Mirage2FA reached 4,500 organizations by stealing sessions instead of breaking MFA
ANY.RUN traced the Mirage2FA phishing-as-a-service kit across 4,532 organization domains from 2024 to 2026. It abuses legitimate Microsoft 365 login flows to lift passwords and session cookies, then rides the authenticated session into every SSO-connected app.
ANY.RUN published analysis on August 25, 2026 of Mirage2FA, a commercial phishing-as-a-service toolkit that has touched 4,532 unique organization email domains between 2024 and 2026. It does not break MFA. It abuses legitimate Microsoft 365 login flows to capture the password and the resulting session cookie, then hijacks the authenticated session and inherits access to everything behind SSO. ANY.RUN counted over 9,000 potential compromise events and estimates 48 percent of targeted addresses were exposed. The United States accounts for 63.7 percent of victims, with activity in India, Singapore, the UK, Canada, Saudi Arabia, and South Africa. Technology, manufacturing, and education were hit hardest.
Why it matters
A two-year campaign at this scale settles the argument about whether push and OTP factors are enough. They are not, because the attacker is not defeating the factor, they are stealing what the factor produces. Once the session cookie is in hand, SSO does the rest of the work for them, and every downstream app trusts the same session. Three defences actually change the outcome: phishing-resistant MFA bound to the origin, token binding or device-bound sessions so a lifted cookie is useless elsewhere, and treating session theft as a full identity incident that requires revoking tokens rather than just resetting a password. Our teardown of infostealer-driven session hijacking covers the response playbook.
Source: The Hacker News
Related on Start with Identity
- BlogInsurance phishing kits now relay your OTP live instead of just stealing your password
CTM360 found a phishing operation, centered on Saudi Arabia with activity across Europe, the US, and India, using a kit called InsureOTP that authenticates agai
- BlogForged OIDC tokens in SimpleHelp RMM handed out technician access to 1,000 exposed servers, no MFA required
CVE-2026-48558 lets an unauthenticated attacker forge OpenID Connect tokens against SimpleHelp remote-monitoring software configured for group login, gaining pr
- BlogKratos phishing-as-a-service dismantled: 200 servers, 1,800 customers, MFA walked past every time
German, US, and Indonesian authorities took down Kratos (tracked by Microsoft as SneakyLog), a phishing-as-a-service kit that used a Node.js reverse proxy to re
- BreachMFA fatigue and push bombing: defeating MFA without breaking it
Push-based MFA can be defeated not by breaking the cryptography but by wearing the user down. Here is how MFA-fatigue attacks work and why number matching and p
- ArticleB2B vs B2C CIAM: Tenancy, Organizations, and Architecture
B2B and B2C customer identity share a name but differ in architecture. This guide explains the organization and tenancy model, who administers users, and why ch
- RankingBest MFA for Enterprises: Top 5 Multi-Factor Authentication Platforms
The best enterprise MFA platforms in 2026: Duo, Microsoft Authenticator, Yubico, RSA SecurID, and HYPR. Ranked for coverage, phishing resistance, and workforce