Ptechhub
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
PtechHub
No Result
View All Result

Mirage2FA Surge Hits 4,500 US and EU Companies, Abusing Microsoft 365 Login Flows

The Hacker News by The Hacker News
August 25, 2026
Home Cybersecurity
Share on FacebookShare on Twitter


The Hacker NewsAug 25, 2026Phishing / Enterprise Security

Thousands of companies have been affected by the Mirage2FA campaign from 2024 to 2026. The commercial phishing-as-a-service toolkit targets Microsoft 365 accounts by abusing legitimate login flows and bypassing two-factor authentication.

According to ANY.RUN research, 48% of targeted email addresses were potentially compromised. Most of the affected companies are US-based.

Mirage2FA Campaign Scope and Impact

By stealing passwords and session cookies, attackers can gain access to authenticated Microsoft 365 sessions and SSO-connected services. This creates significant identity-related risks for companies, potentially exposing corporate email, trusted business accounts, and other sensitive data.

Once an authenticated Microsoft 365 session is hijacked, a path for impersonation, fraud, and further compromise is created.

Key takeaways about Mirage2FA by ANY.RUN

The campaign has a broad geographic and corporate reach. Apart from the United States accounting for 63.7% of the total victims, Mirage2FA activity was also observed in India, Singapore, the United Kingdom, Canada, Saudi Arabia, South Africa, and other countries. 

Overall, Mirage2FA activity is potentially linked to 4,532 unique organization email domains. Technology, manufacturing, and education were among the most targeted industries.

A major part of the risk for affected companies comes from session theft. ANY.RUN’s research uncovered more than 9,000 potential compromise events involving cookie and password theft, SSO logins, and 2FA bypass.

Findings from ANY.RUN research show how AiTM attacks can exploit gaps in authentication and session management even when two-factor authentication is in place. 

The impact can also extend beyond the initially compromised account. Follow-on access, SSO-connected apps, and other internal workflows can increase the attack radius, further increasing containment costs. 

Another costly factor is that impact goes beyond password theft, as attackers gain access to the corporate environment or Microsoft 365 services through hijacked user sessions, making it harder to take swift measures.

How to Reduce Mirage2FA Risk in Your Company

Organizations can reduce exposure by strengthening authentication, detecting campaign behavior, and treating session theft as an identity incident.

Detect Attacks Earlier with Deeper Analysis

Mirage2FA analysis in ANY.RUN’s Interactive Sandbox

Seamlessly integrating sandboxing into existing workflows helps SOC teams safely investigate suspicious content and identify phishing behavior before it leads to account compromise.

Enterprise Security Tip How ANY.RUN Helps
Analyze suspicious attachments and URLs in isolation. Interactive Sandbox exposes redirects, scripts, WebSocket activity, and fake Microsoft 365 login pages.
Move beyond traditional MFA. Use phishing-resistant authentication and stronger session controls. Sandbox analysis helps identify attacks designed to bypass traditional authentication controls.

These measures help security teams detect Mirage2FA activity earlier, investigate its wider scope, and limit the impact of session theft.

Lower the cost of account compromise with early detection with ANY.RUN.

Detect threats in 14 sec and cut MTTR by 21 mins per case.

Integrate ANY.RUN in your SOC

Uncover the Infrastructure Behind Campaigns

Mirage2FA activity should be investigated beyond individual IOCs. Recurring loaders, encoded data, suspicious WebSocket activity, and related infrastructure can help reveal connections to a wider campaign.

ANY.RUN’s Threat Intelligence Feeds: how they work and what impact they bring

Session theft should be treated as an identity incident. Teams should revoke compromised sessions and tokens and investigate activity tied to the affected identity rather than relying on a password reset alone.

Integration of real-time Threat Intelligence Feeds provides fresh malicious indicators that complement behavioral detections as attacker infrastructure changes. Analysts can then use Threat Intelligence Lookup to pivot from suspicious URLs, domains, IPs, and files to related infrastructure and activity.

Turn isolated IOCs into actionable intelligence backed by threat data from 16,000+ organizations.

Explore ANY.RUN

Conclusion

Mirage2FA shows how phishing has evolved beyond credential theft. By hijacking Microsoft 365 sessions, attackers can bypass conventional MFA and gain access through trusted user identities.

With thousands of organizations affected, particularly in the US, businesses need to prioritize phishing-resistant authentication, behavioral detection, and response procedures designed for session theft.

Found this article interesting? This article is a contributed piece from one of our valued partners. Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.





Source link

The Hacker News

The Hacker News

Next Post

China needs U.S. dollars but is building a hedge against Washington’s sanctions

Recommended.

BUBBA®, MLF Officially Launch SCORETRACKER® LIVE for Consumers While BUBBA® Expands Its Connected Fishing Ecosystem at ICAST 2026

BUBBA®, MLF Officially Launch SCORETRACKER® LIVE for Consumers While BUBBA® Expands Its Connected Fishing Ecosystem at ICAST 2026

July 13, 2026
Elon Musk Seemingly Admits xAI Has Used OpenAI’s Models to Train Its Own

Elon Musk Seemingly Admits xAI Has Used OpenAI’s Models to Train Its Own

April 30, 2026

Trending.

AWS, Google, Oracle, Microsoft Top Gartner’s Cloud AI Infrastructure List For 2026

AWS, Google, Oracle, Microsoft Top Gartner’s Cloud AI Infrastructure List For 2026

July 29, 2026
Cloud Market Share Q1 2026: AWS, Microsoft, Google Battling In AI Era

Cloud Market Share Q1 2026: AWS, Microsoft, Google Battling In AI Era

May 4, 2026
Anthropic lost control of Claude in latest AI cyber blunder | Computer Weekly

Anthropic lost control of Claude in latest AI cyber blunder | Computer Weekly

July 31, 2026
The 50 Coolest Software-Defined Storage Vendors: The 2026 Storage 100

The 50 Coolest Software-Defined Storage Vendors: The 2026 Storage 100

April 13, 2026
IDCA datacentres report: Global concentration and the Goldilocks zone | Computer Weekly

IDCA datacentres report: Global concentration and the Goldilocks zone | Computer Weekly

May 12, 2026

PTechHub

A tech news platform delivering fresh perspectives, critical insights, and in-depth reporting — beyond the buzz. We cover innovation, policy, and digital culture with clarity, independence, and a sharp editorial edge.

Follow Us

Industries

  • AI & ML
  • Cybersecurity
  • Enterprise IT
  • Finance
  • Telco

Navigation

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Subscribe to Our Newsletter

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Copyright © 2025 | Powered By Porpholio

No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs

Copyright © 2025 | Powered By Porpholio