Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now

Mirage2FA

40
Global rank
11 infographic chevron month
Month rank
11 infographic chevron week
Week rank

Mirage2FA is a Phishing-as-a-Service toolkit designed to compromise Microsoft 365 accounts and bypass conventional MFA through Adversary-in-the-Middle attacks. It uses malicious HTML, XHTML, and SVG files to deliver JavaScript loaders that connect victims to attacker-controlled phishing infrastructure. The toolkit relays authentication in real time, capturing credentials, 2FA codes, and authenticated session cookies. It also uses browser fingerprinting, WebSockets, obfuscation, and rotating infrastructure to evade detection and maintain access to compromised accounts.

Phishingkit
Type
LinX Coders
Origin
23 September, 2024
First seen
28 September, 2026
Last seen

How to analyze Mirage2FA with ANY.RUN

Type
LinX Coders
Origin
23 September, 2024
First seen
28 September, 2026
Last seen

IOCs

IP addresses
20.165.94.63
23.11.40.157
95.100.102.9
2.21.239.158
48.209.138.168
185.174.100.90
172.67.74.152
2.23.227.142
74.178.76.54
151.101.65.155
91.229.77.71
13.107.246.44
150.171.28.11
150.171.109.193
142.251.20.132
199.232.196.193
204.79.197.203
150.171.27.11
2.16.204.160
23.59.18.102
Hashes
a796b38365910aa3443c68fa88e9f1e91afc0ac9d9478dd631b026555505d9ab
b9fa2d52a4ffabb438b56184131b893b04655b01f336066415d4fe839efe64e7
c79bcd93abf3636643fbf079a7fb98f79745c7996f18dc13bf3347ca401dc010
5b4bce78452a2272d5b4249f927acf5fca9483f5ca28c1788e714cb520ad69bb
75da533888189d13fc340d40637b9fc07a3f732e3fcf33ec300f4c7268790a62
907f2709d1d3c8fa26294938f4080bc477e62281c4c50a082c22db0195cda663
22ca9415e294d9c3ec3384b9d08cdaf5164af73b4e4c251559e09e529c843ea6
474d668707f1cb929fef1e3798b71b632e50675bd1a9dceaab90c9587f72f680
3d0361a85adfcd35d0de74135723a75b646965e775188f7dcdd35e3e42db788e
6028bd681dbf11a0a58dde8a0cd884115c04caa59d080ba51bde1b086ce0079d
9c70f766d3b84fc2bb298efa37cc9191f28bec336329cc11468cfadbc3b137f4
eacd09517ce90d34ba562171d15ac40d302f0e691b439f91be1b6406e25f5913
b3ece279943b28c8d855ec86ac1ce53bdfb6a709240d653508764493a75f7518
4ecedb9c1f3dd0d0e3aeb86146561b3d7e58656cbdbed1a39b91737b52ec7f2c
e758273c25fbad804fe884584e2797caefbbd1c2877dfd6f87ab1340cd25252e
3377a873db531113d79919e7a89369a79a602bac6ae09b9864b9378dc285f345
a3eb276fbd19dce2b00db6937578b214b9e33d67487659fe0bf21a86225ece73
a41670d52423ba69c7a65e7e153e7b9994e8dd0370c584bda0714bd61c49c578
54241ebe651a8344235cc47afd274c080abaebc8c3a25afb95d8373b6a5670a2
bbd37d41b7de6f93948fa2437a7699d4c30a3c39e736179702f212cb36a3133c
Domains
code.jquery.com
api.ipify.org
edge-consumer-static.azureedge.net
client.wns.windows.com
copilot.microsoft.com
letsgetitnow2.store
go.microsoft.com
edge.microsoft.com
ajax.googleapis.com
settings-win.data.microsoft.com
aadcdn.msauth.net
oneocsp.microsoft.com
ocsp.digicert.com
fe3cr.delivery.mp.microsoft.com
xmn.giza-enta.xyz
config.edge.skype.com
vxc.cheacker.store
www.bing.com
crl.microsoft.com
self.events.data.microsoft.com
URLs
http://crl.microsoft.com/pki/crl/products/microoceraut2011_2011_03_22.crl
http://www.microsoft.com/pkiops/crl/microsoft%20secure%20server%20ca%202026.crl
https://settings-win.data.microsoft.com/settings/v3.0/wsd/waasassessment?os=windows&osver=10.0.19041.1.amd64fre.vb_release.191206-&ring=retail&sku=48&deviceclass=windows.desktop&locale=en-us&deviceid=bad99146-31d3-4ec6-a1a4-be76f32ba5d4&flightring=retail&telemetrylevel=1&hidovergattreg=c%3a%5cwindows%5csystem32%5cdriverstore%5cfilerepository%5chidbthle.inf_amd64_9610b4821fdf82a5%5cmicrosoft.bluetooth.profiles.hidovergatt.dll&appver=10.0&processoridentifier=amd64%20family%2023%20model%201%20stepping%202&oemmodel=dell&updateoffereddays=4294967295&processormanufacturer=authenticamd&installdate=1661339444&oemmodelbaseboard=&branchreadinesslevel=cb&oemsubmodel=j5cr&isclouddomainjoined=0&deferfeatureupdateperiodindays=30&isdeviceretaildemo=0&flightingbranchname=&osuilocale=en-us&devicefamily=windows.desktop&wuclientver=10.0.19041.3996&uninstallactive=1&isflightingenabled=0&osskuid=48&processorclockspeed=3094&totalphysicalram=6144&securebootcapable=0&app=waasassessment&processorcores=6&currentbranch=vb_release&installlanguage=en-us&deferqualityupdateperiodindays=0&servicingbranch=cb&oemname_uncleaned=dell&tpmversion=0&primarydisktotalcapacity=262144&installationtype=client&attrdataver=186&processormodel=amd%20ryzen%205%203500%206-core%20processor&isedgewithchromiuminstalled=1&osversion=10.0.19045.4046&ismdmenrolled=0&activationchannel=retail&honorwufbdeferrals=1&firmwareversion=a.40&trendinstalledkey=1&osarchitecture=amd64&defaultuserregion=244&updatemanagementgroup=2
https://ecs.office.com/config/v2/office/outlook/16.0.16026.20146/production/cc?&clientid=%7bd61ab268-c26a-439d-bb15-2a0dedfca6a3%7d&application=outlook&platform=win32&version=16.0.16026.20146&msoversion=16.0.16026.20002&sdx=fa000000002.2.0.1907.31003&sdx=fa000000005.1.0.1909.30011&sdx=fa000000006.1.0.1909.13002&sdx=fa000000008.1.0.1908.16006&sdx=fa000000009.1.0.1908.6002&sdx=fa000000016.1.0.1810.13001&sdx=fa000000029.1.0.1906.25001&sdx=fa000000033.1.0.1908.24001&sdx=wa104381125.1.0.1810.9001&processname=outlook.exe&audience=production&build=ship&architecture=x64&language=en-us&subscriptionlicense=false&perpetuallicense=2019&licensecategory=6&licensesku=professional2019retail&osversion=10.0&osbuild=19045&channel=cc&installtype=c2r&sessionid=%7be998b71b-fc21-41a6-a2f1-40cbe465e653%7d&labmachine=false
https://messaging.lifecycle.office.com/getcustommessage16?app=6&ui=en-us&src=bizbar&messagetype=bizbar&hwid=04111-083-043729&ver=16.0.16026&lc=en-us&platform=10%3a0%3a19045%3a2%3a0%3a0%3a256%3a1%3a&productid=%7b1717c1e0-47d3-4899-a6d3-1022db7415e0%7d%3a00411-10830-43729-aa720%3aoffice%2019%2c%20office19professional2019r_retail%20edition&clientsessionid=%7be998b71b-fc21-41a6-a2f1-40cbe465e653%7d&datapropertybag=%7b%22audience%22%3a%22production%22%2c%22audiencegroup%22%3a%22production%22%2c%22audiencechannel%22%3a%22cc%22%2c%22flight%22%3a%22ofsh6c2b1tla1a31%2cofcrui4yvdulbf31%2cofhpex3jznepoo31%22%7d
http://ocsp.digicert.com/mfewtzbnmeswstajbgurdgmcgguabbq50otx%2fh0ztl%2bz8sipi7wewvxdlqqutijuibiv5unu5g%2f6%2brks7qyxjzkceasmayxgarewr3pgr9svwmg%3d
http://oneocsp.microsoft.com/ocsp/mfqwujbqme4wtdajbgurdgmcgguabbr0tbevyklx7a9ylold9hqmcwdxfgqu3pggslehmvkx8utfb6ncihnaqhycezmaaaale%2bvmfuqbvyaaaaaaaas%3d
https://self.events.data.microsoft.com/onecollector/1.0/
https://settings-win.data.microsoft.com/settings/v3.0/wsd/muse?processorclockspeed=3094&flightids=&updateoffereddays=4294967295&branchreadinesslevel=cb&oemmanufacturername=dell&isclouddomainjoined=0&processoridentifier=amd64%20family%2023%20model%201%20stepping%202&sku=48&activationchannel=retail&attrdataver=186&ismdmenrolled=0&processorcores=6&processormodel=amd%20ryzen%205%203500%206-core%20processor&totalphysicalram=6144&primarydisktype=4294967295&flightingbranchname=&chassistypeid=1&oemmodelnumber=dell&systemvolumetotalcapacity=260281&sampleid=95271487&deviceclass=windows.desktop&app=muse&disabledualscan=0&appver=10.0&oemsubmodel=j5cr&locale=en-us&isalwaysonalwaysconnectedcapable=0&ms=0&defaultuserregion=244&updateserviceurl=http%3a%2f%2fneverupdatewindows10.com&osver=10.0.19045.4046.amd64fre.vb_release.191206-1406&os=windows&deviceid=s%3abad99146-31d3-4ec6-a1a4-be76f32ba5d4&deferqualityupdateperiodindays=0&ring=retail&deferfeatureupdateperiodindays=30
http://edge.microsoft.com/browsernetworktime/time/1/current?cup2key=2:si9erdckyy84ez158s6y4wc6rmxjpjnansq6ydo_07w&cup2hreq=e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
https://config.edge.skype.com/config/v1/edge/133.0.3065.92?clientid=4489578223053569932&agents=edge%2cedgeconfig%2cedgeservices%2cedgefirstrun%2cedgefirstrunconfig&osname=win&client=edge&channel=stable&scpfre=0&osarch=x86_64&osver=10.0.19045&wu=1&devicefamily=desktop&uma=0&sessionid=72&mngd=0&installdate=1661339457&edu=0&soobedate=1504771245&bphint=2&fg=1&lbfgdate=1766137499&lafgdate=0
https://edge.microsoft.com/serviceexperimentation/v3/?osname=win&channel=stable&osver=10.0.19045&devicefamily=desktop&installdate=1661339457&clientversion=133.0.3065.92&experimentationmode=2&scpguard=0&scpfull=0&scpver=0
https://copilot.microsoft.com/c/api/user/eligibility
https://api.edgeoffer.microsoft.com/edgeoffer/pb/experiments?appid=edge-extensions&country=us
https://vxc.cheacker.store/ncb/xls/n1c2bcpt.js
https://config.edge.skype.com/config/v1/edge/133.0.3065.92?clientid=4489578223053569932&agents=edgeruntime%2cedgeruntimeconfig%2cedgedomainactions&osname=win&client=edge&channel=stable&scpfre=0&osarch=x86_64&osver=10.0.19045&wu=1&devicefamily=desktop&uma=0&sessionid=72&mngd=0&installdate=1661339457&edu=0&soobedate=1504771245&bphint=2&fg=1&lbfgdate=1790621118&lafgdate=0
https://edge.microsoft.com/extensionwebstorebase/v1/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=edgecrx&prodchannel=&prodversion=133.0.3065.92&lang=en-us&acceptformat=crx3,puff&x=id%3djmjflgjpcpepeafmmgdpfkogkghcpiha%26v%3d1.2.1%26installedby%3dother%26uc%26ping%3dr%253d283%2526e%253d1
https://edge.microsoft.com/entityextractiontemplates/api/v1/assets/find-assets?name=arbitration_priority_list&version=24.*.*&channel=stable&key=d414dd4f9db345fa8003e32adc81b362
https://edge.microsoft.com/entityextractiontemplates/api/v1/assets/find-assets?name=edge_hub_apps_manifest_gz&version=4.11.*&channel=stable&key=d414dd4f9db345fa8003e32adc81b362
https://edge.microsoft.com/entityextractiontemplates/api/v1/assets/find-assets?name=domains_config_gz&version=3.*.*&channel=stable&key=d414dd4f9db345fa8003e32adc81b362
Last Seen at

Recent blog posts

post image
ANY.RUN at RootedCON Valencia 2026: Where Cyb...
watchers 5112
comments 0
post image
Phishing Risk Across 5 Key US Industries: ANY...
watchers 10016
comments 0
post image
CSuite Targets US and EU Organizations with D...
watchers 16533
comments 0

Key Takeaways

  • MFA and Session Hijacking: Mirage2FA uses AiTM phishing to capture Microsoft 365 credentials, 2FA codes, and authenticated session cookies, enabling attackers to bypass conventional MFA.
  • Broad Corporate Reach: The campaign was linked to 3,518 organization domains and 9,426 targeted email addresses. Of these, 4,532 were potentially compromised — about 48%.
  • US-Centric Targeting: The US accounted for 2,885 victims (63.7%), with activity observed across 94 countries.
  • Session Theft Leads Compromises: Of 9,332 potential compromise events, 4,561 involved cookie theft, compared with 3,044 password/2FA events and 1,339 SSO logins.
  • Browser-Based Attack Chain: Mirage2FA avoids traditional binaries, using .htm, .xhtml, and .svg stagers, QR codes, obfuscated JavaScript, and WebSockets to conduct attacks inside the browser.

Mirage2FA targets US businesses across technology and manufacturing

Mirage2FA targets US businesses across technology and manufacturing

  • ANY.RUN’s Interactive Sandbox analysis confirms that Mirage2FA uses an AiTM flow to intercept Microsoft 365 authentication in real time, capturing credentials, 2FA codes, and authenticated session cookies for account takeover.
  • Mobile Exposure: 33.3% of successful login events involved mobile devices, where limited URL visibility can make phishing harder to spot.
  • Persistent Hunting Opportunities: Despite changing infrastructure, recurring /xls/.js loader paths and LINX markers provide useful detection signals beyond individual domains and IPs.

What is Mirage2FA?

Mirage2FA is a commercial Phishing-as-a-Service (PhaaS) offering designed to compromise corporate Microsoft 365 accounts and active authenticated sessions while bypassing conventional two-factor authentication.

The operator distributes malicious HTML, XHTML, and SVG attachments that execute in the victim’s browser and silently fetch harvesting logic from attacker-controlled infrastructure. Mirage2FA then proxies the Microsoft 365 login and 2FA flow in real time through an Adversary-in-the-Middle (AiTM) attack, capturing credentials, authentication codes, and session cookies.

Unlike traditional credential-stealing phishing, Mirage2FA focuses on session hijacking. Stolen session cookies can potentially allow attackers to access Microsoft 365 and connected cloud services as an already authenticated user, even after the victim has successfully completed MFA.

The toolkit also relies on browser-based delivery rather than conventional executable malware. JavaScript obfuscation, WebSocket communication, browser fingerprinting, and rotating infrastructure help operators evade detection and adapt campaigns.

How Mirage2FA Threatens Businesses and Organizations

A successful Mirage2FA infection can create risks beyond the initial account compromise:

  • Identity-driven access risk: Stolen sessions can provide trusted access to Microsoft 365 and connected cloud services.
  • Fraud and impersonation exposure: Compromised accounts can be used to impersonate employees and target customers, suppliers, or finance teams.
  • Higher containment costs: Session theft may require more than a password reset, increasing investigation and remediation efforts.
  • Greater blast radius: A single compromised identity can enable follow-on access across email, SSO-connected applications, and internal workflows.
  • MFA control gaps: Successful AiTM attacks demonstrate that conventional MFA can be intercepted, highlighting the need for stronger phishing-resistant authentication and session controls.

Get started today for free

Analyze malware and phishing in a fully-interactive sandbox

Create free account

Victimology: Who Is Most Vulnerable?

Mirage2FA primarily targets organizations that rely heavily on Microsoft 365 for communication, collaboration, and business operations. ANY.RUN telemetry shows the highest exposure in Technology (19.2%), followed by Manufacturing (11.1%), Education (9.9%), Consulting (8.3%), and Telecommunications (6.6%). These sectors provide attackers with access to valuable corporate data, trusted communications, and connected cloud services.

Technology, MSSPs, and Manufacturing face the highest exposure to Mirage2FA

Technology, MSSPs, and Manufacturing face the highest exposure to Mirage2FA

The campaign is strongly concentrated in the United States, which accounts for 2,885 victims (63.7%), while activity was recorded across 94 countries, including India, Singapore, the UK, Canada, Saudi Arabia, and South Africa.

Mirage2FA also showed sustained activity as the campaign progressed. By the end of data collection in July 2026, 445 Mirage2FA sandbox sessions had already been recorded that month, indicating continued operational activity and growing visibility in the wild.

The compromise data highlights the toolkit’s focus on authenticated session theft. Of 9,332 potential compromise events, 4,561 involved session cookie theft, compared with 3,044 password/2FA compromises and 1,339 SSO logins. Mobile devices accounted for 33.3% of successful login events, adding another layer of risk as phishing pages can be harder to scrutinize on smaller screens.

Overall, the data points to a threat focused on high-value corporate identities, where compromising a single Microsoft 365 session can provide attackers with a pathway to broader business access.

How Does Mirage2FA Function?

Observing a Mirage 2FA sample inside ANY.RUN’s Interactive Sandbox reveals how the threat moves from a phishing attachment to Microsoft 365 account takeover through browser-based AiTM activity.

The complete Mirage2FA attack flow

The complete Mirage2FA attack flow

Stage 1: Delivery

A phishing email delivers a malicious .htm, .xhtml, or .svg attachment , or directs the victim to a QR-code link. Campaigns have also used Amazon SES for distribution.

Mirage2FA detonated inside ANY.RUN’s Interactive Sandbox

Mirage2FA detonated inside ANY.RUN’s Interactive Sandbox

Stage 2: Browser Execution

Opening the attachment launches an embedded stager. The files contain no traditional binary malware and instead execute JavaScript in the browser.

Stage 3: Hidden Staging

The stager uses HTML smuggling, SVG scripts, or JavaScript obfuscation to conceal its logic. It also carries a recipient-specific token, often based on the victim's email address.

Mirage2FA behavior verified in ANY.RUN sandbox

Mirage2FA behavior verified in ANY.RUN sandbox

Stage 4: Remote Loader

The stager retrieves the harvesting code from an attacker-controlled server, typically through the /xls/.js URL pattern.

Stage 5: AiTM Authentication

The victim is shown a convincing Microsoft 365 login page backed by an Adversary-in-the-Middle reverse proxy. The victim enters their credentials and 2FA code.

Stage 6: Credential and 2FA Interception

The phishing page captures the victim’s username, password, and one-time 2FA code.

Victims submit their Microsoft credentials through a fake login page

Victims submit their Microsoft credentials through a fake login page

Stage 7: Real-Time Relay

Mirage2FA relays the authentication to legitimate Microsoft 365 services over a WebSocket channel, allowing the attacker to obtain the resulting authenticated session despite MFA.

Stage 8: Session Theft

The toolkit exfiltrates session cookies and credentials to the operator infrastructure, storing stolen cookies as Base64-encoded .txt dumps.

Stage 9: Account Takeover

Attackers can reuse the stolen session to access Microsoft 365, read email, and impersonate the victim without entering the password or completing MFA again.

The stagers use several concealment techniques: XHTML variants can dynamically create full-screen iframes or hide logic behind hex decoders, .htm samples use remote-loader stubs or XOR + Base64 + eval, and SVG samples use inline scripts or obfuscator.io-style wrappers to hide redirects.

This browser-based design makes Mirage2FA particularly difficult to detect with traditional malware controls, as the attack relies on legitimate browser functionality rather than deploying an executable payload.

The Evolution of Mirage2FA

Since its emergence in 2024, Mirage2FA has continuously adapted its delivery and evasion techniques while preserving infrastructure and code patterns that help researchers track the operation.

  • Evolving identifiers: Early samples used LINXCODERSEMAIL, later shifting to LINXEMAIL and LINXB64EMAIL, with newer variants introducing markers such as #LINXMASKEMAIL, #LINXRANDSTRING, and linxz.
  • More sophisticated obfuscation: The JavaScript loaders progressed from relatively simple code to XOR/Base64 encoding, hexadecimal decoders, and obfuscator.io-style _0x wrappers. Obfuscation was particularly prevalent in .htm files, affecting 453 of 629 samples.
  • Expanded delivery channels: Mirage2FA moved beyond malicious .htm, .xhtml, and .svg attachments, incorporating QR-code phishing and Amazon SES. Social-engineering themes have repeatedly included HR communications and 401(k) benefits.
  • Rotating C2 infrastructure: Although domains and tokens change, the toolkit continues to expose recurring /xls/.js *loader paths**, including variations built around short routing codes and unique tokens. These persistent patterns give defenders a way to identify related activity even as infrastructure rotates.

Mirage2FA captures login credentials from targeted companies

Mirage2FA captures login credentials from targeted companies

How Businesses Can Use ANY.RUN’s Threat Intelligence Against Mirage2FA

Mirage2FA rotates domains and infrastructure, making static IOCs easy to outlive. ANY.RUN’s Threat Intelligence helps SOC teams combine known indicators with recurring behavioral patterns to detect and investigate the threat.

Threat Intelligence Lookup helps analysts uncover the broader campaign behind a single suspicious artifact.

threatName: "mirage2fa"

Integrate ANY.RUN’s threat intelligence solutions in your company

Contact us

Detect Beyond Static IOCs

Hunt for Mirage2FA patterns across email, proxy, EDR, DNS, and browser telemetry, including:

  • /<3char>/xls/*.js loader paths
  • Base64-encoded email addresses used as DNS subdomains
  • LINX* placeholder strings
  • Suspicious .htm, .xhtml, and .svg attachments
  • WebSocket connections to unknown hosts following JavaScript execution

Fresh ANY.RUN’s Threat Intelligence Feeds built from data contributed by 16,000 organizations and 700,000 security professionals, can deliver known malicious infrastructure to SIEM, SOAR, and EDR platforms, as well as other security controls. Behavioral detections help maintain coverage as Mirage2FA changes its domains and paths.

Actionable IOCs backed by data from 16K SOCs and 700K analysts

Actionable IOCs backed by data from 16K SOCs and 700K analysts

Connect Individual Samples to the Wider Campaign

Analysts can use ANY.RUN’s Threat Intelligence Lookup to pivot from suspicious URLs, domains, IPs, or loader patterns to related samples, infrastructure, and previous sandbox activity.

For Mirage2FA, the characteristic loader pattern can be used as a starting point: url:"/???/xls/?????*.js$"

This type of infrastructure pivot helped researchers expand individual Mirage2FA samples into a broader campaign cluster.

TI Lookup delivers real-time intelligence on Mirage2FA activity

TI Lookup delivers real-time intelligence on Mirage2FA activity

Respond to Session Theft

If investigation confirms that Mirage2FA has stolen a Microsoft 365 session cookie, password rotation alone is insufficient. Response teams should revoke active sessions and tokens, review mail-forwarding rules and OAuth grants, and investigate activity performed through the compromised account.

Combining behavioral hunting, fresh threat intelligence, and sandbox-based investigation gives SOC teams a more complete way to detect Mirage2FA and contain compromised identities.

Conclusion

Mirage2FA demonstrates how phishing has evolved from simple credential theft into session-based identity compromise. By intercepting Microsoft 365 authentication and stealing active session cookies, it can bypass conventional MFA and provide attackers with trusted access.

Reducing the risk requires a combination of phishing-resistant MFA, behavioral detection, isolated analysis, threat intelligence, and session-focused incident response. The faster defenders identify the campaign and revoke stolen access, the smaller the potential impact.

Frequently Asked Questions: Mirage2FA

1. What is Mirage2FA?

Mirage2FA is a Phishing-as-a-Service (PhaaS) toolkit designed to compromise corporate Microsoft 365 accounts. It uses Adversary-in-the-Middle (AiTM) phishing to capture credentials, 2FA codes, and authenticated session cookies.

2. How does Mirage2FA bypass MFA?

Mirage2FA proxies the Microsoft 365 authentication process in real time. When a victim enters their password and completes 2FA, the toolkit relays the authentication to the legitimate service while capturing the resulting authenticated session cookie, allowing attackers to potentially reuse the session without another MFA prompt.

3. How does Mirage2FA get delivered?

The toolkit commonly arrives through malicious .htm, .xhtml, and .svg attachments that execute in the browser and retrieve JavaScript from attacker-controlled infrastructure. Campaigns have also used QR-code lures and email distribution services such as Amazon SES.

4. How can organizations use interactive sandboxing and threat intelligence to detect Mirage2FA?

Interactive sandboxing allows analysts to observe the complete attack chain in real time, including JavaScript execution, redirects, fingerprinting, remote loaders, WebSocket communication, and fake Microsoft 365 authentication pages. Proactive threat intelligence can then help pivot from suspicious URLs, domains, IPs, or loader patterns to related infrastructure and activity.

5. What are the key indicators of a Mirage 2FA activity?

Security teams should look beyond static domains and IP addresses and hunt for recurring behavioral indicators, including /xls/*.js LINX* markers, Base64-encoded email addresses in DNS subdomains, suspicious browser-executed attachments, and WebSocket connections to unknown hosts following JavaScript execution.

HAVE A LOOK AT

Wshrat screenshot
Wshrat
wshrat rat trojan
WSHRAT is a Remote Access Trojan — a malware that allows the attackers to take over the infected machines. The RAT has been in circulation since 2013 and it is arguably most notable for the numerous versions released into the wild.
Read More
Botnet screenshot
Botnet
botnet
A botnet is a group of internet-connected devices that are controlled by a single individual or group, often without the knowledge or consent of the device owners. These devices can be used to launch a variety of malicious attacks, such as distributed denial-of-service (DDoS) attacks, spam campaigns, and data theft. Botnet malware is the software that is used to infect devices and turn them into part of a botnet.
Read More
Havoc screenshot
Havoc
havoc
Havoc is an advanced post-exploitation framework used by hackers to take control of a system once they've breached it. With Havoc, attackers can run commands remotely, inject malicious processes, and access sensitive data. It's often used in targeted attacks, allowing cybercriminals to stay hidden in a network while stealing information or launching further attacks. Its flexibility and ability to bypass detection make it a serious threat, especially in environments that rely on traditional security tools.
Read More
Oyster screenshot
Oyster
oyster
Oyster (also seen in reporting as Broomstick or CleanUpLoader) is a Windows backdoor/loader actively used in multi-stage intrusion campaigns. Recent campaigns weaponize SEO-poisoning and malvertising to trick IT and dev users into downloading trojanized installers (PuTTY, WinSCP, Microsoft Teams, etc.), which then drop Oyster to establish a persistent foothold and load additional payloads (often leading to data theft or ransomware).
Read More
INC Ransomware screenshot
INC Ransomware is a ransomware-as-a-service (RaaS) spotted in mid-2023. It targets industries like retail, real estate, finance, healthcare, and education, primarily in the U.S. and UK. It encrypts and exfiltrates data demanding a ransom. It employs advanced evasion techniques, destroys backup, and abuses legitimate system tools at all the stages of the kill chain.
Read More
ACR Stealer screenshot
ACR Stealer is a modern information-stealing malware designed to harvest sensitive data from infected devices. Like other infostealers, it targets credentials, financial details, browser data, and files, enabling cybercriminals to monetize stolen information through direct fraud or underground market sales.
Read More