Researchers at ANY.RUN have published research into Mirage2FA, a phishing-as-a-service platform targeting Microsoft 365 users. The campaign has been linked to as many as 4,532 organisation email domains.
The mechanics matter more than the scale. Mirage2FA steals passwords and session cookies, then hijacks Microsoft 365 sessions after the user has already authenticated. Where two-factor authentication is enabled, the attacker does not need to beat it. They wait for the victim to satisfy it, then take the session that results.
Why identity teams should care
MFA adoption is often reported internally as if it were the finish line. This campaign is a reminder that the thing MFA produces, an authenticated session, is itself a credential, and it is one that most organisations protect far less carefully than the login that created it.
Three controls decide how much this style of attack costs you. Session token binding and device-based conditional access determine whether a stolen cookie works from the attacker's infrastructure at all. Session lifetime and re-authentication policy determine how long a stolen session stays useful. And detection of impossible travel and anomalous session reuse determines whether anyone notices before the attacker is finished.
Phishing kits industrialised the credential theft. Platforms like Mirage2FA are industrialising the step after it. The defensive question has moved from "can they get a password" to "what is a session worth once they have one".
Source
Mirage2FA surge hits 4,500 US and EU organisations, The Hacker News