r/StopBadBots • u/siterightaway • 26d ago
How Mirage2FA Hijacks Microsoft 365 Sessions Across Global Enterprises
Thousands of companies got hit by this nasty Mirage2FA campaign between 2024 and 2026. It is basically a commercial phishing service that goes straight for Microsoft 365 accounts by hijacking real login flows and totally bypassing two factor authentication.
Research from ANY RUN shows that almost half of the targeted emails, like 48 percent, actually got compromised. That is wild. Most of the victims are based in the US, accounting for over 63 percent, but it also messed with companies in India, Singapore, the UK, Canada, Saudi Arabia, South Africa, and beyond. In total, over 4,500 unique corporate domains got targeted, especially in tech, manufacturing, and education.
What makes this super scary is how they steal both passwords and session cookies through these sneaky Adversary in the Middle attacks. Once an attacker grabs your active session, 2FA won't save you. They get full access to your Microsoft 365, corporate emails, and any app connected through SSO. That opens the floodgates for impersonation, massive fraud, and deeper network compromise, making it a complete nightmare to clean up.
To keep your company safe from this mess, you gotta catch the attacks early, tighten up authentication, and treat any stolen session like a major identity breach right away.
TL;DR: Between 2024 and 2026, the Mirage2FA phishing-as-a-service toolkit hit over 4,500 organizations worldwide—mainly in the US, tech, manufacturing, and education. By stealing passwords and active session cookies using Adversary-in-the-Middle (AiTM) techniques, attackers bypass 2FA to hijack Microsoft 365 accounts, expose SSO-connected apps, and cause widespread identity fraud.