TechNewsReel
Live

Mirage2FA Toolkit Bypasses 2FA to Target 4,500 US and EU Companies

A sophisticated Phishing-as-a-Service campaign is compromising Microsoft 365 accounts by intercepting session tokens through AiTM techniques.

TechNewsReel Newsroom · August 25, 2026

A commercial phishing-as-a-service (PhaaS) toolkit known as Mirage2FA has targeted approximately 4,500 companies across the United States and European Union. The campaign specifically targets Microsoft 365 accounts, utilizing advanced techniques to neutralize two-factor authentication (2FA) and gain unauthorized access to corporate environments.

According to reports from The Hacker News and security research from ANY.RUN, the Mirage2FA toolkit abuses legitimate Microsoft 365 login flows to deceive users. The attackers employ Adversary-in-the-Middle (AiTM) techniques and HTML smuggling to intercept session tokens in real-time. By capturing these tokens, the toolkit allows attackers to bypass traditional 2FA requirements entirely, as the session is already authenticated by the time the attacker gains control. Data from ANY.RUN indicates a heavy concentration of victims in the United States, which accounts for 63.7% of the affected organizations.

The Rise of PhaaS

Mirage2FA operates on a Phishing-as-a-Service model, a growing trend in the cybercrime economy that lowers the barrier to entry for attackers. Instead of building their own infrastructure, threat actors rent sophisticated toolkits that provide ready-made phishing pages mirroring official Microsoft login portals. This automation allows for rapid deployment and scaling, enabling a relatively small number of operators to target thousands of organizations simultaneously across different geographic regions.

Why Standard 2FA is Failing

This campaign underscores a critical vulnerability in standard multi-factor authentication implementations. For years, 2FA was considered a robust defense against credential theft; however, AiTM attacks prove that simply requiring a code or a push notification is no longer sufficient. Because Mirage2FA intercepts the session token—the digital "key" that tells a server a user is already logged in—the security layer is bypassed without the attacker ever needing to know the user's actual 2FA code.

The Path Forward

As phishing toolkits become more automated and capable of bypassing legacy security layers, the industry is seeing a forced shift toward phishing-resistant authentication. Security experts are increasingly recommending the adoption of FIDO2-compliant hardware keys and certificate-based authentication, which cannot be intercepted by AiTM proxies. Organizations currently relying on SMS or app-based 2FA remain at risk as toolkits like Mirage2FA continue to evolve and expand their reach.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.