A large-scale phishing campaign dubbed Mirage2FA has impacted over 4,500 organizations in the US and EU, abusing Microsoft 365 login flows to bypass two-factor authentication (2FA). According to research from ANY.RUN, the campaign, active from 2024 to 2026, targeted Microsoft 365 accounts by stealing passwords and session cookies, allowing attackers to hijack authenticated sessions and access SSO-connected services.
The campaign’s reach is broad, with the United States accounting for 63.7% of victims, followed by India, Singapore, the UK, Canada, Saudi Arabia, South Africa, and others. Technology, manufacturing, and education were the most targeted industries. ANY.RUN identified over 9,000 potential compromise events involving cookie and password theft, SSO logins, and 2FA bypass. The research highlights how adversary-in-the-middle (AiTM) attacks can exploit gaps in authentication and session management, even when 2FA is enabled.
The impact extends beyond initial account compromise, as attackers can access corporate environments and Microsoft 365 services through hijacked sessions, increasing containment costs and enabling impersonation, fraud, and further compromise. To mitigate risks, ANY.RUN recommends strengthening authentication with phishing-resistant methods, detecting campaign behavior through sandboxing and threat intelligence, and treating session theft as an identity incident. Organizations should revoke compromised sessions and tokens, and investigate activity tied to the affected identity rather than relying solely on password resets.
ANY.RUN’s Interactive Sandbox and Threat Intelligence Feeds help SOC teams detect such attacks earlier, analyze suspicious attachments and URLs in isolation, and uncover related infrastructure. The campaign underscores the evolution of phishing beyond credential theft, emphasizing the need for businesses to prioritize phishing-resistant authentication and behavioral detection.
CVEs: CVE-2026-58231
Malware: Mirage2FA
Companies: ANY.RUN
Products: ANY.RUN Interactive Sandbox, ANY.RUN Threat Intelligence Feeds, ANY.RUN Threat Intelligence Lookup
Original source: thehackernews.com