top of page

Warning: Over 4,500 businesses fall victim to Mirage2FA phishing campaign targeting Microsoft 365

Changing passwords is usually the first instinct of IT departments upon detecting a compromised internal account. However, with the emergence of the phishing campaign known as Mirage2FA, this action is entirely ineffective. Directly targeting Microsoft 365 services, this sophisticated phishing kit does not stop at stealing passwords – it also hijacks login session "keys." As a result, hackers can open the doors wide to corporate systems without worrying about the two-factor authentication (2FA) layer.

Over 4.500 organizations and alarming numbers from Mirage2FA

According to the latest security analysis from ANY.RUN, the Mirage2FA campaign (believed to be operated by the hacker group LinX Coders) has left traces across 94 countries, with 9,332 recorded intrusion incidents. Notably, the campaign's success rate is extremely high: approximately 48% of the 9,426 targeted emails successfully hit their targets, leading to 4,532 accounts across more than 3,500 organizations being compromised.

The United States is currently the epicenter, bearing 63.7% of all compromise cases (over 2,800 victims), followed by India (5.1%), Singapore (4.1%), and the UK and Canada (both at 1.7%). By industry sector, technology and manufacturing companies are the most heavily affected, accounting for 19.2% and 11.1% of targets respectively, closely followed by the education sector (9.9%).

impacts-of-mirage2fa
Impacts of Mirage2FA (Cre: ANY.RUN)

Session hijacking: A sophisticated tactic requiring no malware

The danger of Mirage2FA lies in the fact that it does not use any traditional malicious executable files, allowing it to easily remain "invisible" to many antivirus software programs. Cybercriminals typically begin with a phishing email – impersonating notices from HR or benefits departments – sent en masse with attached web-format files (such as .htm, .svg) or QR codes.

When users click on them, the tool triggers an Adversary-in-the-Middle (AiTM) technique. It displays a fake Microsoft 365 login page that looks identical to the original. As soon as you enter your password and 2FA code, it immediately forwards this data to the real Microsoft server. Once Microsoft validates the credentials and returns a "session cookie" (a digital marker proving you have validly logged in), this intermediary system quietly retains and steals that exact cookie.

Statistics show that up to 51% of Mirage2FA incidents involve pure cookie theft, far exceeding standard password harvesting rates. With this cookie in hand, hackers can freely enter and exit accounts, read emails, or access internal applications without caring about your password or needing the system to resend a 2FA code. Notably, about 33.3% of successful unauthorized logins occur on mobile devices, where scaled-down browser interfaces make it difficult for users to inspect fraudulent links closely.

What should businesses do to defend against Mirage2FA?

Because Mirage2FA renders conventional Multi-Factor Authentication (MFA) methods useless, organizations need a deeper response strategy to protect their personnel:

  • Block at the gateway: Corporate email security systems must be configured with aggressive filters to automatically block or quarantine suspicious attachments (.htm, .xhtml, .svg), while maintaining high alert for emails containing QR codes.

  • Transition authentication methods: Personnel holding sensitive data, such as system administrators, executive management, or finance teams, should switch to phishing-resistant MFA methods like FIDO2 hardware keys, WebAuthn, or Passkeys.

  • Thorough incident resolution: Upon detecting signs of account compromise, changing passwords is not enough. The IT department must immediately revoke all active tokens and sessions, while auditing to ensure hackers have not stealthily granted unauthorized access permissions to third-party applications.

  • Awareness training: Although technical solutions play a core role, human factors remain the most crucial filter against sophisticated phishing scenarios. To prevent personnel from becoming the "weakest link," equipping them with the knowledge and skills to recognize real-world attack flows is an urgent requirement.

Businesses can refer to IPSIP's Cybersecurity Training & InfoSec Consulting solutions to build a solid security culture and heighten vigilance across the entire organization against threats like Mirage2FA.

The rise of Mirage2FA in 2026 serves as proof that cybercriminals have evolved significantly. To protect digital assets, businesses cannot rely indefinitely on legacy defenses, but must continuously upgrade systems and educate employees on maintaining vigilance in a complex online environment.

Refer to: Cyber Press

Comments


follow ipsip vietnam.png
40051abd5a76713af8f015988fc6780e-blue-phone-icon-with-a-wave-on-it.webp
Logo-Zalo-Arc.webp
pngtree-minimal-calendar-icon-vector-png-image_21233134.png
IPSIP logo transparent.png

IPSIP VIETNAM ONE MEMBER LIMITED LIABILITY COMPANY (IPSIP VIETNAM OMLLC)

Tax code: 0313859600

🏢 SH05.01, B4 Street, Saritown Area, An Khanh Ward, Ho Chi Minh City, Vietnam

​☎  +84 918 397 489

  • Linkedin
  • Facebook
  • TikTok
  • Email liên hệ
png-clipart-iso-iec-27001-information-security-management-iso-iec-27002-international-orga
soc 2 type ii

Our Services

Sign up to receive in-depth cybersecurity documents and news from IPSIP Vietnam.

bottom of page