Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Hackers Exploit MFA to Hijack Microsoft 365 Sessions

Hackers Exploit MFA to Hijack Microsoft 365 Sessions

Posted on August 19, 2026 By CWS

A new Phishing-as-a-Service platform called Mirage2FA is providing cybercriminals with the ability to bypass multi-factor authentication (MFA) in Microsoft 365 accounts. This sophisticated tool allows attackers to intercept authenticated sessions after users complete their login process, posing significant threats to enterprise security.

How Mirage2FA Compromises Security

Security researchers from ANY.RUN have uncovered how the Adversary-in-the-Middle (AiTM) framework employed by Mirage2FA leads to massive session cookie theft rather than merely targeting passwords. This method has been in effect since late 2024, resulting in a substantial number of compromised accounts.

The tool operates by positioning itself between users and legitimate authentication endpoints. When users enter their credentials and one-time passcodes into a fake login portal, the data is immediately relayed to the actual Microsoft 365 service. Once authentication is confirmed, the tool intercepts the session tokens, allowing unauthorized access.

Impact and Reach of Session Hijacking

Armed with intercepted session cookies, attackers can access various Microsoft 365 services without triggering additional authentication prompts. The group behind this operation, identified as LinX Coders, uses particular configurations and telemetry channels to manage the stolen sessions.

ANY.RUN’s analysis shows a vast exposure across enterprises, affecting 3,518 email domains and 9,426 accounts, with the United States being the most impacted. The campaign also hit countries like India, Singapore, and the UK, with the technology sector being the primary target.

Mitigation and Future Outlook

The infection chain operates entirely in the browser, often using obfuscated HTML and SVG attachments in phishing emails. Security experts stress the importance of focusing on structural attack patterns rather than domain names. Immediate actions include invalidating active sessions, revisiting OAuth permissions, and implementing hardware security solutions like FIDO2 keys.

Organizations must remain vigilant and proactive in addressing these threats. Traditional password resets are inadequate; comprehensive strategies must be adopted to ensure session security and prevent unauthorized access.

As the cybercrime landscape evolves, integrating advanced threat detection and investigation tools, such as ANY.RUN, is crucial for strengthening security operations centers (SOCs) and combating phishing campaigns effectively.

Cyber Security News Tags:ANY.RUN, Cybercrime, Cybersecurity, enterprise security, LinX Coders, MFA breach, Microsoft 365, Mirage2FA, phishing-as-a-service, session cookies, session hijacking, technology sector

Post navigation

Previous Post: Spectre Attack on Cloudflare Workers Leaks JWT
Next Post: OpenAI Enhances AI Security Amid Training Pause

Related Posts

WhatsApp Developers Under Attack From Weaponized npm Packages with Remote Kill Switch WhatsApp Developers Under Attack From Weaponized npm Packages with Remote Kill Switch Cyber Security News
Mongobleed PoC Exploit Tool Released for MongoDB Flaw that Exposes Sensitive Data Mongobleed PoC Exploit Tool Released for MongoDB Flaw that Exposes Sensitive Data Cyber Security News
Telnyx SDK on PyPI Compromised by Hackers Telnyx SDK on PyPI Compromised by Hackers Cyber Security News
Pay2Key Linux Ransomware Targets Servers and Cloud Systems Pay2Key Linux Ransomware Targets Servers and Cloud Systems Cyber Security News
Police Body Camera Apps Sending Data to Cloud Servers Hosted in China Via TLS Port 9091 Police Body Camera Apps Sending Data to Cloud Servers Hosted in China Via TLS Port 9091 Cyber Security News
Kodak Acknowledges Data Breach Amid ShinyHunters Threat Kodak Acknowledges Data Breach Amid ShinyHunters Threat Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Vercel Unveils KVM Zero-Day Flaw, Rewards Researcher $50K
  • ShinyHunters Suspect in Jordan Assists FBI in Hack Probe
  • Addressing Cybersecurity in an Era of Connected Vehicles
  • Warlock Group Targets SharePoint Flaws for Ransomware Attacks
  • Microsoft Releases Critical Exchange Update for Security Flaw

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • October 2026
  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Vercel Unveils KVM Zero-Day Flaw, Rewards Researcher $50K
  • ShinyHunters Suspect in Jordan Assists FBI in Hack Probe
  • Addressing Cybersecurity in an Era of Connected Vehicles
  • Warlock Group Targets SharePoint Flaws for Ransomware Attacks
  • Microsoft Releases Critical Exchange Update for Security Flaw

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark