Mirage2FA Phishing Targets Microsoft 365 Accounts | Britec

Mirage2FA Phishing Campaign Targets Microsoft 365 Accounts

Security researchers have identified a large-scale phishing campaign targeting Microsoft 365 users and attempting to bypass conventional multifactor authentication.

The campaign uses Mirage2FA, a commercial phishing-as-a-service toolkit designed to steal passwords and authenticated session cookies. Researchers linked its activity to more than 4,500 organizational email domains and over 9,000 potential compromise events between 2024 and 2026.

What Is Mirage2FA?

Mirage2FA uses adversary-in-the-middle phishing to imitate legitimate Microsoft 365 login pages.

When a victim enters their password and completes an MFA request, the attacker intercepts the login process and captures the resulting session cookie. That cookie may allow the attacker to access the authenticated account without completing MFA again.

The campaign does not exploit a vulnerability in Microsoft 365 or technically break MFA. Instead, it tricks the user into completing a legitimate authentication request while the attacker steals the resulting session.

Why It Matters

A stolen Microsoft 365 session could give an attacker access to corporate email, files and other applications connected through single sign-on.

This access may be used to:

  • Impersonate employees or executives.
  • Launch business email compromise attacks.
  • Access sensitive emails and documents.
  • Create malicious inbox or forwarding rules.
  • Target customers, vendors and other employees.
  • Access additional applications connected through SSO.

A password reset may not be enough to remove the attacker if an active session or authentication token remains valid. Microsoft advises organizations responding to token theft to revoke active sessions and tokens in addition to resetting the affected password.

How Businesses Can Respond

Organizations can reduce the risk of Mirage2FA and similar attacks by taking the following steps:

  • Introduce phishing-resistant authentication, such as passkeys, FIDO2 security keys or Windows Hello for Business.
  • Use Conditional Access to restrict access from unmanaged devices, risky locations and unusual sign-in attempts.
  • Monitor Microsoft Entra ID for unfamiliar devices, locations, MFA registrations and suspicious login activity.
  • Review Microsoft 365 accounts for unauthorized forwarding rules, application permissions and mailbox changes.
  • Train employees to carefully inspect unexpected Microsoft 365 login pages and authentication requests.
  • Revoke active sessions and tokens immediately when an account compromise is suspected.
  • Reset the affected password and verify that no unauthorized MFA methods were added.

Traditional MFA remains an essential security control, but Mirage2FA demonstrates why businesses also need phishing-resistant authentication, session monitoring and a complete identity-incident response process.

Britec helps businesses strengthen Microsoft 365 security, monitor suspicious activity and respond to compromised accounts before the damage spreads.