Mirage2FA Hijacks Companies’ Microsoft 365 Sessions, with Over 4K Victims in the US
Mirage2FA is a phishing-as-a-service toolkit that uses an Adversary-in-the-Middle (AiTM) architecture to steal Microsoft 365 credentials and authenticated session cookies. It bypasses conventional multi-factor authentication by relaying victim credentials and 2FA codes to Microsoft over WebSocket channels in real-time. The campaign primarily targets US organizations across technology, manufacturing, and education sectors using browser-executed attachments like .htm, .xhtml, and .svg.
- domainadp[.]pslcertlive[.]sitePhishing domain used in the campaign.
- domainans[.]rsxbenefits[.]comPhishing domain used in the campaign.
- domainari[.]vslbertlive[.]infoPhishing domain used in the campaign.
- domainars[.]greebys[.]comPhishing domain used in the campaign.
- domainasvbtech[.]storePhishing domain used in the campaign.
- domainavsbtech[.]storePhishing domain used in the campaign.
- domainbezdelz[.]storePhishing domain used in the campaign.
- domainbns[.]baseasix[.]comPhishing domain used in the campaign.
- domainbsf[.]allmetreod[.]comPhishing domain used in the campaign.
- domainbverster[.]storePhishing domain used in the campaign.
- domaincementslabconstruction[.]comPhishing domain used in the campaign.
- domaincer[.]septey[.]shopPhishing domain used in the campaign.
- domaincer[.]verpox[.]shopPhishing domain used in the campaign.
- domaincureaveritax[.]storePhishing domain used in the campaign.
- domaincvs[.]pcvgtech[.]onlinePhishing domain used in the campaign.
- domaindezbelz[.]storePhishing domain used in the campaign.
- domaindverster[.]storePhishing domain used in the campaign.
- domaineverster[.]storePhishing domain used in the campaign.
- domainfureaveritax[.]storePhishing domain used in the campaign.
- domainfverster[.]storePhishing domain used in the campaign.
- domaingacorslot7d[.]comPhishing domain used in the campaign.
- domaingalatasaraydanhaberler[.]comPhishing domain used in the campaign.
- domaingectech[.]storePhishing domain used in the campaign.
- domaingverster[.]storePhishing domain used in the campaign.
- domaingztev[.]it[.]comPhishing domain used in the campaign.
- domainhpn[.]bandhiem[.]comPhishing domain used in the campaign.
- domainhverster[.]storePhishing domain used in the campaign.
- domainhvr[.]volatilesour[.]storeC2 domain used for loader retrieval and AiTM proxy operations.
- domainhynutech[.]storePhishing domain used in the campaign.
- domainimplentedgucedirectory[.]comPhishing domain used in the campaign.
- domainintrugementslayerdocuservice[.]comPhishing domain used in the campaign.
- domainiverster[.]storePhishing domain used in the campaign.
- domainjscvbtech[.]storePhishing domain used in the campaign.
- domainjureaveritax[.]storePhishing domain used in the campaign.
- domainjverster[.]storePhishing domain used in the campaign.
- domainmettsoll[.]comPhishing domain used in the campaign.
- domainoectech[.]storePhishing domain used in the campaign.
- domainoffice[.]avcbtech[.]storePhishing domain used in the campaign.
- domainoffice[.]pcvgtech[.]storePhishing domain used in the campaign.
- domainpancincorp[.]comPhishing domain used in the campaign.
- domainpavetech[.]storePhishing domain used in the campaign.
- domainpectech[.]storePhishing domain used in the campaign.
- domainpezbelz[.]storePhishing domain used in the campaign.
- domainpureaveritax[.]storePhishing domain used in the campaign.
- domainpvf[.]schwiessdoors[.]comPhishing domain used in the campaign.
- domainpvs[.]schwiessdoors[.]comPhishing domain used in the campaign.
- domainpxvbtech[.]storePhishing domain used in the campaign.
- domainpynutech[.]storePhishing domain used in the campaign.
- domainrfm[.]m3-bulders[.]comPhishing domain used in the campaign.
- domainrmf[.]diversesgs[.]comPhishing domain used in the campaign.
- domainrmf[.]m3-bulders[.]comPhishing domain used in the campaign.
- domainsopbtech[.]storePhishing domain used in the campaign.
- domainsvn[.]dpsindustrialsgroup[.]comPhishing domain used in the campaign.
- domainsvr[.]schwiessdoors[.]comPhishing domain used in the campaign.
- domainuser[.]cheacker[.]storeC2 domain used for loader retrieval and AiTM proxy operations.
- domainver[.]verpox[.]shopPhishing domain used in the campaign.
- domainvezbelz[.]storePhishing domain used in the campaign.
- domainvns1[.]pigotnet[.]comPhishing domain used in the campaign.
- domainvns[.]pigotnet[.]comPhishing domain used in the campaign.
- domainvns[.]tvgsv[.]comPhishing domain used in the campaign.
- domainvrf[.]atskinsonel[.]comPhishing domain used in the campaign.
- domainvrf[.]bereetro[.]it[.]comPhishing domain used in the campaign.
- domainvrf[.]gavernova[.]comPhishing domain used in the campaign.
- domainvrf[.]iar0nline[.]comPhishing domain used in the campaign.
- domainwectech[.]storePhishing domain used in the campaign.
- domainwes[.]cadsta[.]onlinePhishing domain used in the campaign.
- domainzectech[.]storePhishing domain used in the campaign.
- filenamecontract_agreement_edocs_reviewd_Refs%23_452aa66aa92077018d7b7b979edca39dfb0931fc.htmlMalicious HTML file dropped to disk for execution in the browser.
- filenameC:\Users\admin\Desktop\contract_agreement_edocs_reviewd_Refs%23_452aa66aa92077018d7b7b979edca39dfb0931fc.htmlFile path of the malicious HTML attachment opened on the victim's desktop.
- ip139[.]28[.]36[.]38Operator test IP used for dry-run submissions.
- ip141[.]95[.]59[.]233Operator test IP used for dry-run submissions.
- ip146[.]70[.]195[.]104Operator test IP used for dry-run submissions.
- ip181[.]214[.]165[.]173Operator test IP used for dry-run submissions.
- ip185[.]174[.]100[.]20Operator test IP used for dry-run submissions across multiple bots.
- ip185[.]174[.]100[.]224C2 and loader IP address used to host malicious JavaScript payloads.
- ip185[.]174[.]100[.]76Operator test IP used for dry-run submissions.
- ip185[.]199[.]103[.]116Operator test IP used for dry-run submissions.
- ip185[.]91[.]122[.]32Operator test IP used for dry-run submissions.
- ip192[.]52[.]166[.]55Operator test IP used for dry-run submissions.
- ip199[.]233[.]237[.]30Operator test IP used for dry-run submissions.
- ip209[.]205[.]192[.]6Operator test IP used for dry-run submissions.
- ip209[.]205[.]197[.]130Operator test IP used for dry-run submissions.
- ip83[.]147[.]53[.]130Operator test IP used for dry-run submissions.
- ip84[.]239[.]25[.]135Operator test IP used for dry-run submissions.
- ip84[.]239[.]25[.]139Operator test IP used for dry-run submissions.
- ip84[.]239[.]25[.]144Operator test IP used for dry-run submissions.
- ip84[.]239[.]27[.]17Operator test IP used for dry-run submissions.
- ip84[.]239[.]43[.]155Operator test IP used for dry-run submissions.
- ip98[.]144[.]204[.]109Operator test IP used for dry-run submissions.
- ip98[.]93[.]13[.]101Operator test IP used for dry-run submissions.
- ip98[.]98[.]79[.]35Operator test IP used for dry-run submissions.
- md5920ca9177f0eb0612f597ee3a2bd4731MD5 hash of the malicious archive containing the HTML phishing stager.
Detection / Hunteropenrouter
What Happened
Attackers are using a service called Mirage2FA to steal active login sessions for Microsoft 365 accounts. They send phishing emails with attachments or QR codes that, when opened, display a fake login page. When a user enters their password and second factor code, the attackers intercept it, log in to the real Microsoft on the user's behalf, and steal the active session. This affects companies, especially in the US, and means that just having a password and a phone code is not enough to stop them. Organizations should use stronger login methods like passkeys, block suspicious email attachments, and teach employees to watch out for these fake login pages.
Key Takeaways
- Mirage2FA is a phishing-as-a-service toolkit that uses Adversary-in-the-Middle (AiTM) architecture to steal Microsoft 365 credentials and active session cookies.
- The toolkit bypasses conventional MFA by relaying authentication data to Microsoft over WebSocket channels in real-time.
- Attackers deliver the phishing payload via browser-executed attachments like .htm, .xhtml, and .svg, avoiding binary malware.
- The campaign has targeted over 4,000 victims, primarily in the United States, focusing on the Technology, Manufacturing, and Education sectors.
- Detection should focus on behavioral patterns like the /xls/*.js loader path, Base64-encoded email subdomains, and outbound WebSocket traffic post-JavaScript execution.
Affected Systems
- Microsoft 365 users
- Corporate environments
- Web browsers
Vulnerabilities (CVEs)
None identified.
Attack Chain
- Initial Access: Phishing email delivers a malicious .htm, .xhtml, or .svg attachment, or directs the victim to a QR-code link.
- Execution: The victim opens the attachment, causing the browser to execute the embedded JavaScript stager.
- Client-side staging: Obfuscated HTML or SVG decodes and reads a per-recipient token, such as the victim's Base64-encoded email.
- C2: The stager retrieves harvesting logic from a remote loader using the /xls/<token>.js pattern.
- Credential Capture: The victim enters credentials and 2FA on a fake Microsoft 365 page proxied by an AiTM reverse proxy.
- Exfiltration: Authenticated session cookies and credentials are exfiltrated to the operator panel as Base64-encoded .txt dumps.
Detection Availability
- YARA Rules: No
- Sigma Rules: No
- Snort/Suricata Rules: No
- KQL Queries: No
- Splunk SPL Queries: No
- EQL Queries: No
- Other Detection Logic: Yes
- Platforms: ANY.RUN TI Lookup
The article provides a TI Lookup query string (url:"/???/xls/?????*.js$") and regex patterns for network signatures, but does not provide formal YARA, Sigma, or SIEM query bodies.
Detection Engineering Assessment
| Dimension | Rating | Rationale |
|---|---|---|
| EDR Visibility | Medium | EDR can detect file drops and process execution, such as msedge.exe opening local HTML files. Browser-based JavaScript execution and WebSocket traffic may be opaque depending on the EDR's telemetry depth. |
| Network Visibility | High | Web proxy logs and DNS queries can capture the /xls/*.js requests, Base64 email subdomains, and outbound WebSocket connections to C2 infrastructure. |
| Detection Difficulty | Moderate | The attack uses standard web protocols and rotates domains, but the /xls/*.js path pattern and Base64 email subdomains are distinct behavioral indicators. |
Required Log Sources
- Web proxy logs
- DNS logs
- Email gateway logs
- EDR process execution logs
- Microsoft Entra ID sign-in logs
Hunting Hypotheses
| Hypothesis | Telemetry | ATT&CK Stage | FP Risk |
|---|---|---|---|
| Hunt for HTTP GET requests matching the path pattern for JavaScript loaders in web proxy logs, which indicates Mirage2FA loader retrieval. | Web proxy logs | C2 | Low. The specific path structure is atypical for standard web applications. |
| Look for DNS queries where the subdomain label is a Base64-encoded string ending in a known kit domain, as this decodes to the victim's email address. | DNS logs | C2 | Low. Base64-encoded email subdomains are not standard DNS behavior. |
| Search for outbound WebSocket connections initiated by browser processes shortly after fetching a JavaScript file from an unknown or recently registered domain. | EDR network telemetry, endpoint firewall logs | Exfiltration | Medium. WebSocket connections are common for modern web applications, requiring context of the preceding JS fetch. |
| Identify local HTML or SVG files being opened by browser processes that originate from email attachments or user desktop folders. | EDR process execution logs | Execution | Medium. Legitimate users may open local HTML files, but those originating from email attachments are suspicious. |
| Monitor Microsoft Entra ID sign-in logs for sessions where the client IP or user agent does not match the user's typical profile, indicating a stolen session cookie being reused. | Microsoft Entra ID sign-in logs | Account Takeover | Medium. Users may travel or use new devices, requiring baseline behavior analysis. |
Control Gaps
- Traditional MFA (OTP) does not prevent AiTM attacks.
- Static URL and domain blocklists will fail due to rapid infrastructure rotation.
- Email gateways may not inspect obfuscated JavaScript inside .htm or .svg attachments.
Key Behavioral Indicators
- Browser process opening local .htm or .svg file followed by outbound network connection to fetch /xls/*.js.
- WebSocket traffic to unknown host post-JavaScript execution.
- Presence of LINX* placeholder strings in HTTP requests or file contents.
False Positive Assessment
Low. The /xls/*.js path pattern and Base64 email subdomains are highly specific to this phishing kit.
Recommendations
Immediate Mitigation
- Verify against your organization's incident response runbook and team escalation paths before acting. If compromise is suspected, revoke all active sessions and tokens for the affected user in Microsoft Entra ID, not just resetting the password.
- Block or quarantine .htm, .xhtml, and .svg attachments at the email gateway where possible.
- Add detection for HTML smuggling and obfuscated JavaScript characteristics in email attachments.
Infrastructure Hardening
- Consider implementing Continuous Access Evaluation (CAE) in Microsoft Entra ID to shorten the window of opportunity for stolen session cookies.
- Evaluate blocking outbound WebSocket connections to unknown or newly registered domains from corporate endpoints.
- Implement DNS filtering for Base64-encoded subdomains resolving to known phishing TLDs.
User Protection
- Move high-risk users (administrators, finance, executives) to phishing-resistant MFA such as FIDO2/WebAuthn or passkeys.
- Shorten session lifetimes for Microsoft 365 applications to limit the usability of stolen cookies.
- Ensure mobile devices used for corporate email have endpoint protection or secure browsers to inspect URLs better.
Security Awareness
- Incorporate warnings about QR-code phishing and fake Microsoft 365 login pages into existing security awareness training.
- Emphasize that mobile devices are heavily targeted and URL inspection is more difficult on those platforms.
- Train users to report emails from Amazon SES or external senders containing attachments requiring immediate action.
MITRE ATT&CK Mapping
Initial Access
Execution
Credential Access
Command and Control
Additional IOCs
- Ips:
209[.]205[.]192[.]6- Operator test IP used for dry-run submissions.141[.]95[.]59[.]233- Operator test IP used for dry-run submissions.185[.]174[.]100[.]20- Operator test IP used for dry-run submissions across multiple bots.181[.]214[.]165[.]173- Operator test IP used for dry-run submissions.84[.]239[.]43[.]155- Operator test IP used for dry-run submissions.83[.]147[.]53[.]130- Operator test IP used for dry-run submissions.146[.]70[.]195[.]104- Operator test IP used for dry-run submissions.139[.]28[.]36[.]38- Operator test IP used for dry-run submissions.185[.]174[.]100[.]76- Operator test IP used for dry-run submissions.209[.]205[.]197[.]130- Operator test IP used for dry-run submissions.98[.]144[.]204[.]109- Operator test IP used for dry-run submissions.84[.]239[.]25[.]144- Operator test IP used for dry-run submissions.84[.]239[.]25[.]135- Operator test IP used for dry-run submissions.84[.]239[.]27[.]17- Operator test IP used for dry-run submissions.98[.]98[.]79[.]35- Operator test IP used for dry-run submissions.185[.]91[.]122[.]32- Operator test IP used for dry-run submissions.185[.]199[.]103[.]116- Operator test IP used for dry-run submissions.192[.]52[.]166[.]55- Operator test IP used for dry-run submissions.84[.]239[.]25[.]139- Operator test IP used for dry-run submissions.199[.]233[.]237[.]30- Operator test IP used for dry-run submissions.98[.]93[.]13[.]101- Operator test IP used for dry-run submissions.
- Domains:
adp[.]pslcertlive[.]site- Phishing domain used in the campaign.ans[.]rsxbenefits[.]com- Phishing domain used in the campaign.ari[.]vslbertlive[.]info- Phishing domain used in the campaign.ars[.]greebys[.]com- Phishing domain used in the campaign.asvbtech[.]store- Phishing domain used in the campaign.avsbtech[.]store- Phishing domain used in the campaign.bezdelz[.]store- Phishing domain used in the campaign.bns[.]baseasix[.]com- Phishing domain used in the campaign.bsf[.]allmetreod[.]com- Phishing domain used in the campaign.bverster[.]store- Phishing domain used in the campaign.cementslabconstruction[.]com- Phishing domain used in the campaign.cer[.]septey[.]shop- Phishing domain used in the campaign.cer[.]verpox[.]shop- Phishing domain used in the campaign.cureaveritax[.]store- Phishing domain used in the campaign.cvs[.]pcvgtech[.]online- Phishing domain used in the campaign.dezbelz[.]store- Phishing domain used in the campaign.dverster[.]store- Phishing domain used in the campaign.everster[.]store- Phishing domain used in the campaign.fureaveritax[.]store- Phishing domain used in the campaign.fverster[.]store- Phishing domain used in the campaign.gacorslot7d[.]com- Phishing domain used in the campaign.galatasaraydanhaberler[.]com- Phishing domain used in the campaign.gectech[.]store- Phishing domain used in the campaign.gverster[.]store- Phishing domain used in the campaign.gztev[.]it[.]com- Phishing domain used in the campaign.hpn[.]bandhiem[.]com- Phishing domain used in the campaign.hverster[.]store- Phishing domain used in the campaign.hynutech[.]store- Phishing domain used in the campaign.implentedgucedirectory[.]com- Phishing domain used in the campaign.intrugementslayerdocuservice[.]com- Phishing domain used in the campaign.iverster[.]store- Phishing domain used in the campaign.jscvbtech[.]store- Phishing domain used in the campaign.jureaveritax[.]store- Phishing domain used in the campaign.jverster[.]store- Phishing domain used in the campaign.mettsoll[.]com- Phishing domain used in the campaign.oectech[.]store- Phishing domain used in the campaign.office[.]avcbtech[.]store- Phishing domain used in the campaign.office[.]pcvgtech[.]store- Phishing domain used in the campaign.pancincorp[.]com- Phishing domain used in the campaign.pavetech[.]store- Phishing domain used in the campaign.pectech[.]store- Phishing domain used in the campaign.pezbelz[.]store- Phishing domain used in the campaign.pureaveritax[.]store- Phishing domain used in the campaign.pvf[.]schwiessdoors[.]com- Phishing domain used in the campaign.pvs[.]schwiessdoors[.]com- Phishing domain used in the campaign.pxvbtech[.]store- Phishing domain used in the campaign.pynutech[.]store- Phishing domain used in the campaign.rfm[.]m3-bulders[.]com- Phishing domain used in the campaign.rmf[.]diversesgs[.]com- Phishing domain used in the campaign.rmf[.]m3-bulders[.]com- Phishing domain used in the campaign.sopbtech[.]store- Phishing domain used in the campaign.svn[.]dpsindustrialsgroup[.]com- Phishing domain used in the campaign.svr[.]schwiessdoors[.]com- Phishing domain used in the campaign.ver[.]verpox[.]shop- Phishing domain used in the campaign.vezbelz[.]store- Phishing domain used in the campaign.vns[.]pigotnet[.]com- Phishing domain used in the campaign.vns[.]tvgsv[.]com- Phishing domain used in the campaign.vns1[.]pigotnet[.]com- Phishing domain used in the campaign.vrf[.]atskinsonel[.]com- Phishing domain used in the campaign.vrf[.]bereetro[.]it[.]com- Phishing domain used in the campaign.vrf[.]gavernova[.]com- Phishing domain used in the campaign.vrf[.]iar0nline[.]com- Phishing domain used in the campaign.wectech[.]store- Phishing domain used in the campaign.wes[.]cadsta[.]online- Phishing domain used in the campaign.zectech[.]store- Phishing domain used in the campaign.
- File Hashes:
920CA9177F0EB0612F597EE3A2BD4731(MD5) - MD5 hash of the malicious archive containing the HTML phishing stager.
- File Paths:
C:\Users\admin\Desktop\contract_agreement_edocs_reviewd_Refs%23_452aa66aa92077018d7b7b979edca39dfb0931fc.html- File path of the malicious HTML attachment opened on the victim's desktop.
- Command Lines:
- Purpose: Open malicious HTML attachment in browser | Tools:
msedge.exe| Stage: Execution |msedge.exe --single-argument <file_path>
- Purpose: Open malicious HTML attachment in browser | Tools: