Mirage2FA Hijacks Companies’ Microsoft 365 Sessions, with Over 4K Victims in the US
Mirage2FA phishing-as-a-service kit uses AiTM attacks to hijack Microsoft 365 sessions, with over 4,000 US victims.
ANY.RUN analyzed Mirage2FA, an active phishing-as-a-service toolkit that steals Microsoft 365 credentials and authenticated sessions through Adversary-in-the-Middle phishing pages. About 63.7% of identified victims are in the US, with Technology, Manufacturing, and Education the most targeted industries. Thousands of compromise events were recorded between 2024 and 2026.
- PhaaS toolkit performs AiTM credential and session theft
- 63.7% of identified victims are US-based
- Technology, Manufacturing, and Education most targeted
- Over 4,000 victims observed from 2024 to 2026
Mirage2FA is an active phishing-as-a-service toolkit built to steal Microsoft 365 credentials and authenticated sessions through Adversary-in-the-Middle (AiTM) attacks. ANY.RUN research shows that 63.7% of identified victims are in the US, with Technologies, Manufacturing, and Education among the most targeted industries. The operation has generated thousands of compromise events between 2024 and 2026, including stolen […] The post Mirage2FA Hijacks Companies’ Microsoft 365 Sessions, with Over 4K Victims in the US appeared first on ANY.RUN's Cybersecurity Blog.
This source does not provide full text. Read it at any.run.