Start with Identity
← Blog
News

Mirage2FA reached 4,500 organizations by stealing sessions instead of breaking MFA

ANY.RUN traced the Mirage2FA phishing-as-a-service kit across 4,532 organization domains from 2024 to 2026. It abuses legitimate Microsoft 365 login flows to lift passwords and session cookies, then rides the authenticated session into every SSO-connected app.

By SWI Community TeamAug 25, 2026Updated Aug 29, 2026

ANY.RUN published analysis on August 25, 2026 of Mirage2FA, a commercial phishing-as-a-service toolkit that has touched 4,532 unique organization email domains between 2024 and 2026. It does not break MFA. It abuses legitimate Microsoft 365 login flows to capture the password and the resulting session cookie, then hijacks the authenticated session and inherits access to everything behind SSO. ANY.RUN counted over 9,000 potential compromise events and estimates 48 percent of targeted addresses were exposed. The United States accounts for 63.7 percent of victims, with activity in India, Singapore, the UK, Canada, Saudi Arabia, and South Africa. Technology, manufacturing, and education were hit hardest.

Why it matters

A two-year campaign at this scale settles the argument about whether push and OTP factors are enough. They are not, because the attacker is not defeating the factor, they are stealing what the factor produces. Once the session cookie is in hand, SSO does the rest of the work for them, and every downstream app trusts the same session. Three defences actually change the outcome: phishing-resistant MFA bound to the origin, token binding or device-bound sessions so a lifted cookie is useless elsewhere, and treating session theft as a full identity incident that requires revoking tokens rather than just resetting a password. Our teardown of infostealer-driven session hijacking covers the response playbook.

Source: The Hacker News

Last reviewed By SWI Community TeamSuggest a correctionHow we research
Independent analysis. No vendor sponsorship.