Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Critical WordPress Plugin Vulnerability Exposes 400,000 Sites
August 26, 2026
Iran-Linked Hackers Exploit Legitimate Dev Tool to Conceal Didoor Backdoor
August 26, 2026
Mirage2FA Phishing Kit Bypasses MFA, Hijacks Microsoft 365 Sessions
August 26, 2026
Home/CyberSecurity News/Mirage2FA Phishing Kit Bypasses MFA, Hijacks Microsoft 365 Sessions
CyberSecurity News

Mirage2FA Phishing Kit Bypasses MFA, Hijacks Microsoft 365 Sessions

Key Takeaways The Mirage2FA phishing kit is actively bypassing multi-factor authentication (MFA) to compromise Microsoft 365 sessions. The kit primarily targets organizations in the technology and...

Jennifer sherman
Jennifer sherman
August 26, 2026 3 Min Read
3 0

Key Takeaways

  • The Mirage2FA phishing kit is actively bypassing multi-factor authentication (MFA) to compromise Microsoft 365 sessions.
  • The kit primarily targets organizations in the technology and manufacturing sectors, with a significant focus on U.S. companies.
  • Mirage2FA utilizes sophisticated techniques including session cookie hijacking and varied obfuscation methods.
  • Threat intelligence indicates a steady rise in Mirage2FA attacks, with observed activity spanning from September 2024 to July 2026.

Mirage2FA: A Persistent Threat to Microsoft 365 Security

A new phishing kit, dubbed Mirage2FA, has emerged as a significant threat, demonstrating the capability to bypass multi-factor authentication (MFA) and hijack Microsoft 365 user sessions. This sophisticated tool is actively targeting organizations, particularly those within the technology and manufacturing industries, with a strong emphasis on U.S.-based entities.

Table Of Content

  • Key Takeaways
  • Mirage2FA: A Persistent Threat to Microsoft 365 Security
  • Technical Modus Operandi
  • Indicators of Compromise (Selection)
  • What You Should Do

According to threat intelligence gathered by ANY.RUN, Mirage2FA attacks are on a consistent upward trend, with observed activity projected to continue through July 2026. The kit’s primary objective is session cookie theft, which accounts for over half of all successful compromises. This allows attackers to bypass traditional authentication mechanisms, including MFA, by replaying stolen session cookies.

Technical Modus Operandi

Mirage2FA employs several advanced techniques to evade detection and achieve its malicious goals. The kit leverages dynamic iframes and remote loaders, often embedded within plain XHTML variants of phishing pages. This allows the attackers to inject malicious code and capture credentials or session cookies in real-time.

Further enhancing its stealth, Mirage2FA utilizes robust obfuscation methods. One notable technique involves a combination of XOR encryption (with a 0xAD key), Base64 encoding, and dynamic evaluation functions within obfuscated .htm variants. This makes static analysis challenging and helps the kit evade security solutions that rely on signature-based detection.

Investigators have identified open directories on the kit’s infrastructure, exposing components such as the xwps.php handler and dated backup copies. This provides crucial insight into the kit’s operational setup and evolution. Real-time threat intelligence lookups, such as a query for /xls/*.js, have also revealed loader clusters on specific IP addresses, including 185.174.100.224, indicating active command and control infrastructure.

Organizations can Get a full version of the Mirage2FA report for SOC and MSSP teams., which includes a comprehensive list of Indicators of Compromise (IOCs) for SIEM/EDR integration.

Indicators of Compromise (Selection)

Analysis of Mirage2FA’s infrastructure and attack patterns has yielded several key indicators of compromise that security teams can use for detection and prevention:

  • C2 / loader IP: 185.174.100.224 (AS-Colocrossing)
  • Loader domains: user.cheacker[.]store, hvr.volatilesour[.]store, ver.bandhiem[.]com, pynutech[.]store
  • Phishing domains (sample): pectech[.]store, bns.baseasix[.]com, adp.pslcertlive[.]site, office.pcvgtech[.]store, hpn.bandhiem[.]com, vrf.iar0nline[.]com, ans.rsxbenefits[.]com
  • Loader path: /<3-letter-code>/xls/<token>.js (canonical: /api/xls/a1p2i.js)
  • Build markers: LINXB64EMAIL, LINXEMAIL, LINXCODERSEMAIL, LINXCODERSRANDSTRING, #LINXMASKEMAIL, #LINXRANDSTRING, linxz
  • Obfuscation key: XOR 0xAD (173) + Base64 + eval
  • Activity window: September 2024 – July 2026 (observed)

The complete report offers an extensive list of over 60 phishing domains and 21 operator testing IP addresses, crucial for enhancing threat intelligence feeds. Security teams can Expand threat coverage in your SOC. by integrating these unique threat intelligence feeds based on live data from a vast network of companies and analysts.

What You Should Do

  • Implement Conditional Access Policies: Enforce strict conditional access policies in Microsoft 365, limiting access based on device compliance, location, and user behavior.
  • Monitor Session Activity: Continuously monitor user session activity for anomalous behavior, such as logins from unusual locations or devices, or access attempts to sensitive resources outside normal working hours.
  • Educate Users on Phishing: Conduct regular security awareness training to educate employees about identifying sophisticated phishing attempts, especially those designed to steal session cookies.
  • Deploy Advanced Endpoint Detection and Response (EDR): Utilize EDR solutions that can detect and prevent malicious script execution, obfuscated code, and unusual network connections associated with phishing kits.
  • Integrate Threat Intelligence Feeds: Incorporate up-to-date threat intelligence feeds containing IOCs related to Mirage2FA into your SIEM, SOAR, and EDR systems for proactive detection.
  • Review and Enforce Authentication Policies: Regularly review and strengthen MFA policies, ensuring that even if credentials are compromised, session hijacking is mitigated through re-authentication prompts or session expiry.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackphishingThreat

Share Article

Jennifer sherman

Jennifer sherman

Jennifer is a cybersecurity news reporter covering data breaches, ransomware campaigns, and dark web markets. With a background in incident response, Jennifer provides unique insights into how organizations respond to cyber attacks and the evolving tactics of threat actors. Her reporting has covered major breaches affecting millions of users and has helped organizations understand emerging threats. Jennifer combines technical knowledge with investigative journalism to deliver in-depth coverage of cybersecurity incidents.

Previous Post

NVIDIA NemoCLAW Critical Flaw Lets Attackers Hijack AI Agents

Next Post

Iran-Linked Hackers Exploit Legitimate Dev Tool to Conceal Didoor Backdoor

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
28,000 Git Repositories Exposed API Keys, Bank Details
August 26, 2026
New CoreRAT Malware Grants Full Control to Core Werewolf Hackers
August 26, 2026
Critical Microsoft SharePoint Flaws Let Attackers Hack Servers Remotely
August 26, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us