Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Mirage2FA Hijacks Companies’ Microsoft 365 Sessions, with Over 4K Victims in the US

0
Medium
Published: 08/18/2026 (08/18/2026, 20:48:20 UTC)
Source: AlienVault OTX General

Description

Mirage2FA is an active phishing-as-a-service toolkit built to steal Microsoft 365 credentials and authenticated sessions through Adversary-in-the-Middle attacks. Analysis shows 63.7% of identified victims are in the US, with Technology, Manufacturing, and Education among the most targeted industries. The operation generated thousands of compromise events between 2024 and 2026, including stolen session cookies, passwords, and SSO access. Once a Microsoft 365 session is hijacked, attackers gain access to corporate email, sensitive data, and trusted business accounts. The toolkit uses browser-based delivery through .htm, .xhtml, and .svg stagers, QR codes, JavaScript obfuscation, and WebSocket-based AiTM activity. Of 9,426 unique targeted email addresses, 4,532 were potentially compromised, representing approximately 48% success rate.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/19/2026, 10:50:54 UTC

Technical Analysis

Mirage2FA is an active phishing-as-a-service operation that hijacks Microsoft 365 sessions by conducting Adversary-in-the-Middle attacks to steal credentials and authenticated session tokens. It employs browser-based delivery methods such as .htm, .xhtml, and .svg stagers, QR codes, JavaScript obfuscation, and WebSocket-based communication to evade detection and bypass two-factor authentication. Analysis shows that 63.7% of victims are located in the US, with significant targeting of Technology, Manufacturing, and Education sectors. Between 2024 and 2026, the campaign generated thousands of compromise events, successfully compromising 4,532 out of 9,426 targeted email addresses, representing a 48% success rate. The attackers gain access to corporate email accounts, sensitive data, and trusted business resources once sessions are hijacked.

Potential Impact

Successful exploitation results in theft of Microsoft 365 credentials and session cookies, allowing attackers to bypass two-factor authentication and gain unauthorized access to corporate email, sensitive data, and trusted business accounts. This compromises confidentiality and integrity of corporate communications and data. The campaign has affected thousands of users, primarily in the US, across multiple industries.

Defensive Guidance

No official patch or fix is applicable as this is a phishing campaign targeting user credentials and sessions. Organizations should focus on user awareness training to recognize phishing attempts, implement strong multi-factor authentication methods resistant to session hijacking, and monitor for suspicious login activity. Since this is a phishing-as-a-service operation, endpoint protections and email filtering can help reduce exposure. Vendor-managed remediation is not applicable as this is not a software vulnerability.

Affected Countries

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Author
AlienVault
Tlp
white
References
["https://any.run/cybersecurity-blog/mirage2fa-phishing-targets-us-companies/"]
Adversary
LinX Coders
Pulse Id
6a84c514863d37cbadb72833
Threat Score
null

Indicators of Compromise

Ip

ValueDescriptionCopy
ip192.52.166.55
ip209.205.197.130
ip181.214.165.173
ip83.147.53.130
ip209.205.192.6
ip139.28.36.38
ip98.144.204.109

Domain

ValueDescriptionCopy
domaingalatasaraydanhaberler.com
domainsopbtech.store
domainoffice.pcvgtech.store
domainver.verpox.shop
domaincementslabconstruction.com
domainadp.pslcertlive.site
domainans.rsxbenefits.com
domainari.vslbertlive.info
domainars.greebys.com
domainasvbtech.store
domainavsbtech.store
domainbezdelz.store
domainbns.baseasix.com
domainbsf.allmetreod.com
domainbverster.store
domaincer.septey.shop
domaincer.verpox.shop
domaincureaveritax.store
domaincvs.pcvgtech.online
domaindezbelz.store
domaindverster.store
domaineverster.store
domainfureaveritax.store
domainfverster.store
domaingacorslot7d.com
domaingectech.store
domaingverster.store
domainhpn.bandhiem.com
domainhverster.store
domainhynutech.store
domainimplentedgucedirectory.com
domainintrugementslayerdocuservice.com
domainiverster.store
domainjscvbtech.store
domainjureaveritax.store
domainjverster.store
domainmettsoll.com
domainoectech.store
domainoffice.avcbtech.store
domainpancincorp.com
domainpavetech.store
domainpectech.store
domainpezbelz.store
domainpureaveritax.store
domainpvf.schwiessdoors.com
domainpvs.schwiessdoors.com
domainpxvbtech.store
domainpynutech.store
domainrfm.m3-bulders.com
domainrmf.diversesgs.com
domainrmf.m3-bulders.com
domainsvn.dpsindustrialsgroup.com
domainsvr.schwiessdoors.com
domainvezbelz.store
domainvns.pigotnet.com
domainvns.tvgsv.com
domainvns1.pigotnet.com
domainvrf.atskinsonel.com
domainvrf.gavernova.com
domainvrf.iar0nline.com
domainwectech.store
domainwes.cadsta.online
domainzectech.store
domainuser.cheacker.store
domainhvr.volatilesour.store
domainver.bandhiem.com
domaincheacker.store
domainvolatilesour.store

Threat ID: 6a857fb9c6e8be03328363b6

Added to database: 08/19/2026, 10:04:41 UTC

Last enriched: 08/19/2026, 10:50:54 UTC

Last updated: 08/19/2026, 11:16:13 UTC

Views: 7

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses