
Mirage2FA AiTM Toolkit Compromised 4,532 Domains via Microsoft 365 Session Hijacking 2024-2026
Mirage2FA demonstrates scalable AiTM abuse of Microsoft 365 OAuth flows, stealing live sessions across thousands of organizations. Session theft, not password compromise, is the primary persistence mechanism. Early sandbox detection and token revocation reduce dwell time and downstream fraud exposure.
The campaign deployed commercial phishing kits that proxy Microsoft 365 login flows, capture session cookies and OAuth tokens, then replay them to maintain authenticated access. ANY.RUN sandbox traces showed WebSocket callbacks, encoded redirect chains, and fake login pages that bypassed standard MFA prompts. Victims spanned technology, manufacturing, and education sectors; follow-on activity included mailbox access and lateral movement into connected SaaS platforms.
Technical evidence from sandbox detonations and threat feeds indicates recurring infrastructure patterns consistent with prior Evilginx and EvilProxy operations, yet no state attribution has been confirmed by independent packet or log correlation. Official vendor statements emphasize MFA adoption while understating session-token lifetime risks; procurement records show continued reliance on legacy OAuth grants that lack token-binding or continuous verification.
Microsoft 365 admins must revoke active sessions via Azure AD PowerShell and enforce phishing-resistant methods such as FIDO2 or certificate-based auth within 30 days of detection. Without these controls, session replay will continue to outpace password-reset remediation, driving measurable increases in business-email compromise payouts.
Next indicators to monitor are new loader domains and WebSocket endpoints tied to the same ASN clusters; threat intel feeds updated within 14 seconds of detonation provide the earliest actionable signals.
Microsoft: token-revocation incidents tied to AiTM kits will exceed 15,000 unique domains by end of Q2 2027.
Sources (2)
- [1]Primary Source(https://thehackernews.com/2026/08/mirage2fa-surge-hits-4500-us-and-eu.html)
- [2]Supporting Source(https://any.run/cybersecurity-blog/mirage2fa-analysis/)