Illustrative image generated with AI
Mirage2FA: 48% of Microsoft 365 Phishing Targets Are Potentially Compromised
Mirage2FA phishing campaign compromises 48% of Microsoft 365 targets using AiTM to bypass MFA, affecting US and Europe with stolen sessions enabling SSO fraud.
Text generated by artificial intelligence, published without human review. AI transparency
A Campaign Ongoing for Two Years
Mirage2FA is described as a phishing-as-a-service campaign based on a commercial kit. It targets Microsoft 365 accounts by abusing legitimate login flows. The target is not a specific software version, but the accounts and services connected via single sign-on. ANY.RUN research, disclosed on August 25, 2026, indicates that 48% of the targeted email addresses were potentially compromised. The campaign has been active since 2024 and is still ongoing in 2026.
The numbers are significant: 4,532 email domains of unique organizations are potentially linked to the campaign, totaling around 4,500 companies, predominantly US and European. More than 9,000 potential compromise events have been detected, involving theft of cookies and passwords, login via single sign-on, and bypass of two-factor authentication.
Technique: Adversary-in-the-Middle to Steal Authenticated Sessions
The core of the attack is the adversary-in-the-middle (AiTM) technique. The attacker positions themselves between the victim and the legitimate Microsoft 365 service, intercepting communications. Unlike traditional phishing that only aims to steal credentials, the goal here is the authenticated session: session cookies and tokens are captured in real time while the victim interacts with a fake but functional login page.
The problem is that this approach bypasses two-factor authentication. The victim enters the password and completes the MFA verification, but the attacker intercepts the resulting session cookie. From that moment on, they can use the already authenticated session without having to repeat the MFA. The exploited weaknesses concern authentication and session management, not the weakness of a single password.
Who Is Targeted: United States Leads, Followed by Europe and Asia
The geographic distribution of victims shows a clear predominance of the United States, which represents 63.7% of the total. Activity has also been observed in India, Singapore, United Kingdom, Canada, Saudi Arabia, South Africa and other countries. The most affected sectors are technology, manufacturing, and education.
This is not an indiscriminate attack: the 4,532 unique email domains suggest targeted targeting of specific organizations, with a concentration on US and European companies. The variety of sectors and geographic areas indicates a broad and persistent campaign.
Consequences: Stolen Sessions and SSO Access
The damage is not limited to credential theft. With stolen session cookies and passwords, attackers access corporate email inboxes, trusted accounts, and sensitive data using already authenticated sessions. Single sign-on access extends the danger to connected applications, internal workflows, and cloud services integrated with Microsoft 365.
Compromise creates risks of impersonation, fraud, and further internal attacks. A hijacked session is harder to detect and block than a suspicious login with stolen credentials: the legitimate user appears authenticated normally while the attacker operates in parallel. Containment costs increase because the perimeter to clean up is not a single account but every connected SSO service.
Mitigations: Treat Session Theft as an Identity Incident
Countermeasures require a change in perspective. The first step is to immediately revoke compromised sessions and tokens and launch an investigation into the affected identity. Password reset alone is not enough: if the session cookie is still valid, the attacker retains access even after credential change.
Phishing-resistant authentication should be adopted, going beyond traditional MFA based on codes or push notifications. More rigorous session controls are needed, such as limiting token lifetime and monitoring for anomalous activities. The goal is to reduce the value of a stolen cookie and make it harder for the attacker to reuse an intercepted session.
Detection: Interactive Sandbox and Threat Intelligence
To catch the campaign before compromise, ANY.RUN's interactive sandbox isolates suspicious attachments and URLs and exposes the attack steps: redirects to fake Microsoft 365 login pages, scripts, WebSocket activity. According to the vendor, the platform detects threats in 14 seconds and reduces mean time to respond (MTTR) by 21 minutes per case.
The investigation should not stop at individual indicators of compromise. Recurring loaders, encoded data, and suspicious WebSocket activity can reveal connections to the campaign even when the attacker infrastructure changes. Real-time threat intelligence feeds provide updated indicators, while the Threat Intelligence Lookup service allows pivoting from suspicious URLs, domains, IPs, and files to related infrastructure, drawing on data from over 16,000 organizations.
Sources
This article is an original reworking based on the sources below.
