Mirage2FA Hijacks Companies’ Microsoft 365 Sessions, with Over 4K Victims in the US
Mirage2FA is an active phishing-as-a-service toolkit built to steal Microsoft 365 credentials and authenticated sessions through Adversary-in-the-Middle attacks. Analysis shows 63.7% of identified victims are in the US, with Technology, Manufacturing, and Education among the most targeted industries. The operation generated thousands of compromise events between 2024 and 2026, including stolen session cookies, passwords, and SSO access. Once a Microsoft 365 session is hijacked, attackers gain access to corporate email, sensitive data, and trusted business accounts. The toolkit uses browser-based delivery through .htm, .xhtml, and .svg stagers, QR codes, JavaScript obfuscation, and WebSocket-based AiTM activity. Of 9,426 unique targeted email addresses, 4,532 were potentially compromised, representing approximately 48% success rate.
AI Analysis
Technical Summary
Mirage2FA is an active phishing-as-a-service toolkit designed to hijack Microsoft 365 sessions by stealing credentials and authenticated session cookies through Adversary-in-the-Middle (AiTM) attacks. It employs browser-based delivery techniques such as .htm, .xhtml, and .svg stagers, QR codes, JavaScript obfuscation, and WebSocket communication to evade detection and bypass two-factor authentication. Analysis indicates that 63.7% of victims are located in the United States, with Technology, Manufacturing, and Education sectors being the most targeted. Between 2024 and 2026, the operation generated thousands of compromise events, with a reported success rate of about 48% from 9,426 targeted email addresses, resulting in 4,532 potential compromises. Once sessions are hijacked, attackers gain unauthorized access to corporate email accounts, sensitive data, and trusted business resources.
Potential Impact
The campaign enables attackers to bypass Microsoft 365 two-factor authentication and hijack authenticated sessions, granting access to corporate email, sensitive data, and trusted business accounts. This can lead to data breaches, unauthorized actions within compromised accounts, and potential lateral movement within affected organizations. The high success rate and targeting of critical industries increase the risk of significant operational and reputational damage.
Mitigation Recommendations
No official patch or fix is applicable as this is a phishing campaign exploiting user interaction and session hijacking techniques. Organizations should focus on user awareness training to recognize phishing attempts, implement additional security controls such as conditional access policies, and monitor for suspicious login activity. Since this is a phishing-as-a-service campaign, technical mitigations should include enforcing modern authentication protocols, using hardware-based MFA tokens resistant to AiTM attacks, and employing email filtering solutions to detect and block phishing emails. Vendor advisories do not indicate any direct patch availability for this threat.
Affected Countries
United States
Indicators of Compromise
- ip: 192.52.166.55
- ip: 209.205.197.130
- domain: galatasaraydanhaberler.com
- ip: 181.214.165.173
- ip: 83.147.53.130
- domain: sopbtech.store
- domain: office.pcvgtech.store
- domain: ver.verpox.shop
- domain: cementslabconstruction.com
- domain: adp.pslcertlive.site
- domain: ans.rsxbenefits.com
- domain: ari.vslbertlive.info
- domain: ars.greebys.com
- domain: asvbtech.store
- domain: avsbtech.store
- domain: bezdelz.store
- domain: bns.baseasix.com
- domain: bsf.allmetreod.com
- domain: bverster.store
- domain: cer.septey.shop
- domain: cer.verpox.shop
- domain: cureaveritax.store
- domain: cvs.pcvgtech.online
- domain: dezbelz.store
- domain: dverster.store
- domain: everster.store
- domain: fureaveritax.store
- domain: fverster.store
- domain: gacorslot7d.com
- domain: gectech.store
- domain: gverster.store
- domain: hpn.bandhiem.com
- domain: hverster.store
- domain: hynutech.store
- domain: implentedgucedirectory.com
- domain: intrugementslayerdocuservice.com
- domain: iverster.store
- domain: jscvbtech.store
- domain: jureaveritax.store
- domain: jverster.store
- domain: mettsoll.com
- domain: oectech.store
- domain: office.avcbtech.store
- domain: pancincorp.com
- domain: pavetech.store
- domain: pectech.store
- domain: pezbelz.store
- domain: pureaveritax.store
- domain: pvf.schwiessdoors.com
- domain: pvs.schwiessdoors.com
- domain: pxvbtech.store
- domain: pynutech.store
- domain: rfm.m3-bulders.com
- domain: rmf.diversesgs.com
- domain: rmf.m3-bulders.com
- domain: svn.dpsindustrialsgroup.com
- domain: svr.schwiessdoors.com
- domain: vezbelz.store
- domain: vns.pigotnet.com
- domain: vns.tvgsv.com
- domain: vns1.pigotnet.com
- domain: vrf.atskinsonel.com
- domain: vrf.gavernova.com
- domain: vrf.iar0nline.com
- domain: wectech.store
- domain: wes.cadsta.online
- domain: zectech.store
- domain: user.cheacker.store
- domain: hvr.volatilesour.store
- domain: ver.bandhiem.com
- ip: 209.205.192.6
- ip: 139.28.36.38
- ip: 98.144.204.109
- domain: cheacker.store
- domain: volatilesour.store
Mirage2FA Hijacks Companies’ Microsoft 365 Sessions, with Over 4K Victims in the US
Description
Mirage2FA is an active phishing-as-a-service toolkit built to steal Microsoft 365 credentials and authenticated sessions through Adversary-in-the-Middle attacks. Analysis shows 63.7% of identified victims are in the US, with Technology, Manufacturing, and Education among the most targeted industries. The operation generated thousands of compromise events between 2024 and 2026, including stolen session cookies, passwords, and SSO access. Once a Microsoft 365 session is hijacked, attackers gain access to corporate email, sensitive data, and trusted business accounts. The toolkit uses browser-based delivery through .htm, .xhtml, and .svg stagers, QR codes, JavaScript obfuscation, and WebSocket-based AiTM activity. Of 9,426 unique targeted email addresses, 4,532 were potentially compromised, representing approximately 48% success rate.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Mirage2FA is an active phishing-as-a-service toolkit designed to hijack Microsoft 365 sessions by stealing credentials and authenticated session cookies through Adversary-in-the-Middle (AiTM) attacks. It employs browser-based delivery techniques such as .htm, .xhtml, and .svg stagers, QR codes, JavaScript obfuscation, and WebSocket communication to evade detection and bypass two-factor authentication. Analysis indicates that 63.7% of victims are located in the United States, with Technology, Manufacturing, and Education sectors being the most targeted. Between 2024 and 2026, the operation generated thousands of compromise events, with a reported success rate of about 48% from 9,426 targeted email addresses, resulting in 4,532 potential compromises. Once sessions are hijacked, attackers gain unauthorized access to corporate email accounts, sensitive data, and trusted business resources.
Potential Impact
The campaign enables attackers to bypass Microsoft 365 two-factor authentication and hijack authenticated sessions, granting access to corporate email, sensitive data, and trusted business accounts. This can lead to data breaches, unauthorized actions within compromised accounts, and potential lateral movement within affected organizations. The high success rate and targeting of critical industries increase the risk of significant operational and reputational damage.
Defensive Guidance
No official patch or fix is applicable as this is a phishing campaign exploiting user interaction and session hijacking techniques. Organizations should focus on user awareness training to recognize phishing attempts, implement additional security controls such as conditional access policies, and monitor for suspicious login activity. Since this is a phishing-as-a-service campaign, technical mitigations should include enforcing modern authentication protocols, using hardware-based MFA tokens resistant to AiTM attacks, and employing email filtering solutions to detect and block phishing emails. Vendor advisories do not indicate any direct patch availability for this threat.
Affected Countries
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://any.run/cybersecurity-blog/mirage2fa-phishing-targets-us-companies/"]
- Adversary
- LinX Coders
- Pulse Id
- 6a84c514863d37cbadb72833
Indicators of Compromise
Ip
| Value | Description | Copy |
|---|---|---|
ip192.52.166.55 | — | |
ip209.205.197.130 | — | |
ip181.214.165.173 | — | |
ip83.147.53.130 | — | |
ip209.205.192.6 | — | |
ip139.28.36.38 | — | |
ip98.144.204.109 | — |
Domain
| Value | Description | Copy |
|---|---|---|
domaingalatasaraydanhaberler.com | — | |
domainsopbtech.store | — | |
domainoffice.pcvgtech.store | — | |
domainver.verpox.shop | — | |
domaincementslabconstruction.com | — | |
domainadp.pslcertlive.site | — | |
domainans.rsxbenefits.com | — | |
domainari.vslbertlive.info | — | |
domainars.greebys.com | — | |
domainasvbtech.store | — | |
domainavsbtech.store | — | |
domainbezdelz.store | — | |
domainbns.baseasix.com | — | |
domainbsf.allmetreod.com | — | |
domainbverster.store | — | |
domaincer.septey.shop | — | |
domaincer.verpox.shop | — | |
domaincureaveritax.store | — | |
domaincvs.pcvgtech.online | — | |
domaindezbelz.store | — | |
domaindverster.store | — | |
domaineverster.store | — | |
domainfureaveritax.store | — | |
domainfverster.store | — | |
domaingacorslot7d.com | — | |
domaingectech.store | — | |
domaingverster.store | — | |
domainhpn.bandhiem.com | — | |
domainhverster.store | — | |
domainhynutech.store | — | |
domainimplentedgucedirectory.com | — | |
domainintrugementslayerdocuservice.com | — | |
domainiverster.store | — | |
domainjscvbtech.store | — | |
domainjureaveritax.store | — | |
domainjverster.store | — | |
domainmettsoll.com | — | |
domainoectech.store | — | |
domainoffice.avcbtech.store | — | |
domainpancincorp.com | — | |
domainpavetech.store | — | |
domainpectech.store | — | |
domainpezbelz.store | — | |
domainpureaveritax.store | — | |
domainpvf.schwiessdoors.com | — | |
domainpvs.schwiessdoors.com | — | |
domainpxvbtech.store | — | |
domainpynutech.store | — | |
domainrfm.m3-bulders.com | — | |
domainrmf.diversesgs.com | — | |
domainrmf.m3-bulders.com | — | |
domainsvn.dpsindustrialsgroup.com | — | |
domainsvr.schwiessdoors.com | — | |
domainvezbelz.store | — | |
domainvns.pigotnet.com | — | |
domainvns.tvgsv.com | — | |
domainvns1.pigotnet.com | — | |
domainvrf.atskinsonel.com | — | |
domainvrf.gavernova.com | — | |
domainvrf.iar0nline.com | — | |
domainwectech.store | — | |
domainwes.cadsta.online | — | |
domainzectech.store | — | |
domainuser.cheacker.store | — | |
domainhvr.volatilesour.store | — | |
domainver.bandhiem.com | — | |
domaincheacker.store | — | |
domainvolatilesour.store | — |
Threat ID: 6a857fb9c6e8be03328363b6
Added to database: 08/19/2026, 10:04:41 UTC
Last enriched: 09/18/2026, 22:02:12 UTC
Last updated: 10/02/2026, 13:50:44 UTC
Views: 234
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.