Mirage2FA Phishing Kit Steals Microsoft 365 Sessions

About DFIR · High sophistication
Last updated August 31, 2026

A phishing-as-a-service toolkit called Mirage2FA has been targeting organizations by abusing real Microsoft 365 login pages through a man-in-the-middle proxy. The attackers capture usernames, passwords, and live two-factor authentication codes, then take over the user’s session using stolen session cookies, meaning a password reset alone may not kick them out.

Key findings

  • Mirage2FA uses adversary-in-the-middle (AiTM) proxies to capture Microsoft 365 usernames, passwords, and live 2FA codes, then hijacks session cookies.
  • About 4,500 organizations across 60+ countries have been targeted, with large concentrations in technology, manufacturing, and education.
  • Because attackers steal an active session cookie, resetting a password may not remove attacker access by itself.

Who’s being targeted

  • Commonly targeted roles: All employees, Executives, IT helpdesk, Security team.
  • Affected industries: Technology, Manufacturing, Education.
  • Attack channels: email, website.
  • Impersonated: Microsoft 365.

Awareness takeaways

  • Treat unexpected Microsoft 365 sign-in prompts from email links as suspicious; navigate to Microsoft 365 using bookmarks or known URLs instead.
  • If you entered credentials and a 2FA code on a suspicious page, report immediately, attackers may have an active session even if you reset your password.
  • Train staff that “2FA approved” does not always mean “safe”, session hijacking can bypass protections even when 2FA is used correctly.

Red flags to watch for

  • Unexpected sign-in prompt reached via an email link
  • Login page behaves unusually (extra prompts/redirects) before or after authentication
  • Account still shows suspicious activity even after a password change
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

You click an email: “Action required: Microsoft 365 session expired, sign in to continue.” You log in, approve 2FA… and they still get in. This is Mirage2FA, an adversary-in-the-middle kit that abuses real Microsoft 365 login pages, grabs your username, password, and live 2FA code, then steals the session cookie. Here’s the twist: they don’t just have your password; they hijack your active Microsoft 365 session. So even if you change your password, their stolen session cookie can keep them inside. If an email link makes you sign in to Microsoft 365 and approve 2FA unexpectedly, stop using that tab and go to Microsoft 365 from your bookmark or our official portal instead.

Similar attacks

Phish Adds Passkey That Survives Reset

Phish Adds Passkey That Survives Reset

Researchers described iAuthFlow v2, a phishing toolkit that steals a live Google login session and then uses that access to enroll an attacker-controlled passkey. Because passkeys are separate login methods, the attacker can often get back into the account even after the victim changes their…

August 24, 2026
BlackFile Crew Vishing Hits PE and Finance Firms

BlackFile Crew Vishing Hits PE and Finance Firms

Google and Reuters report a real vishing-led intrusion campaign tied to the extortion crew behind the retired “BlackFile” brand (tracked as UNC6671). Attackers call employees on personal phones spoofing the corporate IT help desk, push a same-day “passkey/MFA update,” and send them to a look‑alike…

August 12, 2026
Phish Login, Then Add Your Own Google Passkey

Phish Login, Then Add Your Own Google Passkey

Researchers describe a phishing workflow where an attacker logs into a victim’s Google account using stolen password + authenticator code, then quickly enrolls a new passkey to keep access even if the password is changed. The trick relies on victims choosing a weaker sign-in fallback (one-time…

August 26, 2026
One-Click Copilot Link Triggers Data Exfil

One-Click Copilot Link Triggers Data Exfil

Researchers showed how an attacker could trick Microsoft Copilot into running a malicious prompt automatically just by getting a user to click a specially crafted link. The prompt can then make Copilot search connected accounts (like email and cloud storage) and send information to an external…

August 18, 2026
Malicious CSS Emails Can Hijack Webmail UI

Malicious CSS Emails Can Hijack Webmail UI

PortSwigger research shows how attackers can weaponize HTML/CSS inside emails to cross trust boundaries in webmail, including UI manipulation, token theft, and password theft. The paper highlights real-world weaknesses in email sanitization and gives concrete examples (including an Outlook…

August 6, 2026
AI Browser Tricked into Spamming WhatsApp, Shopping

AI Browser Tricked into Spamming WhatsApp, Shopping

Researchers showed how a malicious web page could trick OpenAI’s Atlas AI-enabled browser into taking actions a user didn’t intend, like spamming WhatsApp contacts or modifying an Amazon account. The attacks used prompt-injection style instructions hidden in a seemingly legitimate “newsletter…

August 6, 2026