Skip to content

Mirage2FA

Mirage2FA is a phishing-as-a-service adversary-in-the-middle framework attributed to LinX Coders.

Profile source: Mallory opens in a new tab

Mirage2FA

Family profile

Mirage2FA is a phishing-as-a-service adversary-in-the-middle framework attributed to LinX Coders. It targets Microsoft 365 and Microsoft Entra ID users by proxying legitimate authentication workflows through attacker-controlled phishing portals. The framework captures user credentials and one-time MFA codes, then intercepts authenticated session cookies after successful login, allowing operators to reuse the sessions without further MFA challenges. Stolen sessions can enable access to Exchange Online mailboxes, SharePoint, OneDrive, and SSO-connected enterprise applications, as well as victim impersonation. Campaigns use HR and employee-benefits lures delivered through phishing emails, malicious HTML, XHTML, or SVG attachments, embedded links, and QR codes. Browser-based JavaScript stagers retrieve remotely hosted harvesting logic, employ obfuscation, and use WebSocket communications to relay authentication data. Mirage2FA activity has targeted organizations internationally, including technology, manufacturing, education, healthcare, consulting, and finance sectors. The operation is browser-based and does not require deployment of a binary payload on the victim system.

Capabilities

  • Credential Theft
  • Exfiltration
  • Reconnaissance
  • Session Hijacking

Reported operators

Threat actors

1 named in public reporting
LinX Coders

ANY.RUN’s Threat Intelligence Lookup surfaced dozens of related loader URLs on the same IP address; a single /xls/*.js query exposes the loader cluster on 185.174.100.224 and is described as providing intel related to Mirage2FA attacks.

MITRE ATT&CK

Mirage2FA in ATT&CK

16 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.