ANY.RUN’s Threat Intelligence Lookup surfaced dozens of related loader URLs on the same IP address; a single /xls/*.js query exposes the loader cluster on 185.174.100.224 and is described as providing intel related to Mirage2FA attacks.
Mirage2FA
Mirage2FA is a phishing-as-a-service adversary-in-the-middle framework attributed to LinX Coders.
Profile source: Mallory opens in a new tabMirage2FA
Family profile
Mirage2FA is a phishing-as-a-service adversary-in-the-middle framework attributed to LinX Coders. It targets Microsoft 365 and Microsoft Entra ID users by proxying legitimate authentication workflows through attacker-controlled phishing portals. The framework captures user credentials and one-time MFA codes, then intercepts authenticated session cookies after successful login, allowing operators to reuse the sessions without further MFA challenges. Stolen sessions can enable access to Exchange Online mailboxes, SharePoint, OneDrive, and SSO-connected enterprise applications, as well as victim impersonation. Campaigns use HR and employee-benefits lures delivered through phishing emails, malicious HTML, XHTML, or SVG attachments, embedded links, and QR codes. Browser-based JavaScript stagers retrieve remotely hosted harvesting logic, employ obfuscation, and use WebSocket communications to relay authentication data. Mirage2FA activity has targeted organizations internationally, including technology, manufacturing, education, healthcare, consulting, and finance sectors. The operation is browser-based and does not require deployment of a binary payload on the victim system.
Capabilities
- Credential Theft
- Exfiltration
- Reconnaissance
- Session Hijacking
Reported operators
Threat actors
1 named in public reportingMITRE ATT&CK