Mirage2FA Phishing-as-a-Service Bypasses MFA and Hijacks Sessions
Score: 8/10

Mirage2FA Phishing-as-a-Service Bypasses MFA and Hijacks Sessions

The Mirage2FA Phishing-as-a-Service toolkit by LinX Coders utilizes Adversary-in-the-Middle (AiTM) techniques to bypass MFA and steal Microsoft 365 session cookies, primarily targeting US-based technology and manufacturing sectors.

Executive Summary

Mirage2FA is a commercial Phishing-as-a-Service (PhaaS) operation that has been active from late 2024 through 2026. Attributed to the operator 'LinX Coders', the toolkit employs Adversary-in-the-Middle (AiTM) tactics to intercept credentials and one-time 2FA codes in real time. Its primary goal is the exfiltration of authenticated session cookies, allowing attackers to maintain access to Microsoft 365 environments even after a password reset.

The attack chain typically begins with phishing emails containing browser-executed stagers like .htm, .xhtml, or .svg files, or QR-code lures. These stagers use HTML smuggling and JavaScript obfuscation to fetch harvesting logic from a C2 infrastructure. Analysis indicates a high concentration of victims in the United States (63.7%), with significant impact observed in the technology, manufacturing, and education sectors.

This threat is particularly critical because it renders conventional SMS or app-based MFA ineffective. Organizations must pivot toward phishing-resistant authentication methods (FIDO2) and implement session-revocation procedures to mitigate the risk of account takeover via stolen session tokens.

Key Details

Threat Name

Mirage2FA

Affects

—

Adversary

LinX Coders Other Adversaries and Aliases: Lazarus Group

Malware/Tools

Mirage2FA, JS.MonoGlyphRAT, Salty2FA, Tycoon2FA, Tykit

Report Score

8out of 10
Quality Score
Good
IOC Quality8
TTP Details9
Detection Guidance7
Enterprise Relevance9
Clarity & Structure9
Technical Depth8

Sources