Security1 distinct publisher3 min readPublished
ANY.RUN says a commercial phishing kit ran against Microsoft 365 login flows from 2024 to 2026, harvesting session cookies. The control that matters now is what happens to the token.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
An adversary-in-the-middle proxy does not need the second factor to be weak. It needs it used once, in front of a page that relays it, after which the thing worth stealing is the cookie the identity provider returns [8]. ANY.RUN puts the gap in authentication and session management rather than in the factor itself [9], and that distinction is the whole story: the password reset that closes most ticket queues does nothing to a cookie already in someone else's browser [11].
The arithmetic in the writeup is worth doing. More than 9,000 potential compromise events [5] spread across 4,532 organization email domains [4] works out to about two events per domain [15]. That ratio is coarse, because the event categories overlap by design: cookie theft, password theft, SSO logins and 2FA bypass are counted in the same bucket [5], and a single hijacked account can plausibly generate several. Still, it does not look like a spray that landed once per target. Neither does the reported hit rate of 48% of targeted addresses, which is a shade under one in two [2][16].
The hedging deserves attention too. "Potentially compromised" and "potential compromise events" are the load-bearing words [2][5], and the denominator behind them is not published. This is one vendor's telemetry: the two source texts supplied here are the same Hacker News article [14], and it arrives alongside ANY.RUN's own product numbers, including detection in 14 seconds, 21 minutes off mean time to respond per case, and feed data drawn from more than 16,000 organizations [13]. Take the campaign shape seriously and the counts as a floor of unknown height.
What the piece does not say is which authentication methods the victims had switched on [19]. Without that, nobody can claim from this data that phishing-resistant credentials would have stopped it, only that conventional MFA did not [9]. The recommendations stop at prioritising phishing-resistant authentication, behavioural detection and response built for session theft [20], plus revoking sessions and tokens and investigating the identity rather than resetting the password [10]. Those are the right instincts and they stop one step short of the mechanism. If the stolen artifact is a bearer token, the fix is to stop it being a bearer token: bind it to the device that obtained it, and put conditional access in the path so a replay from unfamiliar infrastructure fails the check rather than merely logging it. Neither control is named in the writeup, which is a gap in the advice, not in the finding.
For operators, the practical delta is in the runbook. Technology, manufacturing and education came up most often as targets [7], and any of them can answer a questionnaire truthfully with "MFA enforced" while having no tested procedure for pulling refresh tokens on a Friday night.
Ranked by verification strength, evidence, and original report placement.
Mirage2FA, described as a commercial phishing-as-a-service toolkit, affected thousands of companies from 2024 to 2026 by targeting Microsoft 365 accounts, abusing legitimate login flows and bypassing two-factor authentication.
According to ANY.RUN research, 48% of targeted email addresses were potentially compromised.
Mirage2FA activity is potentially linked to 4,532 unique organization email domains.
The second supplied source block carries the same headline and identical text as the first, both attributed to thehackernews.com at the same article path, with the URLs differing only by tracking parameters.
The published headline reads: Mirage2FA Surge Hits 4,500 US and EU Companies, Abusing Microsoft 365 Login Flows.
The United States accounted for 63.7% of total victims.
Follow any of these and your For You feed starts watching them — no settings page required.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Single vendor-authored post, duplicated
All claims trace to one ANY.RUN write-up republished under one publisher, present twice in the cluster as the same URL with different tracking parameters. The scope figures are hedged ('potentially compromised', 'potentially linked') with no methodology, no deduplication detail, no IOCs, and no victim-side authentication configuration. The mechanism description — AiTM proxying of a Microsoft 365 login to steal session cookies — is internally coherent and consistent with the response guidance, which is what keeps this above the floor.
Vendor telemetry scale, unverified
There is a concrete disclosure event with quantified reach — 4,532 potentially linked email domains, 9,000+ potential compromise events, named countries and industries over a 2024-2026 window — which is real adoption-style scale signal for an attack campaign. It is discounted because every number is self-reported by one vendor, counts domains rather than confirmed victim organizations, and no affected organization, CERT, or platform provider is cited confirming compromise.
Framing outruns the hedged data
Positive gap: the headline promises a 'surge' hitting '4,500 US and EU Companies' when the body names no EU member state and counts email domains rather than companies, and the strongest numbers are qualified as merely potential. The write-up also converts the finding into product calls to action with unaudited performance metrics. The underlying claim that session-cookie theft defeats conventional MFA is not itself overstated — it is well-established tradecraft — which caps the gap short of the extreme.
Vendor research with direct product pitch
The research originator is also the seller: the article ends each mitigation subsection with ANY.RUN calls to action for sandboxing, Threat Intelligence Feeds and Threat Intelligence Lookup, quotes its own detection and MTTR performance numbers, and cites its 16,000+ organization telemetry base as a selling point. The alarming framing of MFA insufficiency directly serves demand for that tooling, and the publisher carries the piece unmodified in duplicate.
Clear on what was claimed, weak on ground truth
Confidence is solid about the text itself — one publisher, two identical items, unambiguous figures and guidance — and about the general validity of the AiTM session-theft mechanism and the token-revocation response. It is materially lower about the campaign's true magnitude, victim identities, and how many of the 'potential' events were real compromises, because there is no second source, no methodology, and no third-party confirmation.
leadership
Enterprise security reviews went from 20 questions to hundreds of rows, and vendors pay first1 distinct publisher
security
Silver Fox times ValleyRAT to India's GST deadline behind a real Microsoft signature1 distinct publisher
build
SPF and DMARC records that pass every free checker and stop nothing1 distinct publisher
build
Google Docs is not end-to-end encrypted because the merge has to happen somewhere1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
2 articles · August 25, 2026