← All articles

Mirage2FA phishing service hijacks Microsoft 365 sessions and bypasses two-factor

A commercial phishing-as-a-service toolkit called Mirage2FA has hit around 4,500 organizations by abusing legitimate Microsoft 365 login flows to steal passwords and session cookies and bypass two-factor authentication. Because it captures the session cookie after a real login completes, the attacker inherits an authenticated Microsoft 365 session and any single-sign-on connected services, defeating multi-factor authentication. Researchers at ANY.RUN linked the campaign to more than 9,000 potential compromise events and found that nearly half of targeted addresses may have been affected, with most victims in the United States across technology, manufacturing, and education. Hijacking one session can expand into connected apps and internal workflows.

Check
Move toward phishing-resistant authentication such as passkeys or hardware security keys, since attacker-in-the-middle kits like this defeat ordinary two-factor by stealing the session after login.
Affected
Microsoft 365 organizations relying on passwords plus standard two-factor authentication; Mirage2FA steals the post-login session cookie to hijack authenticated sessions and single-sign-on services, extending access well beyond the first account.
Fix
Adopt phishing-resistant multi-factor authentication, shorten session lifetimes and bind sessions to devices, monitor for anomalous token use and impossible-travel sign-ins, and revoke sessions on suspicion rather than trusting a successful login.