← Back to feed
PhishingEmerging1 sourceAug 18, 2026 · 09:28via ANY.RUN Blog

Mirage2FA Hijacks Companies’ Microsoft 365 Sessions, with Over 4K Victims in the US

Brief

Mirage2FA is an active phishing-as-a-service toolkit built to steal Microsoft 365 credentials and authenticated sessions through Adversary-in-the-Middle (AiTM) attacks.

ANY. RUN research shows that 63. 7% of identified victims are in the US , with Technologies , Manufacturing , and Education among the most targeted industries. The operation has generated thousands of compromise events between 2024 and 2026, including stolen session cookies, passwords, and SSO access.

Once an authenticated Microsoft 365 session is hijacked, attackers may gain access to corporate email, sensitive data, and trusted business accounts, creating a path for impersonation, fraud, and further compromise . Detecting the attack before stolen sessions are reused can help security teams contain account takeover earlier and reduce the potential business impact.

Read more on ANY.RUN Blog