Mirage2FA: Phishing Toolkit Hijacks Microsoft 365 Sessions, Bypasses MFA to Steal Sensitive Data
August 25, 2026
Mirage2FA is a phishing-as-a-service toolkit that hijacks Microsoft 365 sessions in real time using Adversary-in-the-Middle (AiTM) to bypass MFA and steal session cookies.
Active from 2024 through 2026, the Mirage2FA campaign targets Microsoft 365 accounts by abusing legitimate login flows to bypass two-factor authentication and harvest passwords and session cookies.
Researchers note recurring technical patterns, such as /xls/*.js loader paths and LINX markers, to help hunters detect related activity beyond individual domains or IPs.
The platform blends trusted document platforms, legitimate redirects, and disposable infrastructure to deliver a turnkey session-stealing flow for buyers.
The campaign predominantly targets US organizations, with victims spanning 94 countries and impacts across technology, manufacturing, and education sectors.
Analysis indicates nearly half of targeted email addresses may have been compromised, with the majority of victims in the United States and 4,532 unique organization email domains affected.
EvilTokens represents a shift in the phishing-as-a-service model by automating post-capture fraud mechanics and inbox analysis, lowering the skill bar for attackers.
Defenders should block risky attachments, scrutinize QR-code campaigns and SES-driven outreach, and analyze unknown files in sandbox environments before containment actions.
NovaCookies functions as a variant of Sneaky 2FA, supporting multiple identity providers and using a fully managed PhaaS model hosted by the operator rather than affiliates.
NovaCookies is connected to broader phishing-as-a-service trends, highlighting evolving sophistication and monetization of AiTM-style attacks.
Attack infrastructure appears centralized around LinX Coders, with shared C2 domains, IPs, and user tokens that indicate a reusable phishkit.
Mobile devices contributed about one-third of successful login events, underscoring broad phishing reach and limited URL visibility on mobile.
Summary based on 4 sources
Get a daily email with more Tech stories
Sources

The Hacker News • Aug 25, 2026
Mirage2FA Surge Hits 4,500 US and EU Companies, Abusing Microsoft 365 Login Flows