Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now

Mirage2FA

50
Global rank
17 infographic chevron month
Month rank
20 infographic chevron week
Week rank
0
IOCs

Mirage2FA is a Phishing-as-a-Service toolkit designed to compromise Microsoft 365 accounts and bypass conventional MFA through Adversary-in-the-Middle attacks. It uses malicious HTML, XHTML, and SVG files to deliver JavaScript loaders that connect victims to attacker-controlled phishing infrastructure. The toolkit relays authentication in real time, capturing credentials, 2FA codes, and authenticated session cookies. It also uses browser fingerprinting, WebSockets, obfuscation, and rotating infrastructure to evade detection and maintain access to compromised accounts.

Phishingkit
Type
LinX Coders
Origin
23 September, 2024
First seen
9 September, 2026
Last seen

How to analyze Mirage2FA with ANY.RUN

Type
LinX Coders
Origin
23 September, 2024
First seen
9 September, 2026
Last seen

IOCs

IP addresses
185.174.100.224
162.159.207.0
150.171.28.11
2.21.239.135
150.171.22.17
150.171.27.11
128.24.231.65
172.211.123.249
48.209.138.168
150.171.109.105
135.232.92.97
150.171.109.194
13.107.246.44
2.21.239.158
104.18.95.41
199.232.192.193
95.100.102.9
2.16.204.135
185.174.100.76
150.171.109.193
Hashes
db39694c444ea393569aafb2cd8ec865006f3df9ecbcb7996e7b219b30ec366d
7271dd5c11fb9a1052a5e91a09afbe7d148fd3388dc51c338df62a0a16f06739
474d668707f1cb929fef1e3798b71b632e50675bd1a9dceaab90c9587f72f680
6028bd681dbf11a0a58dde8a0cd884115c04caa59d080ba51bde1b086ce0079d
9c70f766d3b84fc2bb298efa37cc9191f28bec336329cc11468cfadbc3b137f4
0f1bad70c7bd1e0a69562853ec529355462fcd0423263a3d39d6d0d70b780443
f936348f351f327668e8a615c2079068316288234baed4cec9bf35e225b4b0bb
f6c8adab9c15d1deb57ea33ed65e5a1ca3bee42370ce83f5ce52feedddd48fa2
f9e4da319fe1f5a7d497c452421f4648a24ec7588f309ebea0f0cd61a6251eef
d988156066b7fd22de278fbc96759d2caea6552094ffeb2ddd9307806059c5e4
8b2e057387e9714efef3580a36459acf56aab53c806cd7d7dbb6e17cef977ef9
867a31befa91e9aa232b5edcfa3688230e4d77e4f8f63f782f20017aca9a6343
3a657eddec2905ce29950e37a3cc78c6839afc858fe26a89490a1502be032d13
6da43b944e494e885e69af021f93c6d9331c78aa228084711429160a5bbd15b5
d0b1a869600d21076a3fa8b5f52546e55920588ce73dfb7e56ca9dc08bdcaf3e
05b85d96f41fff14d8f608dad03ab71e2c1017c2da0914d7c59291bad7a54f8e
cbb3706e65b35a43bdcfebd23b5479dc0542ca7e23197869b683d12b524472fe
85556761a8800d14ced8fcd41a6b8b26bf012d44a318866c0d81a62092efd9bf
14bf8af0ec00ec4d1b1c48ed250d95f1917a05b4480866a0f0d3e6575f2fb0ba
3100e775e8616cd2611beecfa23a4263d7037586789b43f035236a2e6fbd4c62
Domains
login.live.com
challenges.cloudflare.com
fe3cr.delivery.mp.microsoft.com
edge.microsoft.com
aadcdn.msftauth.net
stun1.l.google.com
code.jquery.com
vatasurifa.bozoncontent.be
aadcdn.msauth.net
login.microsoftonline.com
i.imgur.com
api.edgeoffer.microsoft.com
stun.cloudflare.com
static.edge.microsoftapp.net
client.wns.windows.com
edge-cloud-resource-static.azureedge.net
user.cheacker.store
settings-win.data.microsoft.com
slscr.update.microsoft.com
stun.l.google.com
URLs
http://edge.microsoft.com/browsernetworktime/time/1/current?cup2key=2:hcxzwkf4t5x1tpvp6ujaq1mxj-sk6tpokdzommeh4b0&cup2hreq=e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
https://edge.microsoft.com/serviceexperimentation/v3/?osname=win&channel=stable&osver=10.0.19045&devicefamily=desktop&installdate=1661339457&clientversion=133.0.3065.92&experimentationmode=2&scpguard=0&scpfull=0&scpver=0
https://copilot.microsoft.com/c/api/user/eligibility
https://config.edge.skype.com/config/v1/edge/133.0.3065.92?clientid=4489578223053569932&agents=edge%2cedgeconfig%2cedgeservices%2cedgefirstrun%2cedgefirstrunconfig&osname=win&client=edge&channel=stable&scpfre=0&osarch=x86_64&osver=10.0.19045&wu=1&devicefamily=desktop&uma=0&sessionid=72&mngd=0&installdate=1661339457&edu=0&soobedate=1504771245&bphint=2&fg=1&lbfgdate=1766137499&lafgdate=0
https://login.microsoft.com//////////////////////////////common/oauth2/v2.0/authorize?state=znjhbmnpc2nvlnrvcm9ad29vzhbsyy5jb20=&scope=openid+profile+https%253a%252f%252fgraph.microsoft.com%252fuser.read&prompt=none&client_id=b5264275-2552-4683-9632-b2d24f346bd0&uri=https%253a%252f%252fdeveloper.salesforce.com%252fdashboard%252fsession%252fuser%252fverify%252fstep1&%255ca3edq%250c+2e4c%250d%250a%2593bb66f835%2509%258c2979x%25bcint+builder.decode%250a%2509context+%253a%253d+flowemail+%255b+offsetstream+%253a=%2520token%2509data%2520%257c%2520email%257dfor%2520stream%253a%253dpayloadbuilder+;+valuecontext+%257d+trace%250a%2509decode+.+signalvector+%257b%2520offset%257d%250aa78c998ef06b569e%2597%25e9%252a%25cba93627d06a07eba872664f4a92c74eae25f60308d1cad09a16e7beef0b79c03d8bd7528c4a7efc8bdb3fc053evar%252bvector-secret%25250a%252509decode%252b%25253b%252bbuffer%25250a%252509encode%252b-%252bsession%25250a%252509decode%252b%25255d%252bpayload%25250a%252509offset%252b%25252b%252bbuilder%25250a%252509builder%252b%252528%252btoken%25250a%252509encode%252b.%252bkey%25250a%252509context%252b%25257b%252btoken%25250a%25257d%25250aelse%252bdecode%25252cbuilder%25250a%252509stream%252b%25253a%25253d%252bheader%25250a%252509vector%252b%252526%252bvector%25250a%252509payload%252b%25253d%252bbuilder%25250a%252509value%252b%25257c%252bpayload%25250a%252509secret%252b%25253d%252bbuffer%25250a%25257d%25250aswitch%252bpayload%25252csession%25250a%252509payload%252b%252529%252btoken%25250a%252509payload%252b%252526%252bbuilder%25250a%252509data%252b%25257c%252bdecode%25250a%252509secret%252b%25255b%252bstream%25250a%25257d%25250astring%252bbody%252529session%25250a%252509session%252b%252528%252btrace%25250a%252509buffer%252b%25257b%252bsession%25250a%252509vector%252b%25252a%252bvector%25250a%252509context%252b%25253b%252btoken%25250a%252509value%252b%25252a%252bdata%25250a%252509encode%252b%25253b%252bflow%25250a%252509trace%252b%252529%252btrace%25250a%25257d%25250aint%252btoken%25257csignal%25250a%252509header%252b%25255d%252bflow%
https://api.edgeoffer.microsoft.com/edgeoffer/pb/experiments?appid=edge-extensions&country=us
https://login.microsoftonline.com/common/oauth2/v2.0/authorize?state=znjhbmnpc2nvlnrvcm9ad29vzhbsyy5jb20=&scope=openid+profile+https%253a%252f%252fgraph.microsoft.com%252fuser.read&prompt=none&client_id=b5264275-2552-4683-9632-b2d24f346bd0&uri=https%253a%252f%252fdeveloper.salesforce.com%252fdashboard%252fsession%252fuser%252fverify%252fstep1&%255ca3edq%250c+2e4c%250d%250a%2593bb66f835%2509%258c2979x%25bcint+builder.decode%250a%2509context+%253a%253d+flowemail+%255b+offsetstream+%253a=%2520token%2509data%2520%257c%2520email%257dfor%2520stream%253a%253dpayloadbuilder+;+valuecontext+%257d+trace%250a%2509decode+.+signalvector+%257b%2520offset%257d%250aa78c998ef06b569e%2597%25e9%252a%25cba93627d06a07eba872664f4a92c74eae25f60308d1cad09a16e7beef0b79c03d8bd7528c4a7efc8bdb3fc053evar%252bvector-secret%25250a%252509decode%252b%25253b%252bbuffer%25250a%252509encode%252b-%252bsession%25250a%252509decode%252b%25255d%252bpayload%25250a%252509offset%252b%25252b%252bbuilder%25250a%252509builder%252b%252528%252btoken%25250a%252509encode%252b.%252bkey%25250a%252509context%252b%25257b%252btoken%25250a%25257d%25250aelse%252bdecode%25252cbuilder%25250a%252509stream%252b%25253a%25253d%252bheader%25250a%252509vector%252b%252526%252bvector%25250a%252509payload%252b%25253d%252bbuilder%25250a%252509value%252b%25257c%252bpayload%25250a%252509secret%252b%25253d%252bbuffer%25250a%25257d%25250aswitch%252bpayload%25252csession%25250a%252509payload%252b%252529%252btoken%25250a%252509payload%252b%252526%252bbuilder%25250a%252509data%252b%25257c%252bdecode%25250a%252509secret%252b%25255b%252bstream%25250a%25257d%25250astring%252bbody%252529session%25250a%252509session%252b%252528%252btrace%25250a%252509buffer%252b%25257b%252bsession%25250a%252509vector%252b%25252a%252bvector%25250a%252509context%252b%25253b%252btoken%25250a%252509value%252b%25252a%252bdata%25250a%252509encode%252b%25253b%252bflow%25250a%252509trace%252b%252529%252btrace%25250a%25257d%25250aint%252btoken%25257csignal%25250a%252509header%252b%25255d%252bflow%25
https://config.edge.skype.com/config/v1/edge/133.0.3065.92?clientid=4489578223053569932&agents=edgeruntime%2cedgeruntimeconfig%2cedgedomainactions&osname=win&client=edge&channel=stable&scpfre=0&osarch=x86_64&osver=10.0.19045&wu=1&devicefamily=desktop&uma=0&sessionid=72&mngd=0&installdate=1661339457&edu=0&soobedate=1504771245&bphint=2&fg=1&lbfgdate=1766137499&lafgdate=0
https://aadcdn.msauth.net/shared/1.0/content/js/fetchsessions_core_89q4ntpu5d04aggkhtgcrq2.js
https://www.bing.com/bloomfilterfiles/expandeddomainsfilterglobal.json
https://login.live.com/me.htm?v=3
https://login.microsoftonline.com/favicon.ico
https://vatasurifa.bozoncontent.be/lss?error=interaction_required&error_description=session+information+is+not+sufficient+for+single-sign-on.&state=znjhbmnpc2nvlnrvcm9ad29vzhbsyy5jb20%3d
https://vatasurifa.bozoncontent.be/lss/?error=interaction_required&error_description=session+information+is+not+sufficient+for+single-sign-on.&state=znjhbmnpc2nvlnrvcm9ad29vzhbsyy5jb20%3d
https://identity.nel.measure.office.net/api/report?catid=gw+estsfd+ams2
https://static.cloudflareinsights.com/beacon.min.js/v8c78df7c7c0f484497ecbca7046644da1771523124516
https://fssitecorps.com/z5tj1u6rwwpxpwhnpqqbhodjy2muihus/yqr?7kbq=francisco.toro@woodplc.com
https://fssitecorps.com/verify.html?returnto=%2fz5tj1u6rwwpxpwhnpqqbhodjy2muihus%2fyqr%3f7kbq%3dfrancisco.toro%40woodplc.com
https://challenges.cloudflare.com/turnstile/v0/api.js
https://challenges.cloudflare.com/turnstile/v0/g/330e41bb475c/api.js
Last Seen at

Recent blog posts

post image
15 Minutes Saved Per Alert: How a Lean German...
watchers 837
comments 0
post image
HVNC Backdoor Targets LATAM Organizations wit...
watchers 3133
comments 0
post image
Release Notes: Faster TI Investigations, Fres...
watchers 7591
comments 0

Key Takeaways

  • MFA and Session Hijacking: Mirage2FA uses AiTM phishing to capture Microsoft 365 credentials, 2FA codes, and authenticated session cookies, enabling attackers to bypass conventional MFA.
  • Broad Corporate Reach: The campaign was linked to 3,518 organization domains and 9,426 targeted email addresses. Of these, 4,532 were potentially compromised — about 48%.
  • US-Centric Targeting: The US accounted for 2,885 victims (63.7%), with activity observed across 94 countries.
  • Session Theft Leads Compromises: Of 9,332 potential compromise events, 4,561 involved cookie theft, compared with 3,044 password/2FA events and 1,339 SSO logins.
  • Browser-Based Attack Chain: Mirage2FA avoids traditional binaries, using .htm, .xhtml, and .svg stagers, QR codes, obfuscated JavaScript, and WebSockets to conduct attacks inside the browser.

Mirage2FA targets US businesses across technology and manufacturing

Mirage2FA targets US businesses across technology and manufacturing

  • ANY.RUN’s Interactive Sandbox analysis confirms that Mirage2FA uses an AiTM flow to intercept Microsoft 365 authentication in real time, capturing credentials, 2FA codes, and authenticated session cookies for account takeover.
  • Mobile Exposure: 33.3% of successful login events involved mobile devices, where limited URL visibility can make phishing harder to spot.
  • Persistent Hunting Opportunities: Despite changing infrastructure, recurring /xls/.js loader paths and LINX markers provide useful detection signals beyond individual domains and IPs.

What is Mirage2FA?

Mirage2FA is a commercial Phishing-as-a-Service (PhaaS) offering designed to compromise corporate Microsoft 365 accounts and active authenticated sessions while bypassing conventional two-factor authentication.

The operator distributes malicious HTML, XHTML, and SVG attachments that execute in the victim’s browser and silently fetch harvesting logic from attacker-controlled infrastructure. Mirage2FA then proxies the Microsoft 365 login and 2FA flow in real time through an Adversary-in-the-Middle (AiTM) attack, capturing credentials, authentication codes, and session cookies.

Unlike traditional credential-stealing phishing, Mirage2FA focuses on session hijacking. Stolen session cookies can potentially allow attackers to access Microsoft 365 and connected cloud services as an already authenticated user, even after the victim has successfully completed MFA.

The toolkit also relies on browser-based delivery rather than conventional executable malware. JavaScript obfuscation, WebSocket communication, browser fingerprinting, and rotating infrastructure help operators evade detection and adapt campaigns.

How Mirage2FA Threatens Businesses and Organizations

A successful Mirage2FA infection can create risks beyond the initial account compromise:

  • Identity-driven access risk: Stolen sessions can provide trusted access to Microsoft 365 and connected cloud services.
  • Fraud and impersonation exposure: Compromised accounts can be used to impersonate employees and target customers, suppliers, or finance teams.
  • Higher containment costs: Session theft may require more than a password reset, increasing investigation and remediation efforts.
  • Greater blast radius: A single compromised identity can enable follow-on access across email, SSO-connected applications, and internal workflows.
  • MFA control gaps: Successful AiTM attacks demonstrate that conventional MFA can be intercepted, highlighting the need for stronger phishing-resistant authentication and session controls.

Get started today for free

Analyze malware and phishing in a fully-interactive sandbox

Create free account

Victimology: Who Is Most Vulnerable?

Mirage2FA primarily targets organizations that rely heavily on Microsoft 365 for communication, collaboration, and business operations. ANY.RUN telemetry shows the highest exposure in Technology (19.2%), followed by Manufacturing (11.1%), Education (9.9%), Consulting (8.3%), and Telecommunications (6.6%). These sectors provide attackers with access to valuable corporate data, trusted communications, and connected cloud services.

Technology, MSSPs, and Manufacturing face the highest exposure to Mirage2FA

Technology, MSSPs, and Manufacturing face the highest exposure to Mirage2FA

The campaign is strongly concentrated in the United States, which accounts for 2,885 victims (63.7%), while activity was recorded across 94 countries, including India, Singapore, the UK, Canada, Saudi Arabia, and South Africa.

Mirage2FA also showed sustained activity as the campaign progressed. By the end of data collection in July 2026, 445 Mirage2FA sandbox sessions had already been recorded that month, indicating continued operational activity and growing visibility in the wild.

The compromise data highlights the toolkit’s focus on authenticated session theft. Of 9,332 potential compromise events, 4,561 involved session cookie theft, compared with 3,044 password/2FA compromises and 1,339 SSO logins. Mobile devices accounted for 33.3% of successful login events, adding another layer of risk as phishing pages can be harder to scrutinize on smaller screens.

Overall, the data points to a threat focused on high-value corporate identities, where compromising a single Microsoft 365 session can provide attackers with a pathway to broader business access.

How Does Mirage2FA Function?

Observing a Mirage 2FA sample inside ANY.RUN’s Interactive Sandbox reveals how the threat moves from a phishing attachment to Microsoft 365 account takeover through browser-based AiTM activity.

The complete Mirage2FA attack flow

The complete Mirage2FA attack flow

Stage 1: Delivery

A phishing email delivers a malicious .htm, .xhtml, or .svg attachment , or directs the victim to a QR-code link. Campaigns have also used Amazon SES for distribution.

Mirage2FA detonated inside ANY.RUN’s Interactive Sandbox

Mirage2FA detonated inside ANY.RUN’s Interactive Sandbox

Stage 2: Browser Execution

Opening the attachment launches an embedded stager. The files contain no traditional binary malware and instead execute JavaScript in the browser.

Stage 3: Hidden Staging

The stager uses HTML smuggling, SVG scripts, or JavaScript obfuscation to conceal its logic. It also carries a recipient-specific token, often based on the victim's email address.

Mirage2FA behavior verified in ANY.RUN sandbox

Mirage2FA behavior verified in ANY.RUN sandbox

Stage 4: Remote Loader

The stager retrieves the harvesting code from an attacker-controlled server, typically through the /xls/.js URL pattern.

Stage 5: AiTM Authentication

The victim is shown a convincing Microsoft 365 login page backed by an Adversary-in-the-Middle reverse proxy. The victim enters their credentials and 2FA code.

Stage 6: Credential and 2FA Interception

The phishing page captures the victim’s username, password, and one-time 2FA code.

Victims submit their Microsoft credentials through a fake login page

Victims submit their Microsoft credentials through a fake login page

Stage 7: Real-Time Relay

Mirage2FA relays the authentication to legitimate Microsoft 365 services over a WebSocket channel, allowing the attacker to obtain the resulting authenticated session despite MFA.

Stage 8: Session Theft

The toolkit exfiltrates session cookies and credentials to the operator infrastructure, storing stolen cookies as Base64-encoded .txt dumps.

Stage 9: Account Takeover

Attackers can reuse the stolen session to access Microsoft 365, read email, and impersonate the victim without entering the password or completing MFA again.

The stagers use several concealment techniques: XHTML variants can dynamically create full-screen iframes or hide logic behind hex decoders, .htm samples use remote-loader stubs or XOR + Base64 + eval, and SVG samples use inline scripts or obfuscator.io-style wrappers to hide redirects.

This browser-based design makes Mirage2FA particularly difficult to detect with traditional malware controls, as the attack relies on legitimate browser functionality rather than deploying an executable payload.

The Evolution of Mirage2FA

Since its emergence in 2024, Mirage2FA has continuously adapted its delivery and evasion techniques while preserving infrastructure and code patterns that help researchers track the operation.

  • Evolving identifiers: Early samples used LINXCODERSEMAIL, later shifting to LINXEMAIL and LINXB64EMAIL, with newer variants introducing markers such as #LINXMASKEMAIL, #LINXRANDSTRING, and linxz.
  • More sophisticated obfuscation: The JavaScript loaders progressed from relatively simple code to XOR/Base64 encoding, hexadecimal decoders, and obfuscator.io-style _0x wrappers. Obfuscation was particularly prevalent in .htm files, affecting 453 of 629 samples.
  • Expanded delivery channels: Mirage2FA moved beyond malicious .htm, .xhtml, and .svg attachments, incorporating QR-code phishing and Amazon SES. Social-engineering themes have repeatedly included HR communications and 401(k) benefits.
  • Rotating C2 infrastructure: Although domains and tokens change, the toolkit continues to expose recurring /xls/.js *loader paths**, including variations built around short routing codes and unique tokens. These persistent patterns give defenders a way to identify related activity even as infrastructure rotates.

Mirage2FA captures login credentials from targeted companies

Mirage2FA captures login credentials from targeted companies

How Businesses Can Use ANY.RUN’s Threat Intelligence Against Mirage2FA

Mirage2FA rotates domains and infrastructure, making static IOCs easy to outlive. ANY.RUN’s Threat Intelligence helps SOC teams combine known indicators with recurring behavioral patterns to detect and investigate the threat.

Threat Intelligence Lookup helps analysts uncover the broader campaign behind a single suspicious artifact.

threatName: "mirage2fa"

Integrate ANY.RUN’s threat intelligence solutions in your company

Contact us

Detect Beyond Static IOCs

Hunt for Mirage2FA patterns across email, proxy, EDR, DNS, and browser telemetry, including:

  • /<3char>/xls/*.js loader paths
  • Base64-encoded email addresses used as DNS subdomains
  • LINX* placeholder strings
  • Suspicious .htm, .xhtml, and .svg attachments
  • WebSocket connections to unknown hosts following JavaScript execution

Fresh ANY.RUN’s Threat Intelligence Feeds built from data contributed by 16,000 organizations and 700,000 security professionals, can deliver known malicious infrastructure to SIEM, SOAR, and EDR platforms, as well as other security controls. Behavioral detections help maintain coverage as Mirage2FA changes its domains and paths.

Actionable IOCs backed by data from 16K SOCs and 700K analysts

Actionable IOCs backed by data from 16K SOCs and 700K analysts

Connect Individual Samples to the Wider Campaign

Analysts can use ANY.RUN’s Threat Intelligence Lookup to pivot from suspicious URLs, domains, IPs, or loader patterns to related samples, infrastructure, and previous sandbox activity.

For Mirage2FA, the characteristic loader pattern can be used as a starting point: url:"/???/xls/?????*.js$"

This type of infrastructure pivot helped researchers expand individual Mirage2FA samples into a broader campaign cluster.

TI Lookup delivers real-time intelligence on Mirage2FA activity

TI Lookup delivers real-time intelligence on Mirage2FA activity

Respond to Session Theft

If investigation confirms that Mirage2FA has stolen a Microsoft 365 session cookie, password rotation alone is insufficient. Response teams should revoke active sessions and tokens, review mail-forwarding rules and OAuth grants, and investigate activity performed through the compromised account.

Combining behavioral hunting, fresh threat intelligence, and sandbox-based investigation gives SOC teams a more complete way to detect Mirage2FA and contain compromised identities.

Conclusion

Mirage2FA demonstrates how phishing has evolved from simple credential theft into session-based identity compromise. By intercepting Microsoft 365 authentication and stealing active session cookies, it can bypass conventional MFA and provide attackers with trusted access.

Reducing the risk requires a combination of phishing-resistant MFA, behavioral detection, isolated analysis, threat intelligence, and session-focused incident response. The faster defenders identify the campaign and revoke stolen access, the smaller the potential impact.

Frequently Asked Questions: Mirage2FA

1. What is Mirage2FA?

Mirage2FA is a Phishing-as-a-Service (PhaaS) toolkit designed to compromise corporate Microsoft 365 accounts. It uses Adversary-in-the-Middle (AiTM) phishing to capture credentials, 2FA codes, and authenticated session cookies.

2. How does Mirage2FA bypass MFA?

Mirage2FA proxies the Microsoft 365 authentication process in real time. When a victim enters their password and completes 2FA, the toolkit relays the authentication to the legitimate service while capturing the resulting authenticated session cookie, allowing attackers to potentially reuse the session without another MFA prompt.

3. How does Mirage2FA get delivered?

The toolkit commonly arrives through malicious .htm, .xhtml, and .svg attachments that execute in the browser and retrieve JavaScript from attacker-controlled infrastructure. Campaigns have also used QR-code lures and email distribution services such as Amazon SES.

4. How can organizations use interactive sandboxing and threat intelligence to detect Mirage2FA?

Interactive sandboxing allows analysts to observe the complete attack chain in real time, including JavaScript execution, redirects, fingerprinting, remote loaders, WebSocket communication, and fake Microsoft 365 authentication pages. Proactive threat intelligence can then help pivot from suspicious URLs, domains, IPs, or loader patterns to related infrastructure and activity.

5. What are the key indicators of a Mirage 2FA activity?

Security teams should look beyond static domains and IP addresses and hunt for recurring behavioral indicators, including /xls/*.js LINX* markers, Base64-encoded email addresses in DNS subdomains, suspicious browser-executed attachments, and WebSocket connections to unknown hosts following JavaScript execution.

HAVE A LOOK AT

Ramnit screenshot
Ramnit
ramnit
Ramnit is a highly modular banking trojan and worm that evolved from a file-infecting virus into a powerful cybercrime tool. It specializes in financial fraud, credential theft, remote access, and malware delivery, being a serious threat to businesses and individuals. First spotted in 2010, Ramnit became popular after the 2014 takedown of the GameOver Zeus botnet, as cybercriminals sought alternatives for banking fraud.
Read More
DonutLoader screenshot
DonutLoader
donutloader donut
DonutLoader is a versatile, open-source-based in-memory loader that turns .NET assemblies, executables, DLLs, and scripts into position-independent shellcode for execution entirely in RAM. Originally derived from the popular Donut tool, it enables threat actors to bypass traditional antivirus and EDR solutions by avoiding disk writes and injecting payloads directly into legitimate Windows processes.
Read More
Socelars screenshot
Socelars
socelars
Socelars is an information-stealing Trojan (often categorized as spyware/stealer) that focuses on collecting sensitive data from Windows systems, with standout reporting around Facebook Ads Manager and session cookie theft. Unlike “noisy” malware that immediately breaks something, Socelars quietly converts a single infected machine into access: logged-in sessions, business account data, and pathways to monetization.
Read More
Pulsar RAT screenshot
Pulsar RAT
pulsar
Pulsar RAT is a derivative of Quasar RAT with extensive functionality including keylogging, cryptocurrency wallet clipping, credential theft, file management, remote shell execution, and data exfiltration capabilities. As a modular, open-source remote administration tool designed for Windows systems, Pulsar introduces significant enhancements over its predecessor.
Read More
RondoDox screenshot
RondoDox
rondodox
RondoDox is an emerging Linux-based botnet malware that exploits dozens of known vulnerabilities in internet-facing devices like routers, DVRs, and web servers to build massive networks for DDoS attacks, cryptomining, and data exfiltration. First spotted in mid-2025, its "exploit shotgun" tactic (firing multiple payloads at once) has made it a rapid escalator in the IoT threat landscape, compromising unpatched edge devices worldwide.
Read More
WannaCry screenshot
WannaCry
wannacry ransomware
WannaCry is a famous Ransomware that utilizes the EternalBlue exploit. This malware is known for infecting at least 200,000 computers worldwide and it continues to be an active and dangerous threat.
Read More