Mirage2FA Phishing-as-a-Service Surge Hits 4,532 US and EU Organizations, Abusing Microsoft 365 Login Flows — Threadlinqs Intelligence
As of 2026-08-25, Mirage2FA Phishing-as-a-Service Surge Hits 4,532 US and EU Organizations, Abusing Microsoft 365 Login Flows is a high-severity phishing threat attributed to LinX Coders, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 21 indicators of compromise.
Threat ID: TL-2026-2140 · Severity: HIGH · Status: ACTIVE · Category: PHISHING
Attribution: LinX Coders · FINANCIAL
The commercial Mirage2FA phishing-as-a-service (PhaaS) kit, run by an operator identified as LinX Coders (LinXcoded), uses an adversary-in-the-middle reverse-proxy against real Microsoft 365 login
Mirage2FA is a subscription phishing-as-a-service platform, developed and operated by a group tracked as LinX Coders (Telegram/brand handle "LinXcoded"), purpose-built to compromise corporate Microsoft 365 accounts and hijack their authenticated sessions rather than crack or brute-force MFA. Victims receive email lures — commonly HR/benefits/401(k), invoice, secure-document, or payment-request themed — carrying browser-executable .htm, .xhtml, or .svg attachments, or a QR code ("quishing") pointing to a phishing URL. These stagers are heavily obfuscated (Base64 encoding, single-byte XOR with key 0xAD/173, TextDecoder/eval reconstruction, obfuscator.io-style `_0x` wrappers, and dynamic iframe injection) specifically to defeat static email-gateway and antivirus scanning; no compiled malware binary is ever involved, and the entire chain runs inside the victim's browser.
Once triggered, the stager pulls a second-stage loader script from attacker infrastructure via a path pattern of the form `/<3-letter-code>/xls/<token>.js` (e.g. the canonical `/api/xls/a1p2i.js`), with the victim's email address Base64-encoded into the request/DNS label as a per-recipient tracking token (config placeholders such as `LINXCODERSEMAIL` / `LINXB64EMAIL` were recovered in samples). The loader renders a pixel-accurate fake Microsoft 365 login page and, as the victim submits username, password, and one-time 2FA/authenticator code, relays that data over a persistent WebSocket channel to the real Microsoft 365 authentication endpoint in real time — an adversary-in-the-middle (AiTM) reverse-proxy technique that lets the legitimate login actually succeed while the kit captures the resulting valid session cookie. Some samples also embed fake CAPTCHA screens, spoofed authenticator/number-matching prompts, and (per code review, unconfirmed live) SMS-verification handling to keep victims inside the flow and suppress suspicion. The stolen, Base64-encoded session cookies are logged as text dumps in the operator's back-end panel and pushed to Telegram bots (`linxlogsss...bot`, `linxxlogss...bot`) for the purchasing affiliate to retrieve.
Operators reuse the harvested cookies to access the victim's mailbox, SharePoint, OneDrive, and any SSO-connected application without re-entering a password or MFA — enabling business email compromise, internal phishing pivots, fraud, and further account takeover. About one third of successful session captures originated from mobile-browser logins. Telemetry additionally shows attackers leveraging already-compromised, authenticated Microsoft 365 tenants to send further Mirage2FA lures, letting the campaign ride trusted-sender reputation and bypass conventional email filtering, and distributing lures at scale partly via Amazon SES. Infrastructure is concentrated on a small set of loader/AiTM domains (`cheacker.store` and subdomains, `volatilesour.store`, `bandhiem.com`, `pynutech.store`) and IPs in the 185.174.100.0/24 block (hosted on AS-Colocrossing), alongside 75+ short-lived phishing/typosquat domains impersonating payroll, benefits, and tax-service brands.
Target sectors: technology, manufacturing, education, consulting, telecoms
Target regions: North America, Europe, Asia, Middle East, Africa
Timeline
- Earliest Mirage2FA test activity observed in ANY.RUN interactive sandbox telemetry
- Mirage2FA phishing-as-a-service campaign begins ramping against Microsoft 365 tenants, per ANY.RUN/Fortra telemetry covering late 2024 onward
- Cross-bot operator testing of the AiTM panel observed from IPs 185.174.100.76 (US) and 139.28.36.38 (Ukraine)
- Continued operator/bot testing traffic recorded from IP 185.174.100.20, part of the shared 185.174.100.0/24 infrastructure block
- Loader/harvesting domain cheacker[.]store registered, later used to serve WebSocket-based AiTM sessions
- Fortra publishes technical analysis of the obfuscated HTML loader (Base64 + XOR 0xAD + eval) delivering the Mirage2FA Microsoft 365 MFA phishing kit
- Latest confirmed Mirage2FA sandbox activity recorded in ANY.RUN telemetry, with 445 sandbox sessions logged in July alone marking a campaign escalation
- Brinztech publishes a breach alert on LinXcoded's large-scale adversary-in-the-middle attacks against Microsoft 365 users
- The Hacker News reports ANY.RUN's findings publicly, disclosing the full campaign scale: 4,532 potentially compromised organizations across 94 countries
Detections & IOCs
As of 2026-09-06, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 21 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
PHISHING, HIGH, threat intelligence, cybersecurity, T1583.001, T1586.002, T1566.001, T1566.002, T1204.002, T1027, T1027.006, T1557, T1111, T1539