Mirage2FA: Phishing Toolkit Hijacks Microsoft 365 Sessions, Bypasses MFA to Steal Sensitive Data

August 25, 2026
Mirage2FA: Phishing Toolkit Hijacks Microsoft 365 Sessions, Bypasses MFA to Steal Sensitive Data
  • Mirage2FA is a phishing-as-a-service toolkit that hijacks Microsoft 365 sessions in real time using Adversary-in-the-Middle (AiTM) to bypass MFA and steal session cookies.

  • Active from 2024 through 2026, the Mirage2FA campaign targets Microsoft 365 accounts by abusing legitimate login flows to bypass two-factor authentication and harvest passwords and session cookies.

  • Researchers note recurring technical patterns, such as /xls/*.js loader paths and LINX markers, to help hunters detect related activity beyond individual domains or IPs.

  • The platform blends trusted document platforms, legitimate redirects, and disposable infrastructure to deliver a turnkey session-stealing flow for buyers.

  • The campaign predominantly targets US organizations, with victims spanning 94 countries and impacts across technology, manufacturing, and education sectors.

  • Analysis indicates nearly half of targeted email addresses may have been compromised, with the majority of victims in the United States and 4,532 unique organization email domains affected.

  • EvilTokens represents a shift in the phishing-as-a-service model by automating post-capture fraud mechanics and inbox analysis, lowering the skill bar for attackers.

  • Defenders should block risky attachments, scrutinize QR-code campaigns and SES-driven outreach, and analyze unknown files in sandbox environments before containment actions.

  • NovaCookies functions as a variant of Sneaky 2FA, supporting multiple identity providers and using a fully managed PhaaS model hosted by the operator rather than affiliates.

  • NovaCookies is connected to broader phishing-as-a-service trends, highlighting evolving sophistication and monetization of AiTM-style attacks.

  • Attack infrastructure appears centralized around LinX Coders, with shared C2 domains, IPs, and user tokens that indicate a reusable phishkit.

  • Mobile devices contributed about one-third of successful login events, underscoring broad phishing reach and limited URL visibility on mobile.

Summary based on 4 sources


Get a daily email with more Tech stories

More Stories