Mirage2FA Steals Sessions Past Microsoft 365 MFA

ANY.RUN research says the Mirage2FA phishing-as-a-service campaign has touched about 4,532 organization domains and more than 9,000 potential password and session-theft events across the US and Europe. The kit targets Microsoft 365 sign-ins and uses fake login flows to get past two-factor prompts. The trick is not stopping at the password: once a victim signs in, Mirage2FA captures the browser session cookie and reuses it, so the attacker can look already authenticated in Microsoft 365 and connected single sign-on apps. That means a password change or MFA prompt does not necessarily end the access already inside the session. For organizations that rely on Microsoft 365 as the front door to other SaaS, the durable exposure is the session itself, not just the account secret. The reporting suggests identity teams have to think about account compromise as browser-session theft when access and cleanup are measured.

Part of the PlainSec briefing for 2026-08-26

Every edition of this story: Mirage2FA Steals Sessions Past Microsoft 365 MFA

Sources