Mirage2FA 캠페인이 4,500개 이상의 미국 및 EU 기업을 타겟으로 하여 2단계 인증을 우회하고 있습니다.
Mirage2FA 캠페인은 2024년부터 2026년까지 4,500개 이상의 미국 및 유럽 기업에 영향을 미쳤습니다. 이 캠페인은 Microsoft 365 계정을 목표로 하며, 정당한 로그인 플로우를 악용하고 2단계 인증을 우회하는 피싱 툴킷입니다. ANY.RUN의 연구에 따르면, 목표로 삼은 이메일 주소의 48%가 잠재적으로 침해당했습니다. 대부분의 피해 기업은 미국에 기반을 두고 있습니다.
The Mirage2FA campaign targets 4,500+ US and EU companies by bypassing two-factor authentication on Microsoft 365.
The Mirage2FA campaign has affected over 4,500 companies in the US and EU between 2024 and 2026. This campaign uses a phishing-as-a-service toolkit that targets Microsoft 365 accounts by abusing legitimate login flows and bypassing two-factor authentication. According to ANY.RUN research, 48% of the targeted email addresses may have been compromised, with most affected companies being based in the US.