Detect It Early: Mir0Auth Uses Obfuscated Network Logic for M365 Token Access
Mir0Auth is a phishing toolkit targeting Microsoft 365 authentication tokens. It uses a multi-step phishing flow starting with a business email lure and a PDF attachment leading to a DocuSign-themed page. Victims are redirected to a legitimate Microsoft Device Code authentication page, allowing attackers to obtain M365 tokens. The toolkit employs obfuscated network communication using XOR encoding for command-and-control URLs and payloads. Primary activity has been observed against US organizations.
AI Analysis
Technical Summary
Mir0Auth is a phishing kit designed to steal Microsoft 365 authentication tokens by leveraging a multi-stage attack chain. The attack begins with a phishing email containing a PDF that leads to a DocuSign-themed landing page. This page then redirects victims to a legitimate Microsoft Device Code authentication page (microsoft.com/devicelogin) in a popup, where the victim signs in. Meanwhile, Mir0Auth manages session state and communication through source-code-like endpoints (/task_queue.cs, /context.go, /window.rs) with obfuscated network traffic using XOR encoding for both URLs and JSON payloads. The attacker’s session receives the M365 tokens after victim authentication. The campaign has been primarily observed targeting organizations in the United States.
Potential Impact
Successful exploitation results in attackers obtaining valid Microsoft 365 authentication tokens, potentially allowing unauthorized access to victim M365 accounts and associated resources. This can lead to data theft, account compromise, and further lateral movement within targeted organizations. The use of legitimate Microsoft authentication pages may increase the likelihood of victim trust and successful credential theft.
Mitigation Recommendations
No official patch or fix is applicable as this is a phishing campaign rather than a software vulnerability. Organizations should focus on user awareness training to recognize phishing lures, implement multi-factor authentication (MFA) for Microsoft 365 accounts, and monitor for suspicious authentication activity. Blocking or monitoring the identified obfuscated endpoints and network patterns may aid detection. Since this is an active phishing kit, proactive threat intelligence subscription and IOC tracking are recommended.
Affected Countries
United States
Detect It Early: Mir0Auth Uses Obfuscated Network Logic for M365 Token Access
Description
Mir0Auth is a phishing toolkit targeting Microsoft 365 authentication tokens. It uses a multi-step phishing flow starting with a business email lure and a PDF attachment leading to a DocuSign-themed page. Victims are redirected to a legitimate Microsoft Device Code authentication page, allowing attackers to obtain M365 tokens. The toolkit employs obfuscated network communication using XOR encoding for command-and-control URLs and payloads. Primary activity has been observed against US organizations.
Reddit Discussion
We identified Mir0Auth, a new phishkit targeting M365 auth tokens, with primary activity observed against US organizations. A business email lure with an attached PDF leads to a DocuSign-themed page, then to legitimate Microsoft Device Code authentication, where the attacker’s session obtains M365 tokens.
Mir0Auth uses source-code-like endpoints, including /task_queue.cs, /context.go, and /window.rs, to manage the flow and session state.
See the analysis session: https://app.any.run/tasks/a1553640-c0f5-4d33-a535-36e13dd22f5f/
Network chain:
Phishing page ➡️ POST /task_queue.cs beacon ➡️ POST /context.go returns a device code ➡️ the code is copied to the clipboard, and the legitimate Microsoft sign-in page at microsoft[.]com/devicelogin opens in a popup ➡️ /window.rs session polling every 3s ➡️ victim signs in ➡️ attacker session receives M365 tokens
Traffic obfuscation:
– C2 URLs are hex strings XORed with MiroAuth
– C2 bodies are JSON XORed with M1r0AuthBinProT0c0l_2024!
– Data is sent as raw application/octet-stream; responses use the same key
Pivot from IOCs and subscribe to query updates to proactively track evolving activity.
Links cited in this discussion
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Mir0Auth is a phishing kit designed to steal Microsoft 365 authentication tokens by leveraging a multi-stage attack chain. The attack begins with a phishing email containing a PDF that leads to a DocuSign-themed landing page. This page then redirects victims to a legitimate Microsoft Device Code authentication page (microsoft.com/devicelogin) in a popup, where the victim signs in. Meanwhile, Mir0Auth manages session state and communication through source-code-like endpoints (/task_queue.cs, /context.go, /window.rs) with obfuscated network traffic using XOR encoding for both URLs and JSON payloads. The attacker’s session receives the M365 tokens after victim authentication. The campaign has been primarily observed targeting organizations in the United States.
Potential Impact
Successful exploitation results in attackers obtaining valid Microsoft 365 authentication tokens, potentially allowing unauthorized access to victim M365 accounts and associated resources. This can lead to data theft, account compromise, and further lateral movement within targeted organizations. The use of legitimate Microsoft authentication pages may increase the likelihood of victim trust and successful credential theft.
Defensive Guidance
No official patch or fix is applicable as this is a phishing campaign rather than a software vulnerability. Organizations should focus on user awareness training to recognize phishing lures, implement multi-factor authentication (MFA) for Microsoft 365 accounts, and monitor for suspicious authentication activity. Blocking or monitoring the identified obfuscated endpoints and network patterns may aid detection. Since this is an active phishing kit, proactive threat intelligence subscription and IOC tracking are recommended.
Affected Countries
Technical Details
- Source Type
- Subreddit
- ThreatIntelligence+threatintel+websecurityresearch
- Reddit Score
- 0
- Discussion Level
- minimal
- Content Source
- reddit_link_post
- Post Type
- link
- Newsworthiness Assessment
- {"score":35,"reasons":["external_link","established_author","recent_news"],"isNewsworthy":true}
- Has External Source
- true
- Trusted Domain
- false
Threat ID: 6abda3352a4e24523dc7ff94
Added to database: 10/01/2026, 00:03:01 UTC
Last enriched: 10/01/2026, 00:03:06 UTC
Last updated: 10/01/2026, 04:47:53 UTC
Views: 17
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.