Mirage2FA: The Phishing Kit Silently Bypassing Your MFA

Published: August 25, 2026

Your two-factor authentication might be the weakest link in your security stack, and a new wave of attacks is proving it in real time.

Security researchers at ANY.RUN have been tracking a phishing-as-a-service operation called Mirage2FA that has quietly targeted thousands of organizations since 2024. The name is fitting: it turns the safety net you rely on into a mirage. Instead of cracking passwords, attackers hijack the sessions behind them, walking straight through your Microsoft 365 login flow and past the MFA prompt that was supposed to stop them.

What Mirage2FA actually does

Mirage2FA is not your average credential harvester. It is an adversary-in-the-middle (AiTM) kit built to abuse legitimate Microsoft 365 login flows. A victim clicks a convincing link and lands on a fake but near-perfect Microsoft sign-in page. The toolkit sits between the user and the real service, relaying the password, the session cookie, and even the one-time code you type in. The user sees a normal login. The attacker watches everything happen, then walks away with an authenticated session.

That detail matters. Once a session is stolen, attackers do not need your password anymore. They have your trusted identity, with access to corporate email, SSO-connected apps, and every service that trusts that login. From there it is a short path to impersonation, invoice fraud, and deeper compromise.

The numbers behind the campaign

The scale is what makes this worth paying attention to. ANY.RUN's research links Mirage2FA to 4,532 unique organizational email domains across the US, India, Singapore, the UK, Canada, Saudi Arabia, South Africa, and beyond. The US alone accounts for 63.7 percent of victims. Roughly 48 percent of targeted email addresses were potentially compromised, and researchers logged more than 9,000 potential compromise events involving cookie and password theft, SSO logins, and 2FA bypass.

Technology, manufacturing, and education took the heaviest hits. Those are exactly the sectors where a hijacked Microsoft 365 account can cascade into business email compromise, supply chain fraud, or a ransomware entry point.

Why your MFA won't save you

Here is the uncomfortable part: the MFA you already have is part of the problem. Traditional one-time codes, SMS texts, and app approvals can all be relayed in an AiTM attack. The victim types the code into the fake page, and the attacker forwards it to the real one before it expires. From the user's perspective, login worked perfectly. From the attacker's perspective, they just borrowed your identity.

This is why security teams keep pushing toward phishing-resistant authentication. Hardware security keys and passkeys bind the login to the device and the domain, so there is no reusable code to relay. If you cannot move to those today, at least treat session theft as an identity incident: revoke sessions and tokens, not just passwords, when you see suspicious activity.

What to do about it

Start by moving past the "MFA is enough" mindset. Audit who has access to Microsoft 365 and SSO-connected apps, and cut stale sessions aggressively. Enable conditional access policies that challenge logins from unusual locations or devices. Watch for the hallmarks of AiTM activity: odd redirects, unexpected WebSocket traffic, and logins that arrive from two places at once.

For SOC teams, sandboxing suspicious URLs and emails before users click them still catches a lot of this. Behavioral detection matters too, because the payload here is a trusted session, not a malicious file.

The Mirage2FA campaign is a reminder that authentication security is not a checkbox. It is a moving target. The attackers are not breaking your defenses; they are walking through the door you left open, and they are using your own MFA to unlock it.

Thumbnail: https://upload.wikimedia.org/wikipedia/commons/thumb/1/19/Example_phishing_email.svg/1920px-Example_phishing_email.svg.png
License: CC BY 4.0 (Wikimedia Commons)