Mirage2FA Phishing Kit Slipped Past Microsoft 365 Logins at 4,500 Firms

A rented phishing service quietly harvested Microsoft 365 credentials and two-factor codes across US and European companies for nearly two years.

ThreatVectr NewsdeskAI-assistedPublished Updated · Editor: Lee Brown· 4 min read
A Microsoft 365 login interface on a computer screen with a two-factor authentication prompt, surrounded by other office windows and applications, representing
Illustration made with AI. Not a photograph of the events described.
Share

Key points

  • Mirage2FA, a rented phishing kit, hit around 4,500 companies in the US and Europe between 2024 and 2026, according to sandbox firm ANY.RUN.
  • The kit targets Microsoft 365 accounts and is built to defeat two-factor authentication, the second code most workers enter after their password.
  • ANY.RUN researchers found that 48% of email addresses targeted by the campaign were potentially compromised.
  • Most victim organisations are based in the United States.
  • The attack sits invisibly between the user and the real Microsoft login page, capturing the password and session token together.

A phishing service called Mirage2FA has spent almost two years quietly picking apart Microsoft 365 logins at thousands of companies, and nearly half of the people it aimed at appear to have been caught.

The figures come from ANY.RUN, a malware sandbox company that watched the campaign run from 2024 into 2026. Their tally: about 4,500 affected organisations, mostly in the United States, with a smaller cluster in Europe. The finding was picked up more widely by The Hacker News. Mirage2FA follows a pattern we've tracked closely since July: our earlier story on Forg365 found similar session-theft mechanics targeting Microsoft 365 accounts.

What is Mirage2FA, in plain English?

Mirage2FA is a phishing-as-a-service kit, meaning criminals rent it rather than build their own. It sends fake Microsoft 365 login pages to staff at target companies. When someone types in their password and their two-factor code, the kit passes it through to the real Microsoft site and steals the resulting session in the middle.

That middle step is the one that matters. Old-school phishing grabbed passwords. Kits like Mirage2FA grab the session cookie, the small file your browser holds after you log in, which tells Microsoft you are already signed in. With that cookie, the attacker walks straight into the mailbox without needing a code.

This is an adversary-in-the-middle attack against the OAuth 2.0 and OpenID Connect flows Microsoft 365 uses. The padlock in the browser is genuine, the login page looks correct, and the second code you were told would protect you gets forwarded to the crooks in real time.

Who got hit?

ANY.RUN puts the affected count at roughly 4,500 companies, with US firms taking the brunt. The researchers say 48% of the email addresses the campaign aimed at were potentially compromised. That's not a rounding error. It's close to a coin flip on every inbox the crooks pointed at.

Detail Figure
Campaign active 2024 to 2026
Companies affected ~4,500
Emails targeted and likely compromised 48%
Primary region United States
Target platform Microsoft 365

The kit is sold commercially, so the 4,500 number reflects many different criminal customers running their own smaller campaigns off the same shared infrastructure.

Would MFA have helped?

Not much. Standard two-factor authentication, the kind that sends a code by text message or an authenticator app, is exactly what Mirage2FA is built to defeat. The user enters the code, the kit relays it, and the attacker gets a valid session.

Phishing-resistant MFA does help. That means passkeys or hardware security keys using the FIDO2 standard, which ties the login to the real Microsoft web address at the cryptographic level. A fake page can't request the key, because the key checks the domain itself. Microsoft has been pushing customers toward this for exactly this reason.

Conditional access rules also matter. Blocking logins from unexpected locations, shortening session lifetimes, and enforcing device compliance all reduce how much a stolen cookie is worth.

What should ordinary staff do?

If your employer uses Microsoft 365 and you clicked a login link from an email in the last two years, tell IT. Ask them to check your sign-in history for logins from places you've never been, and to revoke any active sessions on your account. Changing your password alone won't kick an attacker out if they already hold your session cookie.

For everyone else, the rule is small and boring: don't log in to work accounts from links in emails. Go to the site the way you normally do.

© 2026 Threat Vectr