Mirage2FA Surge Hits 4,500 US and EU Companies, Abusing Microsoft 365 Login Flows
The Mirage2FA phishing-as-a-service campaign (2024–2026) has targeted 4,532 unique organization email domains across the US and EU, with 48% of targeted email addresses potentially compromised. Attackers exploit AI-typical (AiTM) phishing techniques to steal passwords and session cookies from Microsoft 365 login flows, effectively bypassing two-factor authentication. Over 9,000 potential compromise events were identified, involving cookie theft, SSO logins, and 2FA bypass, with technology, manuf
Analysis
TL;DR
- The Mirage2FA phishing-as-a-service campaign (2024–2026) has targeted 4,532 unique organization email domains across the US and EU, with 48% of targeted email addresses potentially compromised.
- Attackers exploit AI-typical (AiTM) phishing techniques to steal passwords and session cookies from Microsoft 365 login flows, effectively bypassing two-factor authentication.
- Over 9,000 potential compromise events were identified, involving cookie theft, SSO logins, and 2FA bypass, with technology, manufacturing, and education as the most targeted industries.
- Session hijacking extends the attack radius beyond initial account takeover to SSO-connected services and internal workflows, significantly increasing containment costs.
- Mitigation requires phishing-resistant authentication, behavioral detection via sandboxing, treating session theft as an identity incident, and integrating real-time threat intelligence feeds.
Why It Matters
This campaign demonstrates that traditional MFA is no longer sufficient defense against sophisticated phishing operations, as session cookie theft and AiTM proxies can bypass 2FA entirely. For AI and security practitioners, it underscores the critical need to shift from credential-centric to identity- and session-centric security models, especially as Microsoft 365 remains the dominant corporate email and collaboration platform.
Technical Details
- Mirage2FA operates as a commercial phishing-as-a-service toolkit that deploys AiTM (AI-typical / pass-through) phishing pages mimicking legitimate Microsoft 365 login flows, capturing both credentials and active session cookies in real time.
- The campaign leverages WebSocket activity, encoded payloads, and recurring malware loaders to maintain persistent access and evade traditional signature-based detection.
- Compromised sessions grant attackers authenticated access to Microsoft 365 and all SSO-connected enterprise services, enabling lateral movement, impersonation, and data exfiltration without needing to crack passwords or bypass 2FA prompts.
- ANY.RUN's Interactive Sandbox was used to analyze suspicious attachments and URLs, exposing fake login pages, redirect chains, and script behavior that would otherwise blend into legitimate traffic.
- Threat Intelligence Feeds from 16,000+ organizations were integrated to pivot from individual IOCs to broader campaign infrastructure, revealing connections across recurring loaders and malicious domains.
Industry Insight
- Organizations must prioritize phishing-resistant authentication methods (e.g., FIDO2/WebAuthn, certificate-based auth) over traditional SMS or TOTP-based MFA, as session theft renders conventional 2FA ineffective against AiTM attacks.
- Security operations should treat session theft as a full identity incident—revoking tokens and sessions immediately rather than relying solely on password resets—and invest in behavioral detection and sandboxing to catch phishing infrastructure before compromise occurs.
- The commercialization of phishing toolkits like Mirage2FA signals a broader trend of attack democratization; as detection improves, threat actors will likely shift toward more advanced session manipulation and AI-generated phishing content, making continuous threat intelligence integration essential.
Disclaimer: The above content is generated by AI and is for reference only.