Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now

Mirage2FA

50
Global rank
17 infographic chevron month
Month rank
21 infographic chevron week
Week rank
0
IOCs

Mirage2FA is a Phishing-as-a-Service toolkit designed to compromise Microsoft 365 accounts and bypass conventional MFA through Adversary-in-the-Middle attacks. It uses malicious HTML, XHTML, and SVG files to deliver JavaScript loaders that connect victims to attacker-controlled phishing infrastructure. The toolkit relays authentication in real time, capturing credentials, 2FA codes, and authenticated session cookies. It also uses browser fingerprinting, WebSockets, obfuscation, and rotating infrastructure to evade detection and maintain access to compromised accounts.

Phishingkit
Type
LinX Coders
Origin
23 September, 2024
First seen
8 September, 2026
Last seen

How to analyze Mirage2FA with ANY.RUN

Type
LinX Coders
Origin
23 September, 2024
First seen
8 September, 2026
Last seen

IOCs

IP addresses
150.171.109.194
150.171.109.193
88.221.169.205
192.178.183.94
162.213.253.126
57.153.246.3
48.209.138.168
185.174.100.224
104.18.22.222
40.126.31.128
199.232.214.172
65.8.131.42
48.209.138.189
172.211.123.248
162.159.207.0
184.86.251.16
150.171.27.11
74.125.250.129
104.18.95.41
142.251.20.132
Hashes
b9fa2d52a4ffabb438b56184131b893b04655b01f336066415d4fe839efe64e7
7271dd5c11fb9a1052a5e91a09afbe7d148fd3388dc51c338df62a0a16f06739
75da533888189d13fc340d40637b9fc07a3f732e3fcf33ec300f4c7268790a62
907f2709d1d3c8fa26294938f4080bc477e62281c4c50a082c22db0195cda663
22ca9415e294d9c3ec3384b9d08cdaf5164af73b4e4c251559e09e529c843ea6
474d668707f1cb929fef1e3798b71b632e50675bd1a9dceaab90c9587f72f680
3d0361a85adfcd35d0de74135723a75b646965e775188f7dcdd35e3e42db788e
6028bd681dbf11a0a58dde8a0cd884115c04caa59d080ba51bde1b086ce0079d
9c70f766d3b84fc2bb298efa37cc9191f28bec336329cc11468cfadbc3b137f4
0f1bad70c7bd1e0a69562853ec529355462fcd0423263a3d39d6d0d70b780443
b3ece279943b28c8d855ec86ac1ce53bdfb6a709240d653508764493a75f7518
4ecedb9c1f3dd0d0e3aeb86146561b3d7e58656cbdbed1a39b91737b52ec7f2c
e758273c25fbad804fe884584e2797caefbbd1c2877dfd6f87ab1340cd25252e
3377a873db531113d79919e7a89369a79a602bac6ae09b9864b9378dc285f345
a3eb276fbd19dce2b00db6937578b214b9e33d67487659fe0bf21a86225ece73
a41670d52423ba69c7a65e7e153e7b9994e8dd0370c584bda0714bd61c49c578
54241ebe651a8344235cc47afd274c080abaebc8c3a25afb95d8373b6a5670a2
bbd37d41b7de6f93948fa2437a7699d4c30a3c39e736179702f212cb36a3133c
35872a3343d4b4768fe4702a8dc18b749933e81210db13466ad172bd2880f6eb
de6d7b7c2427ec4e738407d7834b71941f69166b030355e00f325ff1391df5a1
Domains
login.live.com
www.microsoft.com
stun.l.google.com
psaartifacts.store
slscr.update.microsoft.com
edge.microsoft.com
activation-v2.sls.microsoft.com
xpaywalletcdn.azureedge.net
challenges.cloudflare.com
edge-cloud-resource-static.azureedge.net
edge-mobile-static.azureedge.net
api.noteforms.com
noteforms.com
edge-consumer-static.azureedge.net
fonts.gstatic.com
ecs.office.com
settings-win.data.microsoft.com
google.com
config.edge.skype.com
msedge.b.tlu.dl.delivery.mp.microsoft.com
URLs
http://crl.microsoft.com/pki/crl/products/microoceraut2011_2011_03_22.crl
http://www.microsoft.com/pkiops/crl/micsecserca2011_2011-10-18.crl
http://edge.microsoft.com/browsernetworktime/time/1/current?cup2key=2:t1ovb5kz3tqgo0gf3tpvxdgqthv80v-3wsx9hqpopns&cup2hreq=e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
https://edge.microsoft.com/serviceexperimentation/v3/?osname=win&channel=stable&osver=10.0.19045&devicefamily=desktop&installdate=1661339457&clientversion=133.0.3065.92&experimentationmode=2&scpguard=0&scpfull=0&scpver=0
https://noteforms.com/forms/7c1ce181-5184-4cb9-b1ea-d339431b1346
https://copilot.microsoft.com/c/api/user/eligibility
https://config.edge.skype.com/config/v1/edge/133.0.3065.92?clientid=4489578223053569932&agents=edge%2cedgeconfig%2cedgeservices%2cedgefirstrun%2cedgefirstrunconfig&osname=win&client=edge&channel=stable&scpfre=0&osarch=x86_64&osver=10.0.19045&wu=1&devicefamily=desktop&uma=0&sessionid=72&mngd=0&installdate=1661339457&edu=0&soobedate=1504771245&bphint=2&fg=1&lbfgdate=1766137499&lafgdate=0
https://api.edgeoffer.microsoft.com/edgeoffer/pb/experiments?appid=edge-extensions&country=us
https://noteforms.com/_nuxt/entry.cr9ejczp.css
https://noteforms.com/_nuxt/textblock.bdhfcv9q.css
https://noteforms.com/_nuxt/poweredby.gh-l0pel.css
https://noteforms.com/widgets/iframeresizer.contentwindow.min.js
https://noteforms.com/_nuxt/cqcrvi3-.js
https://noteforms.com/_nuxt/bt4jvvlt.js
https://noteforms.com/fonts/inter-normal-400-cyrillic-ext.woff2
https://noteforms.com/_nuxt/lsazwa9a.js
https://noteforms.com/_nuxt/csqlmkis.js
https://noteforms.com/_nuxt/bcuqqms8.js
https://noteforms.com/_nuxt/dmbj6akr.js
https://noteforms.com/_nuxt/dyk42n5a.js
Last Seen at

Recent blog posts

post image
Release Notes: Faster TI Investigations, Fres...
watchers 5952
comments 0
post image
Triage & Response Bottlenecks Eating into...
watchers 5040
comments 0
post image
Major Cyber Attacks in August 2026: US and EU...
watchers 11895
comments 0

Key Takeaways

  • MFA and Session Hijacking: Mirage2FA uses AiTM phishing to capture Microsoft 365 credentials, 2FA codes, and authenticated session cookies, enabling attackers to bypass conventional MFA.
  • Broad Corporate Reach: The campaign was linked to 3,518 organization domains and 9,426 targeted email addresses. Of these, 4,532 were potentially compromised — about 48%.
  • US-Centric Targeting: The US accounted for 2,885 victims (63.7%), with activity observed across 94 countries.
  • Session Theft Leads Compromises: Of 9,332 potential compromise events, 4,561 involved cookie theft, compared with 3,044 password/2FA events and 1,339 SSO logins.
  • Browser-Based Attack Chain: Mirage2FA avoids traditional binaries, using .htm, .xhtml, and .svg stagers, QR codes, obfuscated JavaScript, and WebSockets to conduct attacks inside the browser.

Mirage2FA targets US businesses across technology and manufacturing

Mirage2FA targets US businesses across technology and manufacturing

  • ANY.RUN’s Interactive Sandbox analysis confirms that Mirage2FA uses an AiTM flow to intercept Microsoft 365 authentication in real time, capturing credentials, 2FA codes, and authenticated session cookies for account takeover.
  • Mobile Exposure: 33.3% of successful login events involved mobile devices, where limited URL visibility can make phishing harder to spot.
  • Persistent Hunting Opportunities: Despite changing infrastructure, recurring /xls/.js loader paths and LINX markers provide useful detection signals beyond individual domains and IPs.

What is Mirage2FA?

Mirage2FA is a commercial Phishing-as-a-Service (PhaaS) offering designed to compromise corporate Microsoft 365 accounts and active authenticated sessions while bypassing conventional two-factor authentication.

The operator distributes malicious HTML, XHTML, and SVG attachments that execute in the victim’s browser and silently fetch harvesting logic from attacker-controlled infrastructure. Mirage2FA then proxies the Microsoft 365 login and 2FA flow in real time through an Adversary-in-the-Middle (AiTM) attack, capturing credentials, authentication codes, and session cookies.

Unlike traditional credential-stealing phishing, Mirage2FA focuses on session hijacking. Stolen session cookies can potentially allow attackers to access Microsoft 365 and connected cloud services as an already authenticated user, even after the victim has successfully completed MFA.

The toolkit also relies on browser-based delivery rather than conventional executable malware. JavaScript obfuscation, WebSocket communication, browser fingerprinting, and rotating infrastructure help operators evade detection and adapt campaigns.

How Mirage2FA Threatens Businesses and Organizations

A successful Mirage2FA infection can create risks beyond the initial account compromise:

  • Identity-driven access risk: Stolen sessions can provide trusted access to Microsoft 365 and connected cloud services.
  • Fraud and impersonation exposure: Compromised accounts can be used to impersonate employees and target customers, suppliers, or finance teams.
  • Higher containment costs: Session theft may require more than a password reset, increasing investigation and remediation efforts.
  • Greater blast radius: A single compromised identity can enable follow-on access across email, SSO-connected applications, and internal workflows.
  • MFA control gaps: Successful AiTM attacks demonstrate that conventional MFA can be intercepted, highlighting the need for stronger phishing-resistant authentication and session controls.

Get started today for free

Analyze malware and phishing in a fully-interactive sandbox

Create free account

Victimology: Who Is Most Vulnerable?

Mirage2FA primarily targets organizations that rely heavily on Microsoft 365 for communication, collaboration, and business operations. ANY.RUN telemetry shows the highest exposure in Technology (19.2%), followed by Manufacturing (11.1%), Education (9.9%), Consulting (8.3%), and Telecommunications (6.6%). These sectors provide attackers with access to valuable corporate data, trusted communications, and connected cloud services.

Technology, MSSPs, and Manufacturing face the highest exposure to Mirage2FA

Technology, MSSPs, and Manufacturing face the highest exposure to Mirage2FA

The campaign is strongly concentrated in the United States, which accounts for 2,885 victims (63.7%), while activity was recorded across 94 countries, including India, Singapore, the UK, Canada, Saudi Arabia, and South Africa.

Mirage2FA also showed sustained activity as the campaign progressed. By the end of data collection in July 2026, 445 Mirage2FA sandbox sessions had already been recorded that month, indicating continued operational activity and growing visibility in the wild.

The compromise data highlights the toolkit’s focus on authenticated session theft. Of 9,332 potential compromise events, 4,561 involved session cookie theft, compared with 3,044 password/2FA compromises and 1,339 SSO logins. Mobile devices accounted for 33.3% of successful login events, adding another layer of risk as phishing pages can be harder to scrutinize on smaller screens.

Overall, the data points to a threat focused on high-value corporate identities, where compromising a single Microsoft 365 session can provide attackers with a pathway to broader business access.

How Does Mirage2FA Function?

Observing a Mirage 2FA sample inside ANY.RUN’s Interactive Sandbox reveals how the threat moves from a phishing attachment to Microsoft 365 account takeover through browser-based AiTM activity.

The complete Mirage2FA attack flow

The complete Mirage2FA attack flow

Stage 1: Delivery

A phishing email delivers a malicious .htm, .xhtml, or .svg attachment , or directs the victim to a QR-code link. Campaigns have also used Amazon SES for distribution.

Mirage2FA detonated inside ANY.RUN’s Interactive Sandbox

Mirage2FA detonated inside ANY.RUN’s Interactive Sandbox

Stage 2: Browser Execution

Opening the attachment launches an embedded stager. The files contain no traditional binary malware and instead execute JavaScript in the browser.

Stage 3: Hidden Staging

The stager uses HTML smuggling, SVG scripts, or JavaScript obfuscation to conceal its logic. It also carries a recipient-specific token, often based on the victim's email address.

Mirage2FA behavior verified in ANY.RUN sandbox

Mirage2FA behavior verified in ANY.RUN sandbox

Stage 4: Remote Loader

The stager retrieves the harvesting code from an attacker-controlled server, typically through the /xls/.js URL pattern.

Stage 5: AiTM Authentication

The victim is shown a convincing Microsoft 365 login page backed by an Adversary-in-the-Middle reverse proxy. The victim enters their credentials and 2FA code.

Stage 6: Credential and 2FA Interception

The phishing page captures the victim’s username, password, and one-time 2FA code.

Victims submit their Microsoft credentials through a fake login page

Victims submit their Microsoft credentials through a fake login page

Stage 7: Real-Time Relay

Mirage2FA relays the authentication to legitimate Microsoft 365 services over a WebSocket channel, allowing the attacker to obtain the resulting authenticated session despite MFA.

Stage 8: Session Theft

The toolkit exfiltrates session cookies and credentials to the operator infrastructure, storing stolen cookies as Base64-encoded .txt dumps.

Stage 9: Account Takeover

Attackers can reuse the stolen session to access Microsoft 365, read email, and impersonate the victim without entering the password or completing MFA again.

The stagers use several concealment techniques: XHTML variants can dynamically create full-screen iframes or hide logic behind hex decoders, .htm samples use remote-loader stubs or XOR + Base64 + eval, and SVG samples use inline scripts or obfuscator.io-style wrappers to hide redirects.

This browser-based design makes Mirage2FA particularly difficult to detect with traditional malware controls, as the attack relies on legitimate browser functionality rather than deploying an executable payload.

The Evolution of Mirage2FA

Since its emergence in 2024, Mirage2FA has continuously adapted its delivery and evasion techniques while preserving infrastructure and code patterns that help researchers track the operation.

  • Evolving identifiers: Early samples used LINXCODERSEMAIL, later shifting to LINXEMAIL and LINXB64EMAIL, with newer variants introducing markers such as #LINXMASKEMAIL, #LINXRANDSTRING, and linxz.
  • More sophisticated obfuscation: The JavaScript loaders progressed from relatively simple code to XOR/Base64 encoding, hexadecimal decoders, and obfuscator.io-style _0x wrappers. Obfuscation was particularly prevalent in .htm files, affecting 453 of 629 samples.
  • Expanded delivery channels: Mirage2FA moved beyond malicious .htm, .xhtml, and .svg attachments, incorporating QR-code phishing and Amazon SES. Social-engineering themes have repeatedly included HR communications and 401(k) benefits.
  • Rotating C2 infrastructure: Although domains and tokens change, the toolkit continues to expose recurring /xls/.js *loader paths**, including variations built around short routing codes and unique tokens. These persistent patterns give defenders a way to identify related activity even as infrastructure rotates.

Mirage2FA captures login credentials from targeted companies

Mirage2FA captures login credentials from targeted companies

How Businesses Can Use ANY.RUN’s Threat Intelligence Against Mirage2FA

Mirage2FA rotates domains and infrastructure, making static IOCs easy to outlive. ANY.RUN’s Threat Intelligence helps SOC teams combine known indicators with recurring behavioral patterns to detect and investigate the threat.

Threat Intelligence Lookup helps analysts uncover the broader campaign behind a single suspicious artifact.

threatName: "mirage2fa"

Integrate ANY.RUN’s threat intelligence solutions in your company

Contact us

Detect Beyond Static IOCs

Hunt for Mirage2FA patterns across email, proxy, EDR, DNS, and browser telemetry, including:

  • /<3char>/xls/*.js loader paths
  • Base64-encoded email addresses used as DNS subdomains
  • LINX* placeholder strings
  • Suspicious .htm, .xhtml, and .svg attachments
  • WebSocket connections to unknown hosts following JavaScript execution

Fresh ANY.RUN’s Threat Intelligence Feeds built from data contributed by 16,000 organizations and 700,000 security professionals, can deliver known malicious infrastructure to SIEM, SOAR, and EDR platforms, as well as other security controls. Behavioral detections help maintain coverage as Mirage2FA changes its domains and paths.

Actionable IOCs backed by data from 16K SOCs and 700K analysts

Actionable IOCs backed by data from 16K SOCs and 700K analysts

Connect Individual Samples to the Wider Campaign

Analysts can use ANY.RUN’s Threat Intelligence Lookup to pivot from suspicious URLs, domains, IPs, or loader patterns to related samples, infrastructure, and previous sandbox activity.

For Mirage2FA, the characteristic loader pattern can be used as a starting point: url:"/???/xls/?????*.js$"

This type of infrastructure pivot helped researchers expand individual Mirage2FA samples into a broader campaign cluster.

TI Lookup delivers real-time intelligence on Mirage2FA activity

TI Lookup delivers real-time intelligence on Mirage2FA activity

Respond to Session Theft

If investigation confirms that Mirage2FA has stolen a Microsoft 365 session cookie, password rotation alone is insufficient. Response teams should revoke active sessions and tokens, review mail-forwarding rules and OAuth grants, and investigate activity performed through the compromised account.

Combining behavioral hunting, fresh threat intelligence, and sandbox-based investigation gives SOC teams a more complete way to detect Mirage2FA and contain compromised identities.

Conclusion

Mirage2FA demonstrates how phishing has evolved from simple credential theft into session-based identity compromise. By intercepting Microsoft 365 authentication and stealing active session cookies, it can bypass conventional MFA and provide attackers with trusted access.

Reducing the risk requires a combination of phishing-resistant MFA, behavioral detection, isolated analysis, threat intelligence, and session-focused incident response. The faster defenders identify the campaign and revoke stolen access, the smaller the potential impact.

Frequently Asked Questions: Mirage2FA

1. What is Mirage2FA?

Mirage2FA is a Phishing-as-a-Service (PhaaS) toolkit designed to compromise corporate Microsoft 365 accounts. It uses Adversary-in-the-Middle (AiTM) phishing to capture credentials, 2FA codes, and authenticated session cookies.

2. How does Mirage2FA bypass MFA?

Mirage2FA proxies the Microsoft 365 authentication process in real time. When a victim enters their password and completes 2FA, the toolkit relays the authentication to the legitimate service while capturing the resulting authenticated session cookie, allowing attackers to potentially reuse the session without another MFA prompt.

3. How does Mirage2FA get delivered?

The toolkit commonly arrives through malicious .htm, .xhtml, and .svg attachments that execute in the browser and retrieve JavaScript from attacker-controlled infrastructure. Campaigns have also used QR-code lures and email distribution services such as Amazon SES.

4. How can organizations use interactive sandboxing and threat intelligence to detect Mirage2FA?

Interactive sandboxing allows analysts to observe the complete attack chain in real time, including JavaScript execution, redirects, fingerprinting, remote loaders, WebSocket communication, and fake Microsoft 365 authentication pages. Proactive threat intelligence can then help pivot from suspicious URLs, domains, IPs, or loader patterns to related infrastructure and activity.

5. What are the key indicators of a Mirage 2FA activity?

Security teams should look beyond static domains and IP addresses and hunt for recurring behavioral indicators, including /xls/*.js LINX* markers, Base64-encoded email addresses in DNS subdomains, suspicious browser-executed attachments, and WebSocket connections to unknown hosts following JavaScript execution.

HAVE A LOOK AT

Pay2Key screenshot
Pay2Key is a ransomware strain primarily written in C++ for Windows (with recent Linux variants), attributed to Iranian-linked actors, notably the Fox Kitten APT group (also known as UNC757 or related operations). First observed in late 2020, it employs double-extortion tactics (encrypting files and threatening to leak stolen data) while showing signs of both financial and state-aligned motivations. It has resurfaced in campaigns targeting Western organizations, including rapid encryption attacks on healthcare.
Read More
SolarisLoader screenshot
SolarisLoader
solaris
SolarisLoader is a malware loader designed to neutralize security infrastructure before deploying high-risk secondary payloads. It utilizes a "Bring Your Own Vulnerable Driver" technique to gain kernel-level access and terminate antivirus processes. To remain undetected, the malware patches internal Windows monitoring interfaces and isolates the machine from security updates. Finally, it establishes a resilient three-layer persistence mechanism involving scheduled tasks, registry backups, and a watchdog component.
Read More
ValleyRAT screenshot
ValleyRAT
valleyrat
ValleyRAT is a classic remote access trojan first documented in 2023, targeting mainly Windows systems. It is used by threat actors to gain persistent access to infected devices, steal data, and control compromised machines. ValleyRAT is notable for its relatively advanced evasion techniques and its connections to a prominent Chinese APT group.
Read More
Xeno RAT screenshot
Xeno RAT
xenorat
Xeno RAT is an open-source malware mainly distributed through drive-by downloads. The core capabilities of this threat include remote control, keystroke logging, webcam and microphone access. Equipped with advanced utilities, such as Hidden Virtual Network Computing and Socks5 reverse proxy, Xeno RAT is most frequently used in attacks against individual users.
Read More
FlowerStorm screenshot
FlowerStorm
flowerstorm
FlowerStorm is a phishing-as-a-service (PhaaS) platform used by cybercriminals to steal Microsoft 365 credentials and bypass multi-factor authentication (MFA) protections through adversary-in-the-middle (AiTM) attacks. Emerging after the disruption of Rockstar2FA in late 2024, FlowerStorm rapidly gained popularity among attackers targeting enterprises across North America and Europe.
Read More
BlackMatter screenshot
BlackMatter
blackmatter
BlackMatter is a ransomware strain operating as a Ransomware-as-a-Service (RaaS), designed to encrypt files, remove recovery options, and extort victims across critical industries. Emerging in 2021, it quickly became a major concern due to its ability to evade defenses, spread across networks, and cause large-scale operational disruption, forcing security teams to act against a highly destructive and persistent threat.
Read More