 365 login flows, effectively bypassing two-factor authentication. Over 9,000 potential compromise events were identified, involving cookie theft, SSO logins, and 2FA bypass, with technology, manuf Mirage2FA是2024至2026年间针对Microsoft 365的钓鱼即服务(Phishing-as-a-Service)攻击活动,已影响4,532家美国及欧盟企业 攻击者通过AiTM(Adversary-in-the-Middle)技术窃取密码和会话Cookie,成功绕过传统双因素认证(2FA) 48%的目标邮箱地址可能已被泄露,美国占受害者总数的63.7%,科技、制造和教育行业是主要目标 攻击者通过劫持已认证的Microsoft 365会话和SSO连接服务,实现身份冒用、欺诈及横向渗透 传统MFA已无法有效防御此类攻击,企业需转向抗钓鱼认证、强化会话管理并集成威胁情报

58
Hot 热度
62
Quality 质量
55
Impact 影响力

Analysis 深度分析

TL;DR

  • The Mirage2FA phishing-as-a-service campaign (2024–2026) has targeted 4,532 unique organization email domains across the US and EU, with 48% of targeted email addresses potentially compromised.
  • Attackers exploit AI-typical (AiTM) phishing techniques to steal passwords and session cookies from Microsoft 365 login flows, effectively bypassing two-factor authentication.
  • Over 9,000 potential compromise events were identified, involving cookie theft, SSO logins, and 2FA bypass, with technology, manufacturing, and education as the most targeted industries.
  • Session hijacking extends the attack radius beyond initial account takeover to SSO-connected services and internal workflows, significantly increasing containment costs.
  • Mitigation requires phishing-resistant authentication, behavioral detection via sandboxing, treating session theft as an identity incident, and integrating real-time threat intelligence feeds.

Why It Matters

This campaign demonstrates that traditional MFA is no longer sufficient defense against sophisticated phishing operations, as session cookie theft and AiTM proxies can bypass 2FA entirely. For AI and security practitioners, it underscores the critical need to shift from credential-centric to identity- and session-centric security models, especially as Microsoft 365 remains the dominant corporate email and collaboration platform.

Technical Details

  • Mirage2FA operates as a commercial phishing-as-a-service toolkit that deploys AiTM (AI-typical / pass-through) phishing pages mimicking legitimate Microsoft 365 login flows, capturing both credentials and active session cookies in real time.
  • The campaign leverages WebSocket activity, encoded payloads, and recurring malware loaders to maintain persistent access and evade traditional signature-based detection.
  • Compromised sessions grant attackers authenticated access to Microsoft 365 and all SSO-connected enterprise services, enabling lateral movement, impersonation, and data exfiltration without needing to crack passwords or bypass 2FA prompts.
  • ANY.RUN's Interactive Sandbox was used to analyze suspicious attachments and URLs, exposing fake login pages, redirect chains, and script behavior that would otherwise blend into legitimate traffic.
  • Threat Intelligence Feeds from 16,000+ organizations were integrated to pivot from individual IOCs to broader campaign infrastructure, revealing connections across recurring loaders and malicious domains.

Industry Insight

  • Organizations must prioritize phishing-resistant authentication methods (e.g., FIDO2/WebAuthn, certificate-based auth) over traditional SMS or TOTP-based MFA, as session theft renders conventional 2FA ineffective against AiTM attacks.
  • Security operations should treat session theft as a full identity incident—revoking tokens and sessions immediately rather than relying solely on password resets—and invest in behavioral detection and sandboxing to catch phishing infrastructure before compromise occurs.
  • The commercialization of phishing toolkits like Mirage2FA signals a broader trend of attack democratization; as detection improves, threat actors will likely shift toward more advanced session manipulation and AI-generated phishing content, making continuous threat intelligence integration essential.

TL;DR

  • Mirage2FA是2024至2026年间针对Microsoft 365的钓鱼即服务(Phishing-as-a-Service)攻击活动,已影响4,532家美国及欧盟企业
  • 攻击者通过AiTM(Adversary-in-the-Middle)技术窃取密码和会话Cookie,成功绕过传统双因素认证(2FA)
  • 48%的目标邮箱地址可能已被泄露,美国占受害者总数的63.7%,科技、制造和教育行业是主要目标
  • 攻击者通过劫持已认证的Microsoft 365会话和SSO连接服务,实现身份冒用、欺诈及横向渗透
  • 传统MFA已无法有效防御此类攻击,企业需转向抗钓鱼认证、强化会话管理并集成威胁情报

为什么值得看

本文揭示了当前企业身份安全领域最紧迫的威胁之一:即使部署了双因素认证,攻击者仍能通过会话劫持绕过防护。对于AI从业者及企业安全团队而言,理解Mirage2FA的攻击机制有助于重新评估身份认证架构,推动从"密码+验证码"向抗钓鱼认证演进。

技术解析

  • 攻击技术:Mirage2FA采用AiTM(Adversary-in-the-Middle)中间人攻击模式,通过伪造Microsoft 365登录页面拦截用户凭据,同时窃取会话Cookie实现2FA绕过。攻击者无需破解MFA令牌,而是直接劫持已认证的会话。
  • 影响规模:ANY.RUN研究覆盖4,532个独立组织邮箱域名,发现超过9,000起潜在的凭据和Cookie窃取事件。地理分布上美国占63.7%,其余涉及印度、新加坡、英国、加拿大、沙特阿拉伯和南非等国。
  • 行业分布:科技、制造业和教育行业是主要目标,反映出这些领域对Microsoft 365依赖度高且员工安全意识相对薄弱。
  • 检测方案:ANY.RUN交互式沙箱可隔离分析可疑附件和URL,暴露重定向、脚本、WebSocket活动及伪造登录页面。威胁情报馈送(Threat Intelligence Feeds)整合16,000+组织数据,支持从孤立IOCs向可操作情报转化。
  • 响应建议:将会话窃取视为身份事件而非单纯密码泄露,需撤销被劫持的会话和令牌,调查受影响身份关联活动,而非仅依赖密码重置。

行业启示

  • 认证架构升级:传统MFA已不足以应对现代钓鱼攻击,企业应优先部署FIDO2/WebAuthn等抗钓鱼认证方案,并强化会话生命周期管理。
  • 威胁检测范式转变:从基于IOCs的静态检测转向行为分析,通过沙箱和威胁情报识别攻击基础设施和模式,实现早期预警。
  • 响应流程重构:建立针对会话劫持的专项响应机制,将身份事件纳入SOAR流程,缩短MTTR(平均响应时间),降低账户接管成本。

Disclaimer: The above content is generated by AI and is for reference only. 免责声明:以上内容由 AI 生成,仅供参考。

Security 安全 Research 科学研究