ZeroHour
Threat actor

Mirage2FA

0 mentions in 7 days · 1 in 30 days · 1 total · first seen · last

Timeline

Mirage2FA Hijacks Companies’ Microsoft 365 Sessions, with Over 4K Victims in the US

Mirage2FA phishing-as-a-service kit uses AiTM attacks to hijack Microsoft 365 sessions, with over 4,000 US victims.

ANY.RUN analyzed Mirage2FA, an active phishing-as-a-service toolkit that steals Microsoft 365 credentials and authenticated sessions through Adversary-in-the-Middle phishing pages. About 63.7% of identified victims are in the US, with Technology, Manufacturing, and Education the most targeted industries. Thousands of compromise events were recorded between 2024 and 2026.

ANY.RUN · 28d agoPhishing & fraud in the wild1

Appears with

Entities are extracted by the model from each article. Watching an entity keeps it in this browser only (no account); the watchlist page and dashboard alerts use it.