Mirage2FA: The Phishing Service Turning a Stolen Microsoft 365 Cookie Into Full Account Takeover
Brief
A phishing-as-a-service kit sold by a crew calling itself LinX Coders steals the one thing a password reset can’t fix — the live session cookie — and ANY.RUN’s telemetry ties it to 9,332 compromise events reaching 94 countries.
For most defenders, a phishing alert ends with a forced password change. Mirage2FA is built to make that response useless.
The phishing-as-a-service kit documented by ANY. RUN threat intelligence analysts ShiFu and raptur3 does not just harvest passwords; it sits between the victim and Microsoft as an adversary-in-the-middle (AiTM) proxy, forwards the login and 2FA code in real time, and walks away with the authenticated session cookie Microsoft hands back.
With that cookie replayed, the attacker is already inside no password, no second factor required.
That design has scaled. ANY.
