Back to Feed
Threat IntelligenceAug 25, 2026

Mirage2FA Surge Hits 4,500 US and EU Companies, Abusing Microsoft 365 Login Flows

Mirage2FA campaign targets Microsoft 365 accounts, bypassing 2FA for 4,500+ companies.

Summary

The Mirage2FA campaign, active from 2024 to 2026, has impacted over 4,500 companies globally, with a significant focus on US-based organizations. This phishing-as-a-service toolkit exploits legitimate Microsoft 365 login flows to bypass two-factor authentication by stealing passwords and session cookies. The campaign's success in session hijacking poses substantial identity-related risks, potentially exposing sensitive corporate data and enabling further compromise.

Full text

Mirage2FA Surge Hits 4,500 US and EU Companies, Abusing Microsoft 365 Login Flows The Hacker NewsAug 25, 2026Phishing / Enterprise Security Thousands of companies have been affected by the Mirage2FA campaign from 2024 to 2026. The commercial phishing-as-a-service toolkit targets Microsoft 365 accounts by abusing legitimate login flows and bypassing two-factor authentication. According to ANY.RUN research, 48% of targeted email addresses were potentially compromised. Most of the affected companies are US-based. Mirage2FA Campaign Scope and Impact By stealing passwords and session cookies, attackers can gain access to authenticated Microsoft 365 sessions and SSO-connected services. This creates significant identity-related risks for companies, potentially exposing corporate email, trusted business accounts, and other sensitive data. Once an authenticated Microsoft 365 session is hijacked, a path for impersonation, fraud, and further compromise is created. Key takeaways about Mirage2FA by ANY.RUN The campaign has a broad geographic and corporate reach. Apart from the United States accounting for 63.7% of the total victims, Mirage2FA activity was also observed in India, Singapore, the United Kingdom, Canada, Saudi Arabia, South Africa, and other countries. Overall, Mirage2FA activity is potentially linked to 4,532 unique organization email domains. Technology, manufacturing, and education were among the most targeted industries. A major part of the risk for affected companies comes from session theft. ANY.RUN’s research uncovered more than 9,000 potential compromise events involving cookie and password theft, SSO logins, and 2FA bypass. Findings from ANY.RUN research show how AiTM attacks can exploit gaps in authentication and session management even when two-factor authentication is in place. The impact can also extend beyond the initially compromised account. Follow-on access, SSO-connected apps, and other internal workflows can increase the attack radius, further increasing containment costs. Another costly factor is that impact goes beyond password theft, as attackers gain access to the corporate environment or Microsoft 365 services through hijacked user sessions, making it harder to take swift measures. How to Reduce Mirage2FA Risk in Your Company Organizations can reduce exposure by strengthening authentication, detecting campaign behavior, and treating session theft as an identity incident. Detect Attacks Earlier with Deeper Analysis Mirage2FA analysis in ANY.RUN’s Interactive Sandbox Seamlessly integrating sandboxing into existing workflows helps SOC teams safely investigate suspicious content and identify phishing behavior before it leads to account compromise. Enterprise Security Tip How ANY.RUN Helps Analyze suspicious attachments and URLs in isolation. Interactive Sandbox exposes redirects, scripts, WebSocket activity, and fake Microsoft 365 login pages. Move beyond traditional MFA. Use phishing-resistant authentication and stronger session controls. Sandbox analysis helps identify attacks designed to bypass traditional authentication controls. These measures help security teams detect Mirage2FA activity earlier, investigate its wider scope, and limit the impact of session theft. Lower the cost of account compromise with early detection with ANY.RUN. Detect threats in 14 sec and cut MTTR by 21 mins per case. Integrate ANY.RUN in your SOC Uncover the Infrastructure Behind Campaigns Mirage2FA activity should be investigated beyond individual IOCs. Recurring loaders, encoded data, suspicious WebSocket activity, and related infrastructure can help reveal connections to a wider campaign. ANY.RUN’s Threat Intelligence Feeds: how they work and what impact they bring Session theft should be treated as an identity incident. Teams should revoke compromised sessions and tokens and investigate activity tied to the affected identity rather than relying on a password reset alone. Integration of real-time Threat Intelligence Feeds provides fresh malicious indicators that complement behavioral detections as attacker infrastructure changes. Analysts can then use Threat Intelligence Lookup to pivot from suspicious URLs, domains, IPs, and files to related infrastructure and activity. Turn isolated IOCs into actionable intelligence backed by threat data from 16,000+ organizations. Explore ANY.RUN Conclusion Mirage2FA shows how phishing has evolved beyond credential theft. By hijacking Microsoft 365 sessions, attackers can bypass conventional MFA and gain access through trusted user identities. With thousands of organizations affected, particularly in the US, businesses need to prioritize phishing-resistant authentication, behavioral detection, and response procedures designed for session theft. Found this article interesting? This article is a contributed piece from one of our valued partners. Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post. SHARE     Tweet Share Share Share SHARE  account takeover, Cloud security, Credential Theft, Cyber Attack, enterprise security, Identity Security, Microsoft 365, Phishing, session hijacking, Threat Intelligence ⚡ Top Stories This Week Microsoft Patches Severe Entra ID Flaw (CVSS 10.0) Allowing Remote Code Execution ThreatsDay: Gogs 10.0 RCE, n8n Workflow-to-RCE, $10M Reward, GLM-5.3 AI Exploit, and More New Cryptographic Context Injection Attack Could Let Web Pages Steal Grok Chat Data Zombie Card Attack Can Revive Expired Visa Cards for Contactless Payments CDN Tsunami Attack Abuses HTTP/3 Translation for Up to 350x DoS Amplification Manic Android Malware Exfiltrates Data From Offline Phones via Nearby Infected Devices Cloudflare Workers Spectre Attack Leaks JWT From Co-Located Worker at 12 Bits/Second OpenAI Pauses Frontier RL Training as It Tightens Defenses Against Unsafe AI Behavior Hackers Compromised 14,500+ Dahua Devices Using Credential Attacks, Auth Bypasses, and P2P Microsoft Copilot Personal Flaws Could Let One Click Exfiltrate Data From Connected Apps AI "Mind Viruses" Can Spread Between Agents Through Persistent Prompt Files SafePal Hardware Wallet Maker Says Flaw Exposed Data of Nearly 40,000 Customers Critical GitLab GraphQL Flaw Could Let Unauthenticated Attackers Delete Public Projects ⚡ Weekly Recap: VMware Exploits, Windows 0-Day, MCP Attacks, Browser Hijacks and More Unisoc VoLTE Video Call Exploit Chain Can Give Attackers Full Android Kernel Access Evooo1Bot Linux Botnet Exploits Known Flaws to Turn Edge Devices Into SOCKS5 Proxies SAP Commerce Cloud CVE-2026-58231 Targeted in Exploitation Attempts Days After Patch Hackers Spend Nearly $7 Million on Expired Domains to Redirect Traffic to Scams and Malware Apple Warns Users in 110 Countries They May Be Targets of Mercenary Spyware Trump Memo Paves Way for U.S. Firms to Hack and Disrupt Foreign Crime Groups GeoServer Zero-Day Targeted in Active Exploitation Attempts, Can Lead to RCE Attackers Exploit SharePoint Authentication Bypass After Public PoC Release Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor Attackers Exploit VMware vCenter Vulnerability to Gain Persistent Remote Access ShieldBreak Zero-Day PoC Claims Microsoft Defender Patch Bypass With SYSTEM Access ⭐ Featured Resources See How Keeper Secrets Manager Removes Hard-Coded Credentials Download the CISO's Guide to Smarter AI Security Investment Phishing Is Costing Security Teams More Than Ever — Read the New Report Build AI Agents and Automations Without Losing Security Control

Entities

Microsoft 365 (product)Mirage2FA (threat_actor)Mirage2FA (campaign)ANY.RUN (vendor)