Active Medium impact Data breach Checked 1d ago

Mirage2FA phishing kit hits thousands of Microsoft 365 users

Researchers at ANY.RUN say a phishing-as-a-service kit called Mirage2FA has targeted more than 3,500 organizations in 94 countries, mostly in the United States, since 2024. The kit uses fake Microsoft 365 login pages to steal passwords and session cookies, letting attackers slip past two-factor authentication without installing any malware.

Started
Aug 25, 2026
Latest activity
Sep 10, 2026
Attributed to
LinX CodersLikely
Where
United States, Worldwide
Sectors
Multiple sectors
Scale
3,518 organization domains and 4,532 potential victims across 94 countries, including 2,885 victims in the United States.

Current status

ANY.RUN lists Mirage2FA as last seen on September 10, 2026.

Active: Confirmed and still going. Attacker activity or disruption is continuing.

Who is behind it

Threat intelligence researchers ShiFu and raptur3 at ANY.RUN linked the Mirage2FA kit to a seller they track as LinX Coders; no government agency has confirmed this.

Impact

Attackers used fake Microsoft 365 login pages to steal passwords and active login sessions, letting them get into business email accounts without needing a second factor. Researchers estimate up to 48% of the email addresses targeted may have had their accounts compromised. No malware was installed on victim machines.

What to do

Be suspicious of any Microsoft 365 login page reached through an email link, check the web address carefully before entering a password, and turn on phishing-resistant login methods like security keys if your organization offers them.

Timeline

  1. Sep 10, 2026

    ANY.RUN's Mirage2FA profile listed the campaign as last seen on September 10, 2026, confirming observed activity after the previous September 7 entry.

    Activeany.run
  2. Sep 7, 2026

    ANY.RUN's current Mirage2FA profile listed the campaign as last seen on September 7, indicating confirmed observed activity after the previous August 25 entry.

    Activeany.run
  3. Sep 2, 2026

    Cybersecurity News reported that ANY.RUN's August analysis found Mirage2FA had affected more than 4,000 US victims in an operation spanning 46 countries.

    Activecybersecuritynews.com
  4. Aug 25, 2026

    ANY.RUN researchers published findings tying the Mirage2FA phishing kit to over 9,300 potential Microsoft 365 account compromise events across more than 3,500 organizations in 94 countries since 2024.

    Activecybersecuritynews.com

Sources

Related reports