What happened
ANY.RUN says Mirage2FA activity in its data spans September 2024 through July 2026. ANY.RUN published the new scale and technical analysis on August 18, 2026. The research counted 9,426 targeted email addresses across 3,518 organisational domains and labelled 4,532 unique accounts as victims or potentially compromised. These figures come from research telemetry and should not be treated as independently confirmed breach notifications from every organisation.
ANY.RUN recorded 9,332 compromise events, including 4,561 session-cookie theft events affecting 2,541 unique victims. United States-linked victims numbered 2,885, representing 63.7% of identified victims in the dataset. The campaign also appeared across other countries, while technology, manufacturing and education were among the more heavily represented sectors.
Observed stagers included 629 .htm files, 198 XHTML files and 187 SVG files; the research reported no binary malware in the dataset. Mirage2FA used the /xls/
The production loader resolved to 185.174.100.224 and served domains including user.cheacker.store, hvr.volatilesour.store, ver.bandhiem.com and pynutech.store. Attribution posture: ANY.RUN links the operator branding to LinX Coders through repeated LINX markers, Telegram bots and infrastructure overlap, while warning that panel-derived IP and geolocation data may reflect VPN use or spoofing. The cited research did not publish a single canonical malware hash because the campaign was browser-based and reported no binary malware in the dataset.
Why this matters now
The research describes a control failure that occurs after users complete MFA successfully. Because the operator captures an authenticated session, a password change alone may leave access intact, making session revocation, token invalidation and retrospective cloud-activity review mandatory parts of the containment decision.
Mirage2FA relies on browser-readable attachments, remote JavaScript and a reverse-proxy flow rather than conventional binary malware. That operating model can bypass programmes centred on executable-file detection and requires coordinated evidence from email, secure web gateways, identity providers, endpoint browsers and Microsoft 365 audit logs.
The reported concentration in U.S. organisations and the presence of technology, manufacturing, education, consulting, telecommunications, healthcare and financial victims give the research broad enterprise relevance. Managed-service accounts deserve particular attention because one compromised identity may provide delegated paths into multiple customer environments.
The decision for security leaders
Define session theft as an identity incident category with its own containment runbook. The accountable identity owner must be able to revoke active sessions, invalidate refresh tokens, examine mailbox and cloud activity, and remove attacker-created persistence without waiting for a general password-reset process.
Prioritise phishing-resistant authentication for privileged, finance, HR and managed-service identities. Conventional one-time codes can be relayed through an adversary-in-the-middle flow, so completion of MFA should not be treated as evidence that the authenticated browser session belongs to the expected user.
Join email, web and identity telemetry. Detection requires correlating browser-executable attachments, loader requests, sign-in context, session reuse and subsequent mailbox or application activity; none of those evidence sources alone establishes the full compromise path.
Evidence of closure
- A mail and proxy search records all matches for the published IP, domains, attachment types and loader pattern.
- Every suspected identity has documented session revocation, token invalidation and sign-in review.
- Conditional-access testing blocks replay from an untrusted device or anomalous location.
- Privileged users have verified phishing-resistant authentication without weaker fallback.
The Security.io assessment
The publication’s value lies in the scale and operational detail, but its counts remain research telemetry rather than a regulator-verified incident census. The term potential compromise should remain attached to identities that have not been validated through tenant logs or direct victim confirmation.
Session-cookie theft was the largest reported outcome, which changes containment priorities. A user who has changed a password may still have an attacker operating through a previously issued session, and closure requires evidence that sessions, tokens, mailbox rules, delegated permissions and downstream actions were reviewed.
The infrastructure indicators are immediately useful but inherently perishable. The more durable control decision is whether the organisation can detect browser-based authentication relays, restrict phishable methods for high-value accounts and contain a managed-service identity before access propagates to customer tenants.
Questions for the morning meeting
- Can identity teams revoke sessions and refresh tokens at incident-response speed?
- Which privileged users can still authenticate with phishable MFA methods?
- Do mail and proxy controls inspect browser-executable .htm, XHTML and SVG attachments?
- Can managed-service identities be contained without losing downstream customer visibility?