Skip to main content

Detect It Early: Mir0Auth Uses Obfuscated Network Logic for M365 Token Access

0
Medium
Published: 09/30/2026 (09/30/2026, 14:28:55 UTC)
Source: Reddit ThreatIntel

Description

Mir0Auth is a phishing toolkit targeting Microsoft 365 authentication tokens. It uses a multi-step phishing flow starting with a business email lure and a PDF attachment leading to a DocuSign-themed page. Victims are redirected to a legitimate Microsoft Device Code authentication page, allowing attackers to obtain M365 tokens. The toolkit employs obfuscated network communication using XOR encoding for command-and-control URLs and payloads. Primary activity has been observed against US organizations.

Reddit Discussion

r/threatintel·posted by u/ANYRUN-team
00

We identified Mir0Auth, a new phishkit targeting M365 auth tokens, with primary activity observed against US organizations. A business email lure with an attached PDF leads to a DocuSign-themed page, then to legitimate Microsoft Device Code authentication, where the attacker’s session obtains M365 tokens.

Mir0Auth uses source-code-like endpoints, including /task_queue.cs, /context.go, and /window.rs, to manage the flow and session state.

See the analysis session: https://app.any.run/tasks/a1553640-c0f5-4d33-a535-36e13dd22f5f/

Network chain:

Phishing page ➡️ POST /task_queue.cs beacon ➡️ POST /context.go returns a device code ➡️ the code is copied to the clipboard, and the legitimate Microsoft sign-in page at microsoft[.]com/devicelogin opens in a popup ➡️ /window.rs session polling every 3s ➡️ victim signs in ➡️ attacker session receives M365 tokens

Traffic obfuscation:

– C2 URLs are hex strings XORed with MiroAuth
– C2 bodies are JSON XORed with M1r0AuthBinProT0c0l_2024!
– Data is sent as raw application/octet-stream; responses use the same key

Pivot from IOCs and subscribe to query updates to proactively track evolving activity.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 10/01/2026, 00:03:06 UTC

Technical Analysis

Mir0Auth is a phishing kit designed to steal Microsoft 365 authentication tokens by leveraging a multi-stage attack chain. The attack begins with a phishing email containing a PDF that leads to a DocuSign-themed landing page. This page then redirects victims to a legitimate Microsoft Device Code authentication page (microsoft.com/devicelogin) in a popup, where the victim signs in. Meanwhile, Mir0Auth manages session state and communication through source-code-like endpoints (/task_queue.cs, /context.go, /window.rs) with obfuscated network traffic using XOR encoding for both URLs and JSON payloads. The attacker’s session receives the M365 tokens after victim authentication. The campaign has been primarily observed targeting organizations in the United States.

Potential Impact

Successful exploitation results in attackers obtaining valid Microsoft 365 authentication tokens, potentially allowing unauthorized access to victim M365 accounts and associated resources. This can lead to data theft, account compromise, and further lateral movement within targeted organizations. The use of legitimate Microsoft authentication pages may increase the likelihood of victim trust and successful credential theft.

Defensive Guidance

No official patch or fix is applicable as this is a phishing campaign rather than a software vulnerability. Organizations should focus on user awareness training to recognize phishing lures, implement multi-factor authentication (MFA) for Microsoft 365 accounts, and monitor for suspicious authentication activity. Blocking or monitoring the identified obfuscated endpoints and network patterns may aid detection. Since this is an active phishing kit, proactive threat intelligence subscription and IOC tracking are recommended.

Affected Countries

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Source Type
reddit
Subreddit
ThreatIntelligence+threatintel+websecurityresearch
Reddit Score
0
Discussion Level
minimal
Content Source
reddit_link_post
Post Type
link
Newsworthiness Assessment
{"score":35,"reasons":["external_link","established_author","recent_news"],"isNewsworthy":true}
Has External Source
true
Trusted Domain
false

Threat ID: 6abda3352a4e24523dc7ff94

Added to database: 10/01/2026, 00:03:01 UTC

Last enriched: 10/01/2026, 00:03:06 UTC

Last updated: 10/01/2026, 04:47:53 UTC

Views: 17

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses