Skip to content

Mirage2FA

Mirage2FA is a phishing-as-a-service adversary-in-the-middle framework used to target Microsoft 365 and Microsoft Entra ID users.

Profile source: Mallory opens in a new tab

Mirage2FA

Family profile

Mirage2FA is a phishing-as-a-service adversary-in-the-middle framework used to target Microsoft 365 and Microsoft Entra ID users. It operates by placing an attacker-controlled portal between the victim and legitimate Microsoft authentication services, proxying the login flow in real time so victims complete their normal sign-in and multi-factor authentication process while the operator captures submitted credentials and authenticated session cookies. This enables session hijacking and follow-on access to cloud email, file repositories, and single sign-on-connected enterprise applications without requiring additional MFA prompts.

The platform’s activity has been associated with a threat group identified as LinX Coders. Observed campaigns have targeted organizations across numerous countries, with notable concentration in the United States, and have affected sectors including technology, manufacturing, education, healthcare, consulting, and finance. Reported lure themes included corporate human-resources and benefits notifications.

Mirage2FA delivery has relied on browser-based phishing content distributed through links and HTML-family attachments, including XHTML and SVG formats. The phishing chain uses obfuscated client-side scripts and persistent communications to relay authentication data to legitimate services and return responses to the victim, allowing the attack to remain transparent during login. The operation is notable for functioning entirely within the browser rather than requiring deployment of a traditional binary payload.

Its core capabilities are credential theft and, more prominently, theft of authenticated session material after MFA completion. Because compromise centers on active sessions and refresh tokens, remediation requires revocation of those sessions rather than password reset alone.

Capabilities

  • Credential Theft
  • Session Hijacking

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Aug 19, 2026
Last activity
Aug 24, 2026
Feed role
C2 / Distribution
Host form
0 IP / 70 hostnames

Leading locations

  • US2

Leading providers

  • HostPapa1
  • Namecheap, Inc.1

Infrastructure traits

  • Hosting 2

Reported operators

Threat actors

1 named in public reporting
LinX Coders

A sophisticated Phishing-as-a-Service (PhaaS) platform marketed as Mirage2FA is enabling threat actors to bypass multi-factor authentication (MFA) by allowing Microsoft 365 users to complete their regular login process before covertly stealing the authenticated session.

MITRE ATT&CK

Mirage2FA in ATT&CK

13 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.