Over 4,500 Organizations Targeted in Mirage2FA Campaign Abusing Microsoft 365 Login Flow

Between 2024 and 2026, the Mirage2FA phishing campaign targeted over 4,500 organizations worldwide. Leveraging sophisticated Adversary-in-the-Middle (AiTM) proxies, the toolkit bypasses legacy two-factor authentication to swipe both passwords and active session cookies. With nearly 50% of targeted inboxes potentially compromised, the campaign proves that basic password resets won't cut it, forcing organizations to adopt phishing-resistant FIDO2/passkey authentication and aggressive session revocation.

26 August 2026
3 min read
Mirage2FA Microsoft 365

Over 4,500 organizations have fallen victim to the Mirage2FA campaign, a commercial phishing-as-a-service kit active between 2024 and 2026. The campaign targets business Microsoft 365 accounts using Adversary-in-the-Middle (AiTM) techniques that bypass two-factor authentication (MFA). According to recent data from ANY.RUN, 48% of targeted email addresses were potentially compromised, with the U.S. being the most heavily impacted country at over 63% of victims.

 

1. Mirage2FA Modus Operandi and Security Impact

Unlike traditional phishing attacks that use isolated fake login pages to simply steal a password, Mirage2FA deploys a much more sophisticated Adversary-in-the-Middle (AiTM) infrastructure. Thus, instead of tricking the user into entering data on a dead-end decoy site, the PhaaS toolkit sits quietly and in real time between the victim and the official Microsoft 365 login portal.

The mechanics unfold through three critical stages:

  1. The Phishing Bait and Redirect: Users receive phishing emails that direct them to a fake page designed to faithfully replicate the visual and behavioral flow of Microsoft services.
  2. Real-Time Proxy Intermediation: As the victim inputs their credentials, the attacker-controlled server captures the data and relays it forward to the official Microsoft servers. When the system requests multi-factor authentication (MFA), whether via an SMS code, push notification, or an authenticator app, the code or approval is intercepted on the fly.
  3. Session Hijacking: Once authentication succeeds on the official end, the AiTM server captures the active session cookies. Armed with these valid tokens, attackers can access the account repeatedly and completely independently, bypassing any subsequent MFA hurdles and behaving exactly like the legitimate user within the Microsoft 365 ecosystem.

2. How to Reduce Mirage2FA Risk in Your Company

Because Adversary-in-the-Middle (AiTM) attacks successfully bypass traditional MFA methods, such as SMS codes or basic push notifications, simply resetting a password after an incident is no longer effective. To neutralize campaigns like Mirage2FA, organizations must adopt modern, resilient security measures:

  1. Deploy Phishing-Resistant Authentication (FIDO2 / Passkeys): Transitioning to hardware security keys (like YubiKeys) or FIDO2-based passkeys completely blocks AiTM attacks. These methods cryptographically bind the authentication session to the legitimate domain, making interception or reuse on a fake site impossible.
  2. Enforce Immediate Session Revocation: If an account is compromised, a password reset alone is not enough. Administrators must immediately revoke all active session tokens and cookies from the control panel (e.g., Microsoft Entra ID / Azure AD) to cut off the attackers’ access.
  3. Monitor Behavioral Anomalies and Access Logs: Closely tracking impossible travel anomalies, sudden IP address changes, or the use of unrecognized devices to access Microsoft 365 accounts helps security teams swiftly detect already-hijacked sessions.

Conclusion

The Mirage2FA campaign unequivocally proves that traditional two-factor authentication methods can no longer keep pace with current threats. Therefore, for organizations relying on Microsoft 365, transitioning to phishing-resistant solutions like FIDO2 and passkeys is no longer just a recommendation, but a necessity.

Check your Microsoft 365 security today

See if your current setup actually shields you from modern AiTM attacks.