LinX Coders is a threat group attributed to the Mirage2FA phishing-as-a-service operation, active from at least September 2024 through July 2026. The group targets Microsoft 365 and Microsoft Entra ID users through adversary-in-the-middle phishing that relays victim authentication traffic to legitimate Microsoft services in real time. Its campaigns capture usernames, passwords, MFA codes, and authenticated session cookies, enabling account takeover and access to email, cloud documents, and SSO-connected enterprise applications without a further MFA prompt. LinX Coders uses high-volume HR and employee-benefit lures delivered through malicious browser-executed HTML, XHTML, and SVG attachments, as well as QR-code phishing flows. The toolkit employs per-recipient tracking, JavaScript obfuscation, remote loaders, WebSocket-based proxying, IP and browser fingerprinting, and Microsoft-branded credential prompts. Attribution is supported by recurring LinX-branded build markers, associated Telegram bots and channel branding, operator testing activity, and overlapping operational infrastructure. Observed targeting spans 94 countries, predominantly affecting organizations in the United States, with technology, manufacturing, education, consulting, telecommunications, healthcare, and financial organizations among the affected sectors.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
16 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
93 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Operates and markets an adversary-in-the-middle phishing kit that steals Microsoft credentials, MFA codes, and authenticated session cookies/tokens. The campaign uses high-volume HR and 401(k)-themed email lures, HTML/XHTML/SVG attachments and QR codes, JavaScript loaders, WebSocket-based credential relay, and session theft for subsequent mailbox access and user impersonation.
Operates and markets the Mirage2FA phishing-as-a-service toolkit, conducting adversary-in-the-middle phishing campaigns against Microsoft 365 users. The kit uses HTML, XHTML, SVG, and QR-code lures to proxy Microsoft authentication in real time, capture credentials, MFA codes, and authenticated session cookies, then reuse sessions for mailbox access and impersonation.
Operates the Mirage2FA phishing-as-a-service toolkit to compromise Microsoft 365 accounts by bypassing MFA using an adversary-in-the-middle architecture, capturing credentials, 2FA codes, and authenticated session cookies in real time.
Operating and marketing the Mirage2FA phishing-as-a-service platform to conduct adversary-in-the-middle phishing that steals authenticated Microsoft 365 session cookies after MFA completion, enabling account and SSO session hijacking.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.