Mirage2FA Surge: Microsoft 365 Session Hijacks Rise
π‘οΈ The Mirage2FA campaign (2024β2026) has impacted thousands of organizations by abusing legitimate Microsoft 365 login flows to bypass two-factor authentication. ANY.RUN research links the activity to 4,532 unique organization domains, with 63.7% of victims in the US and others across multiple regions. Attackers steal passwords and session cookies to hijack authenticated sessions, enabling impersonation, fraud, and access to SSO-connected services.
