HackMyIP
← Back to News
2026-08-25 The Hacker News

Mirage2FA Phishing Kit Hits 4,500 Companies, Bypasses Microsoft 365 MFA

PhishingAuthenticationCloud Security

A sweeping phishing-as-a-service operation known as Mirage2FA has compromised or targeted an estimated 4,532 unique corporate email domains across the United States and Europe between 2024 and 2026, according to research published by ANY.RUN and reported by The Hacker News. The toolkit specifically weaponizes Microsoft 365 login flows, intercepting credentials and session cookies through adversary-in-the-middle (AiTM) proxies that relay authentication traffic in real time. This approach allows attackers to bypass two-factor authentication entirely, since the victim completes the 2FA challenge on the legitimate Microsoft login page without ever realizing a proxy sits between them and the server.

ANY.RUN's telemetry indicates that roughly 48% of targeted email addresses may have been successfully compromised, with the United States accounting for 63.7% of victims. Additional impact was observed in India, Singapore, the United Kingdom, Canada, Saudi Arabia, and South Africa, with technology, manufacturing, and education emerging as the most heavily targeted sectors. Researchers logged more than 9,000 potential compromise events involving cookie theft, password harvesting, SSO logins, and 2FA bypass attempts. Once a hijacked session is in hand, attackers can pivot into SSO-connected applications, impersonate users internally, and persist inside corporate tenants long after the initial phishing email is forgotten. Organizations can audit their exposure with an email breach checker to see whether employee credentials tied to Microsoft 365 have already surfaced in known dumps.

The campaign's reliance on session theft rather than raw credential theft makes it especially difficult to contain. Traditional password resets do little to evict an attacker who already holds a valid session token, and Microsoft 365's SSO integrations with third-party SaaS platforms amplify the blast radius considerably. Defenders should treat any detected Mirage2FA indicator as an active identity incident rather than a simple credential leak, rotating session tokens, revoking refresh tokens, and reviewing unified audit logs for anomalous mailbox rules, OAuth grants, and inbox forwarding changes. Employees can verify whether their personal credentials have been recycled in past breaches by running them through a password checker, and security teams should audit tenant-level conditional access policies that may still permit legacy authentication or non-phishing-resistant MFA factors.

To reduce exposure moving forward, organizations are urged to move beyond SMS- and app-based MFA toward phishing-resistant methods such as FIDO2 hardware keys or Windows Hello for Business, which are immune to AiTM relay attacks. Continuous sandbox analysis of suspicious links and attachments, behavioral detection of impossible-travel sign-ins, and strict session lifetime policies provide additional layers of defense against kits like Mirage2FA. As commercial phishing-as-a-service platforms continue lowering the technical barrier for attackers, the incident highlights why session integrity, not just password strength, must sit at the center of every modern cloud identity strategy.

Source: The Hacker News →

Related Tools

Check whether this kind of story affects you — free, no signup:

Email Auth Check →Email Breach Check →Privacy Checkup →

Related Guides

Learn the background behind this story:

How phishing attacks work →How to check if an email is safe →SPF, DKIM & DMARC explained →