Mirage2FA is a commercial phishing-as-a-service toolkit that targets Microsoft 365 accounts by abusing legitimate login flows and bypassing two-factor authentication. Active from 2024 to 2026, it has affected over 4,500 organizations, primarily in the US and EU. The toolkit steals passwords and session cookies, enabling attackers to hijack authenticated sessions and access SSO-connected services.