Executive Summary
Mirage2FA is a commercial Phishing-as-a-Service (PhaaS) operation that has been active from late 2024 through 2026. Attributed to the operator 'LinX Coders', the toolkit employs Adversary-in-the-Middle (AiTM) tactics to intercept credentials and one-time 2FA codes in real time. Its primary goal is the exfiltration of authenticated session cookies, allowing attackers to maintain access to Microsoft 365 environments even after a password reset.
The attack chain typically begins with phishing emails containing browser-executed stagers like .htm, .xhtml, or .svg files, or QR-code lures. These stagers use HTML smuggling and JavaScript obfuscation to fetch harvesting logic from a C2 infrastructure. Analysis indicates a high concentration of victims in the United States (63.7%), with significant impact observed in the technology, manufacturing, and education sectors.
This threat is particularly critical because it renders conventional SMS or app-based MFA ineffective. Organizations must pivot toward phishing-resistant authentication methods (FIDO2) and implement session-revocation procedures to mitigate the risk of account takeover via stolen session tokens.
