Mirage2FA is a phishing-as-a-service adversary-in-the-middle framework used to target Microsoft 365 and Microsoft Entra ID users. It operates by placing an attacker-controlled portal between the victim and legitimate Microsoft authentication services, proxying the login flow in real time so victims complete their normal sign-in and multi-factor authentication process while the operator captures submitted credentials and authenticated session cookies. This enables session hijacking and follow-on access to cloud email, file repositories, and single sign-on-connected enterprise applications without requiring additional MFA prompts.
The platform’s activity has been associated with a threat group identified as LinX Coders. Observed campaigns have targeted organizations across numerous countries, with notable concentration in the United States, and have affected sectors including technology, manufacturing, education, healthcare, consulting, and finance. Reported lure themes included corporate human-resources and benefits notifications.
Mirage2FA delivery has relied on browser-based phishing content distributed through links and HTML-family attachments, including XHTML and SVG formats. The phishing chain uses obfuscated client-side scripts and persistent communications to relay authentication data to legitimate services and return responses to the victim, allowing the attack to remain transparent during login. The operation is notable for functioning entirely within the browser rather than requiring deployment of a traditional binary payload.
Its core capabilities are credential theft and, more prominently, theft of authenticated session material after MFA completion. Because compromise centers on active sessions and refresh tokens, remediation requires revocation of those sessions rather than password reset alone.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
A sophisticated Phishing-as-a-Service (PhaaS) platform marketed as Mirage2FA is enabling threat actors to bypass multi-factor authentication (MFA) by allowing Microsoft 365 users to complete their regular login process before covertly stealing the authenticated session.
8 distinct techniques documented for this family, organized by ATT&CK tactic.
Once opened, the file runs a stager that leverages per-recipient tokens like LINXB64EMAIL to retrieve harvesting logic from remote script paths such as /xls/<token>.js . Obfuscated HTML decodes Base64 payloads and applies XOR operations using key 0xAD , while SVG lures trigger inline scripts that redirect the browser to the active phishing host.
Once Microsoft validates the authentication challenge and issues session tokens, the phishing engine intercepts and retains the authenticated session cookies alongside captured credentials.
Threat researchers at ANY.RUN discovered that the Adversary-in-the-Middle (AiTM) framework generated thousands of potential compromise events from late 2024 through 2026, with the overwhelming majority resulting in hijacked session cookies rather than isolated password theft.
Threat researchers at ANY.RUN discovered that the Adversary-in-the-Middle (AiTM) framework generated thousands of potential compromise events from late 2024 through 2026, with the overwhelming majority resulting in hijacked session cookies rather than isolated password theft.
the toolkit immediately proxies that data to the genuine Microsoft 365 service over a persistent WebSocket channel... Key indicators include web requests matching /<three-letter-code>/xls/*.js , canonical endpoints such as /api/xls/a1p2i.js , and outbound WebSockets established immediately following script retrieval.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An adversary-in-the-middle phishing framework that proxies legitimate Microsoft 365 authentication flows, captures credentials and MFA submissions, and steals authenticated session cookies to hijack user sessions and access mailboxes, SharePoint, OneDrive, and SSO-connected enterprise applications without further prompts.
Named phishing kit/tool referenced in a related article title about a phishing attempt against a large holding company.
Mirage2FA is described as the tool used in a phishing attempt against a large holding company, consistent with an adversary-in-the-middle phishing framework used to capture credentials and likely bypass MFA.
Named in a related-news headline as being used in a phishing attempt against a large holding company; no further malware-specific details are provided in the content.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.