VMTech
Discuss a project

Mirage2FA campaign targets 4,532 organizations via Microsoft 365

Mirage2FA campaign targets 4,532 organizations via Microsoft 365

ANY.RUN has linked the Mirage2FA phishing campaign to 4,532 unique organization email domains between 2024 and 2026. The commercial phishing-as-a-service toolkit targets Microsoft 365 accounts by abusing legitimate login flows, stealing passwords and session cookies, and bypassing two-factor authentication.

The research found that 48% of targeted email addresses were potentially compromised. The United States accounted for 63.7% of victims, while activity was also observed in India, Singapore, the United Kingdom, Canada, Saudi Arabia, South Africa and other countries. Technology, manufacturing and education were among the most targeted sectors.

Session theft expands the impact of phishing

Mirage2FA is designed to do more than collect a password. By capturing an authenticated browser session and its cookies, an attacker can enter Microsoft 365 as a trusted user. That access can also extend to services connected through single sign-on, broadening the consequences beyond the first compromised mailbox.

ANY.RUN identified more than 9,000 potential compromise events involving password and cookie theft, SSO logins and two-factor-authentication bypass. A hijacked session can enable impersonation, fraud and further access to internal workflows or sensitive business data. This makes containment more difficult than in a conventional credential-theft incident, where changing a password may be enough to end access.

Why conventional MFA is not enough

The campaign illustrates how adversary-in-the-middle phishing can exploit gaps in authentication and session management even when MFA is enabled. The attacker does not necessarily need to defeat the authentication factor directly; instead, the attack captures the session created after the user has completed the legitimate login process.

ANY.RUN recommends treating session theft as an identity incident. Security teams should revoke compromised sessions and tokens, then investigate activity associated with the affected identity rather than relying on a password reset alone. They should also assess follow-on access to SSO-connected applications and internal workflows.

Detection and response priorities

Investigations should look beyond isolated indicators of compromise. ANY.RUN notes that recurring loaders, encoded data, suspicious WebSocket activity and related infrastructure can reveal links to a broader campaign. Analysis of suspicious attachments and URLs in an isolated environment can expose redirects, scripts and fake Microsoft 365 login pages before they result in account compromise.

For businesses, the practical response is to pair phishing-resistant authentication with stronger session controls, behavioural detection and procedures for token and session revocation. When a phishing alert involves Microsoft 365, the incident response scope should include the user identity, active sessions and connected services, not just the password.

#cybersecurity#phishing#microsoft365#identitysecurity
Open analytics
On the site 0 views
min read 3 25.08.2026
Instagram

Mirage2FA campaign targets 4,532 organizations via Microsoft 365

Open the post on Instagram ↗