Mirage2FA is a phishing-as-a-service adversary-in-the-middle framework attributed to LinX Coders. It targets Microsoft 365 and Microsoft Entra ID users by proxying legitimate authentication workflows through attacker-controlled phishing portals. The framework captures user credentials and one-time MFA codes, then intercepts authenticated session cookies after successful login, allowing operators to reuse the sessions without further MFA challenges. Stolen sessions can enable access to Exchange Online mailboxes, SharePoint, OneDrive, and SSO-connected enterprise applications, as well as victim impersonation. Campaigns use HR and employee-benefits lures delivered through phishing emails, malicious HTML, XHTML, or SVG attachments, embedded links, and QR codes. Browser-based JavaScript stagers retrieve remotely hosted harvesting logic, employ obfuscation, and use WebSocket communications to relay authentication data. Mirage2FA activity has targeted organizations internationally, including technology, manufacturing, education, healthcare, consulting, and finance sectors. The operation is browser-based and does not require deployment of a binary payload on the victim system.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
ANY.RUN’s Threat Intelligence Lookup surfaced dozens of related loader URLs on the same IP address; a single /xls/*.js query exposes the loader cluster on 185.174.100.224 and is described as providing intel related to Mirage2FA attacks.
16 distinct techniques documented for this family, organized by ATT&CK tactic.
Because the attacker holds a valid session rather than just a password, a password reset does not evict them... [cookies are] ready to be replayed against Microsoft 365, SSO-connected applications, and internal workflows.
A sophisticated Phishing-as-a-Service (PhaaS) platform marketed as Mirage2FA is enabling threat actors to bypass multi-factor authentication (MFA) by allowing Microsoft 365 users to complete their regular login process before covertly stealing the authenticated session.
Once opened, the file runs a stager that leverages per-recipient tokens like LINXB64EMAIL to retrieve harvesting logic from remote script paths such as /xls/<token>.js . Obfuscated HTML decodes Base64 payloads and applies XOR operations using key 0xAD , while SVG lures trigger inline scripts that redirect the browser to the active phishing host.
Its obfuscated counterpart hides the logic behind a hex-to-string decoder... The obfuscated .htm variant... Base64-decodes a blob, XORs every byte with 0xAD (173), and passes the result to eval().
The credentials and 2FA code are relayed to the legitimate Microsoft service over that WebSocket channel (T1557, T1111).
The browser pulls the loader... opens a WebSocket to the command-and-control server... The proxy receives a valid authenticated session... and [it is] reused to read mail and impersonate the user (T1071.001).
93 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
Other indicator types observed in public reporting.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A browser-based adversary-in-the-middle phishing kit delivered through HTML, XHTML, SVG, and QR-code lures. It presents Microsoft-branded login prompts, proxies submitted credentials and MFA codes to Microsoft in real time through a WebSocket channel, captures the resulting authenticated session, and enables mailbox access and user impersonation. Its stagers and JavaScript loaders use per-recipient tokens and increasingly employ Base64, XOR, hex decoding, and JavaScript obfuscation.
An adversary-in-the-middle phishing framework that proxies legitimate Microsoft 365 authentication flows, captures credentials and MFA submissions, and steals authenticated session cookies to hijack user sessions and access mailboxes, SharePoint, OneDrive, and SSO-connected enterprise applications without further prompts.
Named phishing kit/tool referenced in a related article title about a phishing attempt against a large holding company.
Mirage2FA is described as the tool used in a phishing attempt against a large holding company, consistent with an adversary-in-the-middle phishing framework used to capture credentials and likely bypass MFA.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.