Phishing kit bypasses 2FA across 4,500 corporate domains

A two-year phishing-as-a-service campaign bypasses 2FA across more than 4,500 Microsoft 365 domains.

CSBadmin
1 Min Read

A phishing-as-a-service operation has spent two years draining Microsoft 365 sessions across more than 4,500 corporate domains, according to new research from ANY.RUN.

The campaign, dubbed Mirage2FA, abuses legitimate Microsoft login flows to steal passwords and session cookies, then uses the hijacked sessions to skip past two-factor authentication. ANY.RUN says 48% of the targeted email addresses were potentially compromised, with more than 9,000 separate events involving cookie and password theft, SSO logins, and 2FA bypass.

The United States absorbed 63.7% of the victims, with additional activity in India, Singapore, the United Kingdom, Canada, Saudi Arabia, and South Africa. Technology, manufacturing, and education companies were hit hardest.

Researchers describe the attacks as adversary-in-the-middle operations that exploit gaps in authentication and session management even when 2FA is enabled. The danger extends past the first account: stolen sessions grant access to SSO-connected applications and internal workflows, widening the blast radius and inflating containment costs.

ANY.RUN advises organizations to treat session theft as an identity incident, strengthen authentication at login, and watch for the campaign’s behavioral signatures rather than relying on 2FA alone.

CSBadmin

The latest in cybersecurity news and updates.

Share This Article
Follow:
The latest in cybersecurity news and updates.