Mirage2FA campaign hijacks Microsoft 365 sessions for thousands of firms
The Mirage2FA campaign affected thousands of companies from 2024 to 2026, with ANY.RUN research finding 48% of targeted email addresses potentially compromised. Attackers stole passwords and session cookies to access authenticated Microsoft 365 sessions and SSO-connected services, exploiting AiTM gaps in authentication and session management even with 2FA. Defenses include revoking compromised sessions and tokens, sandbox-based investigation, and identity-focused incident response.