preloader

· · digital-security email-deliverability phishing microsoft-365 mfa identity-access-management aitm europe social-engineering

Your Staff Passed the MFA Prompt. The Attacker Was Already Inside.

Source: ANY.RUN

Multi-factor authentication was supposed to be the control that made stolen passwords harmless. Mirage2FA is built specifically to prove that assumption wrong.

A phishing kit that relays your login in real time

Mirage2FA is a phishing-as-a-service toolkit that has been running since 2024 and surged sharply through August 2026, with telemetry linking it to over 4,500 potentially compromised Microsoft 365 accounts across more than 3,500 organisations. The delivery mechanism is deliberately mundane: browser-executed HTML, XHTML, and SVG attachments that route a victim to a convincing fake Microsoft login page. Behind that page sits an adversary-in-the-middle reverse proxy, which passes the victim’s username, password, and one-time MFA code to the real Microsoft login in real time, and then keeps the authenticated session cookie that comes back.

Why a password reset does not fix this

This is the detail that matters most for incident response. Because the attacker ends up holding a live, authenticated session rather than just a stolen password, resetting the victim’s password does not evict them. The session cookie keeps working until it is explicitly revoked or expires on its own, which gives attackers a window to move through Microsoft 365 and any SSO-connected service the victim had access to, well after the “obvious” remediation step has already been taken.

Who is getting hit

Technology companies account for the largest share of victims, followed by manufacturing, education, consulting, telecommunications, healthcare, and finance. Managed service providers also feature prominently among affected sectors, which raises the stakes considerably: a single compromised MSP account can be a path into every downstream customer that provider manages. Victim activity has been logged across dozens of countries, with a meaningful concentration of European organisations alongside the larger US share.

What actually stops an AiTM kit like this

Standard MFA, the kind based on a one-time code the user types in, does nothing against a proxy sitting between the victim and the real login page. What does work is phishing-resistant authentication, such as FIDO2 security keys or passkeys bound to the origin, plus session policies that flag and kill tokens issued from anomalous locations or devices, and conditional access rules that make a stolen cookie less useful even when the credential theft succeeds. None of that is exotic technology in 2026, but a lot of organisations still have MFA configured in the weaker, code-based mode that Mirage2FA is built to defeat.

If you want your Microsoft 365 tenant assessed for exposure to AiTM phishing, or need help moving your organisation to phishing-resistant authentication and session-hardening policies, contact Excello Digital. We help European businesses close the gap between having MFA and having MFA that actually holds up.

These news items are automatically aggregated from industry sources and are not individually reviewed. Any inaccuracies are unintentional — let us know and we'll correct or remove it.

We’ll help you resolve your infrastructure challenges

Our team of experts is ready to help you with your infrastructure challenges. We’ll give you honest and personal treatment. Get in touch to learn more.

Get in touch!