4,532 unique organization email domains were potentially targeted in the Mirage2FA campaign between 2024 and 2026, with U.S.-based companies accounting for 63.7% of the victims.
Mirage2FA: a commercial phishing-as-a-service toolkit
Mirage2FA is described as a commercial phishing-as-a-service toolkit that specifically targets Microsoft 365 login flows and abuses legitimate authentication processes to bypass two-factor authentication (2FA). The campaign has been active from 2024 through 2026 and has affected thousands of companies across multiple countries. According to the reporting, the toolkit’s model allows widespread deployment against enterprise targets by weaponizing standard sign-in pages and session handling.
How Mirage2FA hijacks Microsoft 365 sessions
The threat model reported centers on stealing passwords and session cookies so attackers can access authenticated Microsoft 365 sessions and SSO-connected services. Once an attacker gains a hijacked session, they can impersonate users, access corporate email and trusted business accounts, and move laterally to other services tied to single sign-on. ANY.RUN’s research highlights that these are AiTM (adversary-in-the-middle) style attacks that exploit gaps in authentication and session management — even when multi-factor protections are enabled.

This site is the portfolio.
OSINTSights runs on Cloudflare Workers, D1, R2, and Vectorize, with an AI pipeline on Hetzner ARM. Nubivance designed, built, and operates it. We do the same for clients.
See what we buildANY.RUN’s findings: scale, geographies, and the mechanics of compromise
ANY.RUN’s analysis provides the most specific public footprint available in the source material. Key metrics include:
- 4,532 unique organization email domains potentially targeted by Mirage2FA activity.
- 63.7% of those victims were located in the United States; additional activity was observed in India, Singapore, the United Kingdom, Canada, Saudi Arabia, South Africa, and other countries.
- Industries most frequently targeted included technology, manufacturing, and education.
- About 48% of targeted email addresses were potentially compromised, per ANY.RUN’s research.
- Researchers identified more than 9,000 potential compromise events involving cookie and password theft, SSO logins, and 2FA bypass.
ANY.RUN’s reporting underscores that the core danger is session theft: attackers do not need to break authentication factors if they can capture the authenticated session or associated tokens. That expands the attack radius beyond single credentials to connected apps and internal workflows, increasing containment complexity and cost.
Reducing Mirage2FA risk: strengthen authentication, detection, and response
The source lays out mitigation principles centered on treating session theft as an identity incident and improving detection across attack surfaces. Recommended measures include strengthening authentication (with an emphasis on phishing-resistant approaches), integrating sandboxing into investigative workflows to safely analyze suspicious content, and augmenting behavioral detection that can reveal AiTM patterns such as recurring loaders, encoded payloads, and unusual WebSocket traffic.
Operational advice from the material emphasizes response changes: revoke compromised sessions and tokens and investigate activity tied to the affected identity rather than relying solely on password resets. The reporting also advocates real-time threat intelligence integration to adapt as attacker infrastructure shifts — turning isolated IOCs into actionable intelligence by pivoting from suspicious URLs, domains, IPs, and files to related infrastructure and activity.
ANY.RUN offered performance claims tied to these approaches: detecting threats in 14 seconds and cutting mean time to remediation by 21 minutes per case. The reporting further notes access to threat data from more than 16,000 organizations as part of its intelligence proposition.
What this means for technologists, affected enterprises, and end users
- Technologists and security teams: Expect to prioritize behavioral detection and session-focused playbooks. The source recommends integrating sandboxing, real-time threat feeds, and monitoring for WebSocket and loader patterns to detect AiTM campaigns earlier.
- Affected enterprises and procurement leaders: Companies in technology, manufacturing, and education — and large U.S. employers broadly — should treat session theft as an identity incident, revoke tokens and sessions, and not assume password resets are sufficient to contain compromise.
- End users and administrators: Because Mirage2FA abuses legitimate login flows, user-facing training remains useful but insufficient alone; the material stresses deploying phishing-resistant authentication and ensuring incident response includes token and session revocation.
Mirage2FA demonstrates that phishing has evolved from credential harvesting to session hijacking at scale: thousands of organizations, concentrated in the United States, have been touched by a toolkit that sidesteps conventional MFA by exploiting authenticated sessions. The clear practical takeaway in the reporting is that organizations must combine stronger, phishing-resistant authentication with faster, session-aware detection and response — and treat session theft as a separate class of identity incident rather than a simple password problem.
https://thehackernews.com/2026/08/mirage2fa-surge-hits-4500-us-and-eu.html




