Last seven days
- First activity
- Aug 19, 2026
- Last activity
- Aug 24, 2026
- Feed role
- C2 / Distribution
- Host form
- 0 IP / 70 hostnames
Mirage2FA is a phishing-as-a-service adversary-in-the-middle framework used to target Microsoft 365 and Microsoft Entra ID users.
Profile source: Mallory opens in a new tabMirage2FA
Mirage2FA is a phishing-as-a-service adversary-in-the-middle framework used to target Microsoft 365 and Microsoft Entra ID users. It operates by placing an attacker-controlled portal between the victim and legitimate Microsoft authentication services, proxying the login flow in real time so victims complete their normal sign-in and multi-factor authentication process while the operator captures submitted credentials and authenticated session cookies. This enables session hijacking and follow-on access to cloud email, file repositories, and single sign-on-connected enterprise applications without requiring additional MFA prompts.
The platform’s activity has been associated with a threat group identified as LinX Coders. Observed campaigns have targeted organizations across numerous countries, with notable concentration in the United States, and have affected sectors including technology, manufacturing, education, healthcare, consulting, and finance. Reported lure themes included corporate human-resources and benefits notifications.
Mirage2FA delivery has relied on browser-based phishing content distributed through links and HTML-family attachments, including XHTML and SVG formats. The phishing chain uses obfuscated client-side scripts and persistent communications to relay authentication data to legitimate services and return responses to the victim, allowing the attack to remain transparent during login. The operation is notable for functioning entirely within the browser rather than requiring deployment of a traditional binary payload.
Its core capabilities are credential theft and, more prominently, theft of authenticated session material after MFA completion. Because compromise centers on active sessions and refresh tokens, remediation requires revocation of those sessions rather than password reset alone.
C2 tracking
Derp observations, rolling seven-day window
Reported operators
A sophisticated Phishing-as-a-Service (PhaaS) platform marketed as Mirage2FA is enabling threat actors to bypass multi-factor authentication (MFA) by allowing Microsoft 365 users to complete their regular login process before covertly stealing the authenticated session.
MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.