Mirage2FA phishing kit hits thousands of Microsoft 365 users
Researchers at ANY.RUN say a phishing-as-a-service kit called Mirage2FA has targeted more than 3,500 organizations in 94 countries, mostly in the United States, since 2024. The kit uses fake Microsoft 365 login pages to steal passwords and session cookies, letting attackers slip past two-factor authentication without installing any malware.
- Started
- Aug 25, 2026
- Latest activity
- Sep 10, 2026
- Attributed to
- LinX CodersLikely
- Where
- United States, Worldwide
- Sectors
- Multiple sectors
- Scale
- 3,518 organization domains and 4,532 potential victims across 94 countries, including 2,885 victims in the United States.
Current status
ANY.RUN lists Mirage2FA as last seen on September 10, 2026.
Active: Confirmed and still going. Attacker activity or disruption is continuing.
Who is behind it
Threat intelligence researchers ShiFu and raptur3 at ANY.RUN linked the Mirage2FA kit to a seller they track as LinX Coders; no government agency has confirmed this.
Impact
Attackers used fake Microsoft 365 login pages to steal passwords and active login sessions, letting them get into business email accounts without needing a second factor. Researchers estimate up to 48% of the email addresses targeted may have had their accounts compromised. No malware was installed on victim machines.
What to do
Be suspicious of any Microsoft 365 login page reached through an email link, check the web address carefully before entering a password, and turn on phishing-resistant login methods like security keys if your organization offers them.
Timeline
-
Sep 10, 2026
ANY.RUN's Mirage2FA profile listed the campaign as last seen on September 10, 2026, confirming observed activity after the previous September 7 entry.
Activeany.run -
Sep 7, 2026
ANY.RUN's current Mirage2FA profile listed the campaign as last seen on September 7, indicating confirmed observed activity after the previous August 25 entry.
Activeany.run -
Sep 2, 2026
Cybersecurity News reported that ANY.RUN's August analysis found Mirage2FA had affected more than 4,000 US victims in an operation spanning 46 countries.
Activecybersecuritynews.com -
Aug 25, 2026
ANY.RUN researchers published findings tying the Mirage2FA phishing kit to over 9,300 potential Microsoft 365 account compromise events across more than 3,500 organizations in 94 countries since 2024.
Activecybersecuritynews.com
Sources
- Mirage2FA Surge Hits 4,500 US and EU Companies, Abusing Microsoft 365 Login Flows The Hacker News Aug 25, 2026
- Mirage2FA Phishing Kit Bypasses MFA to Hijack Microsoft 365 Sessions, Targeting 3,500+ Organizations Cyber Security News Aug 25, 2026
- Mirage2FA Hijacks Companies' Microsoft 365 Sessions, with Over 4K Victims in the US HackerNoon Aug 25, 2026
- Mirage2FA Phishing Analysis, Overview by ANY.RUN ANY.RUN Sep 7, 2026
- Hackers Target US and EU Firms With Microsoft 365 Session Hijacking and RMM Abuse Cybersecurity News Sep 2, 2026
Related reports
- Mirage2FA phishing kit steals Microsoft 365 accounts Aug 25, 2026