Loading article…
The Mirage2FA phishing-as-a-service toolkit has compromised 48% of targeted Microsoft 365 accounts, bypassing MFA to steal session cookies and credentials.
The Mirage2FA phishing-as-a-service toolkit has compromised an estimated 4,532 corporate email domains across the US and EU, successfully bypassing conventional two-factor authentication (MFA) to hijack active Microsoft 365 sessions [1]. By capturing session cookies in real-time, the campaign grants attackers persistent access to corporate environments, creating significant identity-related risks that extend to SSO-connected applications and internal workflows [2].
| At a glance | |
|---|---|
| Campaign Target | Microsoft 365 Accounts |
| Estimated Compromise Rate | 48% of targets |
| Primary Victim Region | United States (63.7%) |
| Primary Attack Method | Adversary-in-the-Middle (AiTM) |
Mirage2FA operates as a commercial phishing-as-a-service (PaaS) offering that relies on browser-based delivery rather than traditional binary malware [2]. Attackers distribute malicious .htm, .xhtml, or .svg attachments—or use QR codes—to lure victims into an Adversary-in-the-Middle (AiTM) flow [2]. Once the victim interacts with the phishing page, the toolkit proxies the authentication process in real-time, capturing not only passwords but also the 2FA codes and session cookies required to maintain an authenticated state [2].
The scale of the operation is substantial, with researchers recording 9,332 potential compromise events between 2024 and 2026 [2]. Of these events, session-cookie theft emerged as the most common outcome, accounting for more than half of all recorded incidents [2]. Because the attack hijacks an existing, authenticated session, it effectively renders standard MFA ineffective, as the attacker is already "inside" the perimeter with a valid token [1]. This approach is particularly effective against mobile users, who accounted for 33.3% of successful login events, as the limited URL visibility on mobile devices makes it harder for targets to identify the malicious phishing infrastructure [2].
The campaign shows a clear concentration in sectors that rely heavily on Microsoft 365 for daily operations, specifically technology, manufacturing, and education [1]. While the activity is global—spanning 94 countries—the United States remains the primary target, accounting for 2,885 of the identified victims [2].
The business impact of these compromises often exceeds the initial account takeover. Because attackers gain access to the corporate environment through a trusted user identity, they can move laterally into SSO-connected apps and internal business workflows [1]. Security teams face higher containment costs compared to standard credential theft, as revoking a password is insufficient; organizations must identify and invalidate the specific stolen session tokens to fully eject the attacker from the environment [1].
/xls/*.js loader structure or specific WebSocket activity, which researchers use to track the campaign’s evolution [2].The Mirage2FA campaign highlights a critical vulnerability in modern authentication: as long as session cookies remain valid, MFA is no longer a sufficient barrier against sophisticated phishing. The open question for security teams is whether they can implement phishing-resistant authentication fast enough to close the gap before session-based identity theft becomes the standard for corporate breaches.
Coverage is mostly measured — 206 of 206 reports stay neutral.
Every Monday — the token unlocks, Fed dates & catalysts set to move crypto and markets this week. So you’re never blindsided.
Free · 3-min read · one-click unsubscribe
AI-assisted synthesis by the TrendWatcher Editorial Desk · sourced from 2 outlets · Aug 26, 2026 · How we report
Microsoft was founded on April 4, 1975, by Bill Gates and Paul Allen.
The U.S. Department of Justice and 20 states accused Microsoft of illegally maintaining an operating system monopoly by bundling Internet Explorer with Windows.
Microsoft leadership directed engineers to quickly test and deploy the DeepSeek R1 model on Azure AI Foundry and GitHub.