Mirage2FA Surge Hits 4,500 US and EU Companies, Abusing Microsoft 365 Login Flows

Thousands of companies have been affected by the Mirage2FA campaign from 2024 to 2026. The commercial phishing-as-a-service toolkit targets Microsoft 365 accounts by abusing legitimate login flows and bypassing two-factor authentication.

According to ANY.RUN research, 48% of targeted email addresses were potentially compromised. Most of the affected companies are US-based.

Mirage2FA Campaign Scope and Impact

By stealing passwords and session cookies, attackers can gain access to authenticated Microsoft 365 sessions and SSO-connected services. This creates significant identity-related risks for companies, potentially exposing corporate email, trusted business accounts, and other sensitive data.

Once an authenticated Microsoft 365 session is hijacked, a path for impersonation, fraud, and further compromise is created.

Key takeaways about Mirage2FA by ANY.RUN

The campaign has a broad geographic and corporate reach. Apart from the United States accounting for 63.7% of the total victims, Mirage2FA activity was also observed in India, Singapore, the United Kingdom, Canada, Saudi Arabia, South Africa, and other countries. 

Overall, Mirage2FA activity is potentially linked to 4,532 unique organization email domains. Technology, manufacturing, and education were among the most targeted industries.

A major part of the risk for affected companies comes from session theft. ANY.RUN’s research uncovered more than 9,000 potential compromise events involving cookie and password theft, SSO logins, and 2FA bypass.

Findings from ANY.RUN research show how AiTM attacks can exploit gaps in authentication and session management even when two-factor authentication is in place. 

The impact can also extend beyond the initially compromised account. Follow-on access, SSO-connected apps, and other internal workflows can increase the attack radius, further increasing containment costs. 

Another costly factor is that impact goes beyond password theft, as attackers gain access to the corporate environment or Microsoft 365 services through hijacked user sessions, making it harder to take swift measures.

How to Reduce Mirage2FA Risk in Your Company

Organizations can reduce exposure by strengthening authentication, detecting campaign behavior, and treating session theft as an identity incident.

Detect Attacks Earlier with Deeper Analysis

Mirage2FA analysis in ANY.RUN’s Interactive Sandbox

Seamlessly integrating sandboxing into existing workflows helps SOC teams safely investigate suspicious content and identify phishing behavior before it leads to account compromise.

Enterprise Security Tip How ANY.RUN Helps
Analyze suspicious attachments and URLs in isolation. Interactive Sandbox exposes redirects, scripts, WebSocket activity, and fake Microsoft 365 login pages.
Move beyond traditional MFA. Use phishing-resistant authentication and stronger session controls. Sandbox analysis helps identify attacks designed to bypass traditional authentication controls.

These measures help security teams detect Mirage2FA activity earlier, investigate its wider scope, and limit the impact of session theft.

Lower the cost of account compromise with early detection with ANY.RUN.

Detect threats in 14 sec and cut MTTR by 21 mins per case.

Integrate ANY.RUN in your SOC

Uncover the Infrastructure Behind Campaigns

Mirage2FA activity should be investigated beyond individual IOCs. Recurring loaders, encoded data, suspicious WebSocket activity, and related infrastructure can help reveal connections to a wider campaign.

ANY.RUN’s Threat Intelligence Feeds: how they work and what impact they bring

Session theft should be treated as an identity incident. Teams should revoke compromised sessions and tokens and investigate activity tied to the affected identity rather than relying on a password reset alone.

Integration of real-time Threat Intelligence Feeds provides fresh malicious indicators that complement behavioral detections as attacker infrastructure changes. Analysts can then use Threat Intelligence Lookup to pivot from suspicious URLs, domains, IPs, and files to related infrastructure and activity.

Turn isolated IOCs into actionable intelligence backed by threat data from 16,000+ organizations.

Explore ANY.RUN

Conclusion

Mirage2FA shows how phishing has evolved beyond credential theft. By hijacking Microsoft 365 sessions, attackers can bypass conventional MFA and gain access through trusted user identities.

With thousands of organizations affected, particularly in the US, businesses need to prioritize phishing-resistant authentication, behavioral detection, and response procedures designed for session theft.

source: TheHackerNews