.webp)
Mirage2FA: The Phishing Service Turning a Stolen Microsoft 365 Cookie Into Full Account Takeover
A phishing-as-a-service kit sold by a crew calling itself LinX Coders steals the one thing a password reset can’t fix — the live session cookie — and ANY.RUN’s telemetry ties it to 9,332 compromise events reaching 94 countries. For most defenders, a phishing alert ends with a forced password change. Mirage2FA is built to make that response useless. The phishing-as-a-service kit documented […]
The post Mirage2FA: The Phishing Service Turning a Stolen Microsoft 365 Cookie Into Full Account Takeover appeared first on Cyber Security News.