<img height="1" width="1" style="display:none;" alt="" src="https://px.ads.linkedin.com/collect/?pid=10643465&amp;fmt=gif">

Mirage2FA Phishing Kit Steals Microsoft 365 Sessions, Targets 3,500+ Organizations

Mirage2FA lets victims finish MFA, then lifts their logged-in cookie. ANY.RUN counts 4,532 accounts potentially compromised — resets won't help.
Content Team

A phishing-as-a-service toolkit called Mirage2FA has been linked to attacks on 3 518 organizations, with 4 532 Microsoft 365 accounts potentially compromised, researchers at ANY.RUN report. Active since September 2024, it skips malware entirely — a browser-executed HTML, XHTML or SVG attachment, or a QR code, steers the victim to a fake Microsoft login page.

Whatever the victim types — password and live 2FA code alike — an adversary-in-the-middle proxy passes through to Microsoft in real time. What the attacker keeps is the authenticated session cookie sent back on success, and it works until it expires or someone revokes it — no password or MFA needed.

Cookie theft was the largest single outcome — 4,561 of 9,332 recorded compromise events, just under half — affecting 2,541 accounts. Of the 4,532 accounts potentially compromised overall, 63.7% were in the U.S.; technology, manufacturing and education were the hardest-hit sectors.

A password reset won't fix this. Revoke every active session, and move high-risk users to phishing-resistant MFA — FIDO2 keys or passkeys, which are bound to the real site and can't be relayed. ANY.RUN also recommends blocking those attachment types and shortening session lifetimes.

Source: Cybersecurity News

Share this article
Share on facebook Share on linkedin Share on twitter Share on email
blog_book_a_demo_cta_3x
Have questions about protecting your software?
Our escrow experts are standing by to help.
Book a free demo