Skip to main content

Mirage2FA Hijacks Companies’ Microsoft 365 Sessions, with Over 4K Victims in the US

0
Medium
Published: 08/18/2026 (08/18/2026, 20:48:20 UTC)
Source: AlienVault OTX General

Description

Mirage2FA is an active phishing-as-a-service toolkit built to steal Microsoft 365 credentials and authenticated sessions through Adversary-in-the-Middle attacks. Analysis shows 63.7% of identified victims are in the US, with Technology, Manufacturing, and Education among the most targeted industries. The operation generated thousands of compromise events between 2024 and 2026, including stolen session cookies, passwords, and SSO access. Once a Microsoft 365 session is hijacked, attackers gain access to corporate email, sensitive data, and trusted business accounts. The toolkit uses browser-based delivery through .htm, .xhtml, and .svg stagers, QR codes, JavaScript obfuscation, and WebSocket-based AiTM activity. Of 9,426 unique targeted email addresses, 4,532 were potentially compromised, representing approximately 48% success rate.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/18/2026, 22:02:12 UTC

Technical Analysis

Mirage2FA is an active phishing-as-a-service toolkit designed to hijack Microsoft 365 sessions by stealing credentials and authenticated session cookies through Adversary-in-the-Middle (AiTM) attacks. It employs browser-based delivery techniques such as .htm, .xhtml, and .svg stagers, QR codes, JavaScript obfuscation, and WebSocket communication to evade detection and bypass two-factor authentication. Analysis indicates that 63.7% of victims are located in the United States, with Technology, Manufacturing, and Education sectors being the most targeted. Between 2024 and 2026, the operation generated thousands of compromise events, with a reported success rate of about 48% from 9,426 targeted email addresses, resulting in 4,532 potential compromises. Once sessions are hijacked, attackers gain unauthorized access to corporate email accounts, sensitive data, and trusted business resources.

Potential Impact

The campaign enables attackers to bypass Microsoft 365 two-factor authentication and hijack authenticated sessions, granting access to corporate email, sensitive data, and trusted business accounts. This can lead to data breaches, unauthorized actions within compromised accounts, and potential lateral movement within affected organizations. The high success rate and targeting of critical industries increase the risk of significant operational and reputational damage.

Defensive Guidance

No official patch or fix is applicable as this is a phishing campaign exploiting user interaction and session hijacking techniques. Organizations should focus on user awareness training to recognize phishing attempts, implement additional security controls such as conditional access policies, and monitor for suspicious login activity. Since this is a phishing-as-a-service campaign, technical mitigations should include enforcing modern authentication protocols, using hardware-based MFA tokens resistant to AiTM attacks, and employing email filtering solutions to detect and block phishing emails. Vendor advisories do not indicate any direct patch availability for this threat.

Affected Countries

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Author
AlienVault
Tlp
white
References
["https://any.run/cybersecurity-blog/mirage2fa-phishing-targets-us-companies/"]
Adversary
LinX Coders
Pulse Id
6a84c514863d37cbadb72833

Indicators of Compromise

Ip

ValueDescriptionCopy
ip192.52.166.55
—
ip209.205.197.130
—
ip181.214.165.173
—
ip83.147.53.130
—
ip209.205.192.6
—
ip139.28.36.38
—
ip98.144.204.109
—

Domain

ValueDescriptionCopy
domaingalatasaraydanhaberler.com
—
domainsopbtech.store
—
domainoffice.pcvgtech.store
—
domainver.verpox.shop
—
domaincementslabconstruction.com
—
domainadp.pslcertlive.site
—
domainans.rsxbenefits.com
—
domainari.vslbertlive.info
—
domainars.greebys.com
—
domainasvbtech.store
—
domainavsbtech.store
—
domainbezdelz.store
—
domainbns.baseasix.com
—
domainbsf.allmetreod.com
—
domainbverster.store
—
domaincer.septey.shop
—
domaincer.verpox.shop
—
domaincureaveritax.store
—
domaincvs.pcvgtech.online
—
domaindezbelz.store
—
domaindverster.store
—
domaineverster.store
—
domainfureaveritax.store
—
domainfverster.store
—
domaingacorslot7d.com
—
domaingectech.store
—
domaingverster.store
—
domainhpn.bandhiem.com
—
domainhverster.store
—
domainhynutech.store
—
domainimplentedgucedirectory.com
—
domainintrugementslayerdocuservice.com
—
domainiverster.store
—
domainjscvbtech.store
—
domainjureaveritax.store
—
domainjverster.store
—
domainmettsoll.com
—
domainoectech.store
—
domainoffice.avcbtech.store
—
domainpancincorp.com
—
domainpavetech.store
—
domainpectech.store
—
domainpezbelz.store
—
domainpureaveritax.store
—
domainpvf.schwiessdoors.com
—
domainpvs.schwiessdoors.com
—
domainpxvbtech.store
—
domainpynutech.store
—
domainrfm.m3-bulders.com
—
domainrmf.diversesgs.com
—
domainrmf.m3-bulders.com
—
domainsvn.dpsindustrialsgroup.com
—
domainsvr.schwiessdoors.com
—
domainvezbelz.store
—
domainvns.pigotnet.com
—
domainvns.tvgsv.com
—
domainvns1.pigotnet.com
—
domainvrf.atskinsonel.com
—
domainvrf.gavernova.com
—
domainvrf.iar0nline.com
—
domainwectech.store
—
domainwes.cadsta.online
—
domainzectech.store
—
domainuser.cheacker.store
—
domainhvr.volatilesour.store
—
domainver.bandhiem.com
—
domaincheacker.store
—
domainvolatilesour.store
—

Threat ID: 6a857fb9c6e8be03328363b6

Added to database: 08/19/2026, 10:04:41 UTC

Last enriched: 09/18/2026, 22:02:12 UTC

Last updated: 10/02/2026, 13:50:44 UTC

Views: 234

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses