A sophisticated phishing toolkit known as Mirage2FA is raising alarm in the cybersecurity community due to its ability to bypass multi-factor authentication (MFA) and hijack Microsoft 365 sessions. This malicious tool, linked to the LinX Coders phishing-as-a-service platform, has been associated with over 9,332 compromise events across 94 countries, with a significant concentration of victims in the United States.
Widespread Impact on Microsoft 365 Accounts
The recent analysis by threat intelligence experts ShiFu and raptur3 from ANY.RUN reveals that Mirage2FA has potentially compromised 4,532 Microsoft 365 accounts by targeting over 3,500 organizations. Unlike traditional malware, this kit uses advanced web-based techniques, such as HTML and SVG attachments, to redirect users to a counterfeit Microsoft login page operated by an adversary-in-the-middle (AiTM) proxy server.
This server intercepts login credentials and session cookies, enabling attackers to access accounts without needing to re-enter credentials or pass MFA checks. This method has proven highly effective, particularly against technology and manufacturing firms in the U.S.
Global Reach and Sector Vulnerability
ANY.RUN’s data indicates that nearly half of the targeted accounts may have been compromised, with the campaign reaching 9,426 unique email addresses. The United States accounts for 63.7% of these victims, followed by India, Singapore, the United Kingdom, and Canada. The technology sector bears the brunt of these attacks, followed by manufacturing, education, consulting, and telecommunications industries.
The compromising of Managed Security Service Providers (MSSPs) is particularly concerning as a single breached account can expose numerous client networks. This highlights the widespread risk posed by Mirage2FA’s operations, which have intensified since 2026.
Session Cookie Theft Dominates
Of the recorded compromise events, 51% involved session cookie theft, affecting over 2,500 victims. This method allows attackers to maintain access to accounts even after password resets, complicating incident response efforts. The stolen cookies are stored as Base64-encoded files, ready for reuse in accessing Microsoft 365 and other connected services.
Mirage2FA’s attacks often begin with phishing emails, which contain attachments or QR codes prompting victims to enter credentials on a fake Microsoft page. The entire process, from email to account takeover, is meticulously orchestrated to maximize victim deception.
As businesses continue to face these sophisticated threats, understanding and mitigating the risks associated with tools like Mirage2FA is crucial for maintaining secure operations and protecting sensitive data.
