Actor Profile

Mirage2FA is a commercial phishing-as-a-service (PhaaS) campaign active from 2024 to 2026, targeting Microsoft 365 accounts through adversary-in-the-middle (AiTM) techniques. The campaign leverages a toolkit designed to abuse legitimate Microsoft 365 login flows and bypass two-factor authentication by stealing session cookies and passwords. The operation has affected approximately 4,532 unique organizational email domains, with 63.7% of victims located in the United States. The campaign's commercial nature suggests it is operated as a service available to multiple threat actors, enabling widespread credential harvesting and session hijacking attacks. Motivation centers on gaining authenticated access to corporate Microsoft 365 environments and SSO-connected services for follow-on fraud, impersonation, and data theft.

TTPs (Tactics, Techniques, Procedures)

The Mirage2FA campaign employs adversary-in-the-middle (AiTM) phishing techniques to intercept Microsoft 365 authentication flows. Key TTPs include: credential harvesting through fake Microsoft 365 login pages presented via phishing emails; session cookie theft to hijack authenticated sessions and bypass MFA (T1539: Steal Web Session Cookie); abuse of legitimate login flows and WebSocket activity to proxy authentication requests; SSO exploitation to pivot to connected applications; and use of redirects, encoded data, and suspicious loaders to evade detection. The campaign demonstrates T1566 (Phishing) for initial access, T1078 (Valid Accounts) for persistence via stolen credentials, and T1550.004 (Use Alternate Authentication Material: Web Session Cookie) to maintain access without triggering MFA prompts. Over 9,000 potential compromise events involving password theft, cookie exfiltration, and 2FA bypass have been documented.

Targets & Patterns

Mirage2FA primarily targets technology, manufacturing, and education sectors, with enterprise services organizations also heavily affected. Geographic targeting shows strong focus on the United States (63.7% of victims), with additional activity observed in India, Singapore, United Kingdom, Canada, Saudi Arabia, South Africa, and across the European Union. The campaign targets organizations using Microsoft 365 for corporate email and authentication, particularly those with SSO implementations that expand the attack surface once initial access is gained. The selection pattern suggests opportunistic targeting of organizations with valuable business email compromise (BEC) potential and access to sensitive corporate data. ANY.RUN research indicates 48% of targeted email addresses were potentially compromised, demonstrating high success rates. The focus on enterprise environments with SSO connectivity allows attackers to pivot beyond the initial compromised account to access multiple connected services and internal workflows.

Historical Context

The Mirage2FA campaign represents an evolution in phishing-as-a-service operations, operating continuously from 2024 through 2026 according to ANY.RUN research. The campaign's longevity and scale (4,532 affected organizations) indicate sustained infrastructure investment and operational success. The use of AiTM techniques to bypass MFA reflects broader industry trends where traditional two-factor authentication is increasingly targeted through session hijacking rather than direct credential compromise. The commercial PhaaS model suggests Mirage2FA infrastructure is available to multiple customers or affiliate threat actors, similar to other commoditized attack platforms. The campaign's focus on Microsoft 365 aligns with the platform's widespread enterprise adoption and the high value of corporate email access for business email compromise and fraud operations.

Defensive Recommendations

  • Deploy phishing-resistant authentication methods such as FIDO2/WebAuthn hardware tokens or certificate-based authentication that cannot be proxied by AiTM attacks, moving beyond traditional SMS or app-based MFA
  • Implement continuous session validation and conditional access policies in Microsoft 365 that monitor for anomalous login locations, device compliance, and session characteristics to detect hijacked sessions (T1539)
  • Integrate sandbox analysis tools to detonate suspicious URLs and attachments in isolation, identifying fake Microsoft 365 login pages, WebSocket activity, redirects, and encoded phishing infrastructure before user interaction
  • Treat session theft as an identity incident requiring immediate token and session revocation across all SSO-connected services, rather than relying solely on password resets which do not invalidate stolen session cookies
  • Monitor for indicators of AiTM phishing infrastructure including suspicious redirects to non-Microsoft domains, WebSocket connections during authentication flows, and URL patterns associated with Mirage2FA loaders and encoded data payloads

---

# Geopolitical Context

Geopolitical Context

The Mirage2FA campaign represents a significant evolution in the commercialization of cyber offensive capabilities through phishing-as-a-service (PhaaS) models. Operating from 2024 through 2026, this campaign demonstrates how commoditized toolkits enable persistent, large-scale attacks against Western corporate infrastructure without requiring sophisticated technical expertise from end users. The targeting pattern—with 63.7% of victims US-based and substantial activity across EU member states, India, Singapore, the UK, Canada, and Saudi Arabia—suggests either a broad customer base for the PhaaS toolkit or coordinated campaigns by multiple threat actors leveraging the same commercial infrastructure. The focus on Microsoft 365 environments reflects the strategic value of cloud identity systems as attack surfaces, particularly given their role as authentication gateways to broader enterprise ecosystems through single sign-on integrations. The campaign's scale and geographic distribution indicate that PhaaS platforms now pose systemic risks to transatlantic digital infrastructure, complicating attribution and response efforts while enabling threat actors with varying capabilities to conduct sophisticated adversary-in-the-middle attacks.

State Actor Alignment

No state actor attribution is provided in available reporting. The commercial phishing-as-a-service model suggests a profit-motivated cybercriminal operation rather than state-sponsored activity, though such toolkits may be accessible to or leveraged by state-aligned actors. The ANY.RUN research does not link Mirage2FA to any specific nation-state threat group or government-backed entity. The campaign's broad targeting across multiple allied and non-aligned nations—including US, EU, India, Singapore, UK, Canada, Saudi Arabia, and South Africa—does not exhibit the focused targeting patterns typically associated with espionage or strategic intelligence collection operations. However, the compromise of enterprise Microsoft 365 environments and SSO-connected services could provide access vectors that may be of interest to state actors seeking corporate intelligence or supply chain positioning. Without further technical indicators or operational tradecraft analysis, the campaign appears consistent with financially motivated cybercrime rather than geopolitically directed operations.

Business Impacty pro region

The Mirage2FA campaign poses significant implications for transatlantic digital security cooperation and enterprise resilience. With nearly two-thirds of victims located in the United States and substantial EU exposure, the campaign highlights vulnerabilities in cloud identity infrastructure that underpins critical business operations across NATO allies and partner nations. The 48% potential compromise rate among targeted organizations suggests widespread exposure of corporate communications, intellectual property, and business relationships that could affect supply chain integrity and competitive positioning for Western firms. For European organizations, the campaign intersects with GDPR compliance obligations and NIS2 Directive requirements, as compromised Microsoft 365 sessions may expose personal data and critical service operations. The targeting of technology, manufacturing, and education sectors—industries central to innovation ecosystems and economic competitiveness—raises concerns about long-term impacts on Western technological leadership. The campaign's reach into Singapore, India, and Saudi Arabia also suggests potential exposure of organizations operating in strategic technology partnerships and defense industrial base relationships with Western allies, creating potential vectors for secondary compromise or intelligence collection against allied interests.

Forecast

If the Mirage2FA phishing-as-a-service toolkit remains commercially available and operationally effective, similar campaigns targeting cloud identity platforms are likely to persist and potentially expand in scope. Organizations that fail to implement phishing-resistant authentication mechanisms beyond traditional MFA may continue to experience elevated compromise rates, particularly if session management controls remain inadequate. Should law enforcement or private sector disruption efforts successfully dismantle Mirage2FA infrastructure, competing PhaaS platforms may emerge to fill the operational gap, sustaining the threat landscape. If compromised Microsoft 365 sessions are leveraged for follow-on attacks such as business email compromise, ransomware deployment, or supply chain infiltration, the economic and security impacts may escalate significantly over the coming months. Regulatory responses in the EU and US may accelerate requirements for stronger authentication standards and incident reporting if the campaign's impacts become more widely documented. If threat intelligence sharing improves among affected organizations and security vendors, detection and response timelines may improve, potentially reducing the campaign's effectiveness and forcing operational adaptations by threat actors.