Find notable cyber news and cases, enriched with sources, timelines, and signals.

Mirage2FA Microsoft 365 phishing-as-a-service campaign

Campaign
First reported
Last updated
Happening score
H score 53
1 unique sources, 1 articles

Summary

Hide ▲

The Mirage2FA phishing-as-a-service campaign is actively targeting Microsoft 365 accounts by abusing legitimate login flows and bypassing two-factor authentication, putting authenticated sessions and connected services at risk. Activity spans 2024 to 2026 and has affected thousands of companies. ANY.RUN linked the operation to 4,532 unique organization email domains and more than 9,000 potential compromise events. The broad session-theft model increases the risk of impersonation, fraud, and follow-on access through SSO-connected services.

Related Happenings

UNC7005 (Storm-2945) targeted OAuth and WhatsApp phishing campaign

Campaign
H score16 First: 20.08.2026 22:59 Last: 20.08.2026 22:59 Sources 1

About this happening: A UNC7005 (Storm-2945) campaign is hijacking accounts with OAuth, WhatsApp linking, and device-code phishing across academia, diplomatic, nonprofit, and Euro...

Microsoft 365 AitM phishing campaign using residential proxies

Campaign
H score34 First: 07.08.2026 13:38 Last: 07.08.2026 13:38 Sources 1

About this happening: An active email-driven AitM phishing campaign is hijacking Microsoft 365 accounts and exposing payroll and HR mailboxes across multiple sectors. The operation has targeted...

Greatness PhaaS expands into device code phishing and integrated token-theft operations

Threat Actor Meta
H score40 First: 04.08.2026 20:27 Last: 04.08.2026 20:27 Sources 1

About this happening: Greatness PhaaS has added device code phishing, expanding its crimeware panel into a broader token-theft ecosystem that makes MFA bypass easier for customers targe...

Phishing becomes dominant initial access vector across Cisco Talos incident-response investigations, March-June 2026

Trend
H score30 First: 28.07.2026 16:00 Last: 28.07.2026 16:00 Sources 1

About this happening: Phishing became the dominant initial access vector across incident-response investigations in March to June 2026, raising the risk of credential theft and follow-on co...

Kratos ecosystem shift changes threat-actor operations

Threat Actor Meta
H score39 First: 22.07.2026 02:07 Last: 22.07.2026 02:07 Sources 1

About this happening: The Kratos phishing-as-a-service ecosystem was dismantled after it scaled to more than 1,800 criminal customers, exposing a subscription model that drove roughly 15,000...

Timeline

  1. 25.08.2026 14:56 2 articles · 2h ago

    Mirage2FA campaign targets Microsoft 365 accounts through session theft

    Campaign Scope Update

    Mirage2FA is a phishing-as-a-service campaign targeting Microsoft 365 accounts by abusing legitimate login flows, stealing passwords and session cookies, and bypassing two-factor authentication. ANY.RUN linked the activity to thousands of companies, 4,532 unique organization email domains, more than 9,000 potential compromise events, and 48% of targeted email addresses potentially compromised, with most victims in the United States. Hijacked authenticated Microsoft 365 sessions can extend into SSO-connected services and create follow-on risks including impersonation and fraud.

    Show sources