Key Takeaways
- The Mirage2FA phishing‑as‑a‑service campaign (2024‑2026) targeted Microsoft 365 accounts, abusing legitimate login flows to steal passwords and session cookies and bypass two‑factor authentication.
- ANY.RUN research indicates that ≈ 48 % of the targeted email addresses were potentially compromised, affecting ≈ 4,532 unique organization domains worldwide.
- The United States accounted for 63.7 % of victims, with notable activity also observed in India, Singapore, the United Kingdom, Canada, Saudi Arabia, South Africa, and other regions.
- Technology, manufacturing, and education sectors were the most frequently hit industries.
- Over 9,000 potential compromise events involving cookie theft, password harvesting, SSO logins, and 2FA bypass were uncovered, highlighting session theft as a primary risk.
- Effective mitigation requires phishing‑resistant authentication, robust session controls, early behavioral detection (e.g., sandbox analysis), and treating session theft as an identity incident that demands token revocation and thorough investigation.
- Integrating real‑time threat‑intelligence feeds with tools like ANY.RUN’s Interactive Sandbox helps turn isolated IOCs into actionable intelligence, reduces mean‑time‑to‑respond, and lowers the overall cost of account compromise.
Introduction
From 2024 through 2026, a sophisticated phishing‑as‑a‑service operation dubbed Mirage2FA inundated thousands of enterprises with credential‑harvesting lures that went far beyond simple password theft. By exploiting legitimate Microsoft 365 authentication flows, the campaign succeeded in bypassing multi‑factor authentication (MFA) and hijacking authenticated user sessions. The resulting access granted attackers footholds into corporate email, single‑sign‑on (SSO)‑connected applications, and other sensitive data stores, amplifying the potential damage far beyond the initially compromised credential.
Campaign Overview and Scope
ANY.RUN’s analysis shows that Mirage2FA activity touched ≈ 4,532 unique organization email domains, with a pronounced concentration in the United States (63.7 % of victims). Additional hotspots included India, Singapore, the United Kingdom, Canada, Saudi Arabia, and South Africa, illustrating a truly global reach. The technology, manufacturing, and education sectors bore the brunt of the attacks, likely due to their heavy reliance on Microsoft 365 suites and the value of the intellectual property or operational data they house.
Technical Mechanics: How Mirage2FA Bypasses MFA
At its core, Mirage2FA employs a classic adversary‑in‑the‑middle (AiTM) technique: victims are lured to a convincing replica of the Microsoft 365 login page hosted on attacker‑controlled infrastructure. When users enter their credentials, the proxy forwards them to the genuine Microsoft service, captures the returned authentication token or session cookie, and then presents the user with a seemingly legitimate post‑login experience. Because the attacker obtains a valid session cookie, traditional MFA checks—such as push notifications or SMS codes—are effectively sidestepped; the attacker already possesses an authenticated session that Microsoft trusts.
Geographic and Industry Impact
Beyond the raw numbers, the campaign’s distribution reveals strategic targeting. The United States’ dominance reflects both the large base of Microsoft 365 adopters and the perceived value of corporate data housed there. Observed activity in Asia‑Pacific (India, Singapore) and EMEA (UK, Saudi Arabia, South Africa) suggests the actors leveraged regional language lures and local brand imitation to increase success rates. Within industries, technology firms often possess development environments and source code repositories; manufacturing firms may hold proprietary designs or supply‑chain logistics data; educational institutions store research data and personal information—all high‑value targets for espionage, fraud, or ransomware follow‑ons.
Session Theft as the Primary Risk
ANY.RUN documented more than 9,000 potential compromise events tied to Mirage2FA, the majority involving the theft of session cookies or authentication tokens. Once an attacker holds a valid session, they can impersonate the user across any SSO‑connected service—Exchange Online, SharePoint, Teams, Azure AD‑linked apps—without needing to re‑authenticate. This capability transforms a credential leak into a persistent identity breach, enabling lateral movement, data exfiltration, business‑email‑compromise (BEC) scams, and the planting of malware or backdoors. Because the session remains valid until explicitly revoked, simple password resets are insufficient; the compromised token must be invalidated and any associated activity scrutinized.
Detecting Mirage2FA Earlier with Behavioral Analysis
Early detection hinges on recognizing the subtle hallmarks of AiTM phishing rather than relying solely on known malicious URLs or file hashes. ANY.RUN’s Interactive Sandbox enables security teams to detonate suspicious attachments and URLs in an isolated, observable environment. Within seconds, the sandbox can reveal redirect chains, injected JavaScript, WebSocket communications, and the precise rendering of counterfeit Microsoft 365 login pages—behaviors that static scanners often miss. By capturing these dynamic indicators, analysts can flag Mirage2FA attempts before victims submit credentials, thereby reducing the window of exposure.
Strengthening Authentication and Session Controls
To mitigate the underlying risk, organizations should move beyond traditional MFA toward phishing‑resistant mechanisms such as FIDO2 security keys, certificate‑based authentication, or Windows Hello for Business. These methods bind authentication to a specific device or hardware token, making it far harder for an AiTM proxy to reuse a stolen session. Complementing strong authentication with tighter session management—short‑lived tokens, conditional access policies that enforce device compliance, and real‑time session monitoring—limits the usefulness of any intercepted cookie.
Leveraging Threat Intelligence Feeds for Broader Context
Treating session theft as an identity incident necessitates a shift from isolated IOC enrichment to infrastructure‑level analysis. ANY.RUN’s Threat Intelligence Feeds continuously ingest malicious indicators from over 16,000 organizations, providing fresh data on domains, IPs, file hashes, and associated behavior. When a suspicious URL or attachment is detected, analysts can pivot via Threat Intelligence Lookup to uncover related loaders, encoded payloads, or WebSocket endpoints that belong to the same Mirage2FA campaign. This contextual enrichment transforms a single alert into a map of the attacker’s operational footprint, facilitating proactive blocking and hunt operations.
Practical Benefits: Reduced MTTR and Cost Savings
Integrating these capabilities yields measurable operational improvements. ANY.RUN reports that threats can be detected in as little as 14 seconds, cutting the mean‑time‑to‑respond (MTTR) by approximately 21 minutes per incident. Faster containment translates directly into lower incident‑handling costs, reduced risk of data loss, and diminished likelihood of regulatory penalties. Moreover, by treating each session theft as an identity incident—revoking tokens, auditing linked activities, and enforcing re‑authentication—organizations prevent attackers from maintaining footholds even after a password reset.
Conclusion
Mirage2FA exemplifies how modern phishing has evolved from simple credential harvesting to sophisticated session hijacking that defeats conventional MFA. By stealing authenticated Microsoft 365 sessions, attackers gain persistent, trusted access to a wide array of corporate resources, amplifying the potential for fraud, espionage, and operational disruption. The campaign’s broad geographic sweep, concentration in high‑value sectors, and reliance on cookie theft underscore the need for a layered defense: phishing‑resistant authentication, vigilant session controls, early behavioral detection via sandboxing, and enriched threat‑intelligence‑driven investigations. Enterprises that adopt these practices will be better positioned to detect Mirage2FA‑style threats early, limit their impact, and reduce the overall cost of identity‑centric attacks.

