Two pulses surfaced on AlienVault OTX this week that, while operationally distinct, converge on a single strategic theme: the industrialization of identity and perception attacks. One operation hijacks authenticated Microsoft 365 sessions at scale through Adversary-in-the-Middle phishing; the other sells coordinated inauthentic behavior as a commercial service. Both bypass traditional perimeter defenses, and both are attributable to organized, revenue-driven adversaries. Enterprise defenders should treat these as complementary signals of where the threat economy is heading.
Threat Summary
Pulse 1 — Mirage2FA (Actor: LinX Coders): A phishing-as-a-service (PhaaS) toolkit purpose-built to defeat multi-factor authentication on Microsoft 365 tenants. Between 2024 and 2026 the operation generated thousands of compromise events, with 63.7% of identified victims located in the United States. Technology, Manufacturing, and Education are the most heavily targeted verticals, followed by Finance, Healthcare, and Telecommunications. The kit uses HTML smuggling to deliver lure content past email gateways and a WebSocket-based Adversary-in-the-Middle (AiTM) relay to proxy the victim's live authentication session against legitimate Microsoft endpoints — capturing both credentials and the session cookie, rendering 2FA moot.
Pulse 2 — BlackCore: An Israeli influence-for-hire company identified conducting digital manipulation campaigns across at least eight countries, including the US, UK, France, Angola, Gabon, Togo, Iran, and Australia. Services advertised include discourse dominance, organic engagement manipulation, and counter-operations. Infrastructure analysis reveals a mature multi-tenant platform (dedicated subdomains for API, authentication, client demos, and per-country campaign instances such as angola-plan.blackcore.online) consistent with a commercial operation serving government and political clients. Government and Media sectors are the primary targets.
Collective read: Both operations are service-model threats. Mirage2FA lowers the barrier for commodity criminals to execute nation-state-grade session hijacking; BlackCore lowers the barrier for state and political actors to execute population-scale manipulation. The common denominator is infrastructure-as-a-product — and that infrastructure leaves detectable fingerprints.
Threat Actor / Malware Profile
Mirage2FA PhaaS (LinX Coders)
| Attribute | Detail |
|---|---|
| Distribution | Phishing emails with HTML attachments (HTML smuggling); lures impersonate Microsoft 365, ADP, and benefits/HR portals (note IOC hostnames like adp.pslcertlive.site and ans.rsxbenefits.com) |
| Payload behavior | Smuggled HTML reconstructs a phishing page client-side, then proxies the victim's authentication to legitimate Microsoft login endpoints in real time |
| C2 communication | Persistent WebSocket channel between the victim browser and the attacker-controlled relay; allows live session token and cookie interception, plus real-time operator interaction (e.g., prompting for MFA codes mid-flow) |
| Persistence | Stolen session cookies are replayed directly — no endpoint persistence required. Attackers register attacker-controlled MFA methods or create inbox rules post-compromise for durable access (BEC staging) |
| Anti-analysis | HTML smuggling evades attachment scanning; victim-IP and user-agent filtering on phishing pages; short-lived rotating domains on low-reputation TLDs (.store, .shop, .site, .info) |
Targeting insight: The ADP/benefits-themed hostnames indicate deliberate targeting of HR and payroll workflows — a classic BEC entry point that converts session theft into wire fraud.
BlackCore (Influence-for-Hire)
| Attribute | Detail |
|---|---|
| Model | Commercial influence operations: fake personas, AI-generated content, coordinated engagement manipulation, discourse dominance, counter-operations |
| Infrastructure | Multi-tenant SaaS-style architecture: api.blackcore.online, auth.blackcore.online, demo.blackcore.online, per-language (en.) and per-campaign (angola-plan.) subdomains |
| Delivery | Social media platforms; fake persona networks; AI-generated text and imagery |
| Detection surface | Coordinated inauthentic behavior analytics, infrastructure overlap, WHOIS/DNS clustering, and network traffic to management plane subdomains from corporate networks (potential insider or target reconnaissance indicator) |
IOC Analysis
Indicator composition across both pulses (80 total IOCs):
- Domains (~10): Registrable domains — e.g.,
galatasaraydanhaberler.com,sopbtech.store,blackcore.online,agitanews.net. High-value for DNS sinkholing and proxy blocking; expect short TTLs and fast rotation for the Mirage2FA set. - Hostnames (~14): Fully qualified subdomains carrying campaign context —
office.pcvgtech.store(M365 lure),adp.pslcertlive.site(payroll lure),api.blackcore.online(management plane). Hostnames are the highest-fidelity indicators here: they encode both the lure theme and campaign instance.
Operationalization guidance for SOC teams:
- DNS-layer enforcement: Push domains and hostnames to your recursive DNS resolver (RPZ) and secure web gateway within 1 hour. Hostname-level blocks catch subdomains that domain-level wildcard rules may miss on some appliances.
- Retroactive hunting: Query DNS, proxy, and EDR network telemetry back at least 90 days — Mirage2FA has operated since 2024 and domains rotate quickly; historical hits matter more than forward blocks.
- Certificate transparency: Monitor CT logs for new certificates on lookalike patterns (
*certlive.*,*bertlive.*,office.*on low-reputation TLDs) to catch rotation before OTX pulses land. - Enrichment tooling: ANY.RUN sandbox for dynamic analysis of smuggled HTML; urlscan.io for phishing page DOMs; OTX pulsing for related infrastructure pivots.
Detection Engineering
---
title: Mirage2FA HTML Smuggling Attachment Dropped by Email Client or Browser
description: Detects HTML attachment write events consistent with Mirage2FA PhaaS HTML smuggling lures targeting Microsoft 365 credentials and sessions (LinX Coders).
id: 7a3f1c2e-9b41-4d5a-a1c2-mirage2fa0001
status: experimental
author: Security Arsenal Threat Intelligence
references:
- https://any.run/cybersecurity-blog/mirage2fa-phishing-targets-us-companies/
date: 2026/09/19
logsource:
category: file_event
product: windows
definition: Requires Sysmon or equivalent file creation telemetry
detection:
selection_browser:
Image|endswith:
- '\chrome.exe'
- '\msedge.exe'
- '\firefox.exe'
TargetFilename|endswith:
- '.html'
- '.htm'
selection_office:
Image|endswith:
- '\OUTLOOK.EXE'
TargetFilename|endswith:
- '.html'
- '.htm'
filter_downloads:
TargetFilename|contains:
- '\Downloads\'
- '\AppData\Local\Temp\'
condition: (selection_browser or selection_office) and filter_downloads
falsepositives:
- Legitimate HTML report exports from SaaS applications
level: medium
tags:
- attack.t1566.002
- attack.t1027.006
---
title: WebSocket-Based AiTM Phishing Domain Resolution - Mirage2FA Infrastructure
description: Detects DNS queries to known Mirage2FA PhaaS infrastructure used for Adversary-in-the-Middle Microsoft 365 session hijacking via WebSocket relay.
id: 8b4e2d3f-0c52-5e6b-b2d3-mirage2fa0002
status: experimental
author: Security Arsenal Threat Intelligence
references:
- https://any.run/cybersecurity-blog/mirage2fa-phishing-targets-us-companies/
date: 2026/09/19
logsource:
category: dns
definition: Requires DNS query logging (firewall, resolver, or endpoint)
detection:
selection:
query:
- 'galatasaraydanhaberler.com'
- 'sopbtech.store'
- 'office.pcvgtech.store'
- 'ver.verpox.shop'
- 'cementslabconstruction.com'
- 'adp.pslcertlive.site'
- 'ans.rsxbenefits.com'
- 'ari.vslbertlive.info'
condition: selection
falsepositives:
- Unlikely; low-reputation TLD phishing infrastructure
level: high
tags:
- attack.t1557
- attack.t1539
- attack.t1071.001
---
title: BlackCore Influence Operations Management Plane Access
description: Detects network connections to BlackCore influence-for-hire platform infrastructure, which may indicate targeting reconnaissance, insider engagement, or exposure to influence campaign tooling.
id: 9c5f3e4a-1d63-6f7c-c3e4-blackcore0003
status: experimental
author: Security Arsenal Threat Intelligence
references:
- https://citizenlab.ca/research/blackcores-influence-operations-for-hire/
date: 2026/09/19
logsource:
category: proxy
definition: Requires web proxy or secure web gateway logs
detection:
selection:
c-http-host|contains:
- 'blackcore.online'
- 'agitanews.net'
condition: selection
falsepositives:
- Threat intelligence research and attribution activity by security teams
level: medium
tags:
- attack.t1583.001
- attack.t1585.003
// Mirage2FA + BlackCore IOC and behavior hunt — Microsoft Sentinel
// Hunts network events to known AiTM phishing and influence-for-hire infrastructure,
// plus suspicious WebSocket connections from browsers to low-reputation TLDs.
let Mirage2FA_IOCs = dynamic([
"galatasaraydanhaberler.com", "sopbtech.store", "office.pcvgtech.store",
"ver.verpox.shop", "cementslabconstruction.com", "adp.pslcertlive.site",
"ans.rsxbenefits.com", "ari.vslbertlive.info"
]);
let BlackCore_IOCs = dynamic([
"blackcore.online", "agitanews.net", "angola-plan.blackcore.online",
"api.blackcore.online", "auth.blackcore.online", "ava.blackcore.online",
"demo.blackcore.online", "en.blackcore.online"
]);
let SuspiciousTLDs = dynamic([".store", ".shop", ".site", ".info"]);
union isfuzzy=true
(
DeviceNetworkEvents
| where TimeGenerated > ago(90d)
| where RemoteUrl has_any (Mirage2FA_IOCs)
| extend Campaign = "Mirage2FA"
| project TimeGenerated, Campaign, DeviceName, InitiatingProcessFileName,
InitiatingProcessCommandLine, RemoteUrl, RemoteIP, ActionType
),
(
DeviceNetworkEvents
| where TimeGenerated > ago(90d)
| where RemoteUrl has_any (BlackCore_IOCs)
| extend Campaign = "BlackCore"
| project TimeGenerated, Campaign, DeviceName, InitiatingProcessFileName,
InitiatingProcessCommandLine, RemoteUrl, RemoteIP, ActionType
),
(
// Behavioral: browser-initiated connections to suspicious TLDs followed by M365 auth
DeviceNetworkEvents
| where TimeGenerated > ago(30d)
| where InitiatingProcessFileName in~ ("chrome.exe", "msedge.exe", "firefox.exe")
| where RemoteUrl matches regex @"(?i)(office|login|adp|benefits|verify|secure)[^/]*\.(store|shop|site|info)$"
| extend Campaign = "Behavioral-AiTM-Suspect"
| project TimeGenerated, Campaign, DeviceName, InitiatingProcessFileName,
RemoteUrl, RemoteIP, ActionType
)
| sort by TimeGenerated desc
# Mirage2FA / BlackCore IOC Hunt Script — Security Arsenal
# Checks DNS cache, hosts file, and established connections for known indicators.
# Run elevated on endpoints or via your RMM/EDR remote shell at fleet scale.
$mirage2fa = @(
'galatasaraydanhaberler.com','sopbtech.store','office.pcvgtech.store',
'ver.verpox.shop','cementslabconstruction.com','adp.pslcertlive.site',
'ans.rsxbenefits.com','ari.vslbertlive.info'
)
$blackcore = @(
'blackcore.online','agitanews.net','angola-plan.blackcore.online',
'api.blackcore.online','auth.blackcore.online','ava.blackcore.online',
'demo.blackcore.online','en.blackcore.online'
)
$allIOCs = $mirage2fa + $blackcore
$hits = @()
Write-Host "[*] Checking DNS client cache..." -ForegroundColor Cyan
Get-DnsClientCache -ErrorAction SilentlyContinue | ForEach-Object {
foreach ($ioc in $allIOCs) {
if ($_.Entry -like "*$ioc*") {
$hits += [PSCustomObject]@{Source='DNSCache'; Indicator=$ioc; Detail=$_.Entry; Data=$_.Data}
}
}
}
Write-Host "[*] Checking hosts file for tampering..." -ForegroundColor Cyan
$hostsPath = "$env:SystemRoot\System32\drivers\etc\hosts"
if (Test-Path $hostsPath) {
$hostsContent = Get-Content $hostsPath -ErrorAction SilentlyContinue
foreach ($ioc in $allIOCs) {
$match = $hostsContent | Select-String -Pattern ([regex]::Escape($ioc))
if ($match) { $hits += [PSCustomObject]@{Source='HostsFile'; Indicator=$ioc; Detail=$match.Line; Data=''} }
}
}
Write-Host "[*] Checking active network connections to suspicious TLDs..." -ForegroundColor Cyan
Get-NetTCPConnection -State Established -ErrorAction SilentlyContinue | ForEach-Object {
$conn = $_
try {
$resolved = ([System.Net.Dns]::GetHostEntry($conn.RemoteAddress)).HostName
foreach ($ioc in $allIOCs) {
if ($resolved -like "*$ioc*") {
$proc = (Get-Process -Id $conn.OwningProcess -ErrorAction SilentlyContinue).ProcessName
$hits += [PSCustomObject]@{Source='NetConnection'; Indicator=$ioc; Detail=$resolved; Data="$proc -> $($conn.RemoteAddress):$($conn.RemotePort)"}
}
}
} catch {}
}
Write-Host "[*] Checking for suspicious inbox-rule staging artifacts (recent OST/profile changes)..." -ForegroundColor Cyan
# AiTM compromise often precedes BEC; flag recently created Outlook rules via registry
$rulesKey = "HKCU:\Software\Microsoft\Office\16.0\Outlook\Profiles"
if (Test-Path $rulesKey) {
Write-Host " [i] Outlook profile present — recommend mailbox audit via Graph API for new inbox rules and MFA method changes."
}
if ($hits.Count -gt 0) {
Write-Host "`n[!] INDICATORS FOUND:" -ForegroundColor Red
$hits | Format-Table -AutoSize
$hits | Export-Csv -Path ".\ioc_hunt_$(Get-Date -Format 'yyyyMMdd_HHmmss').csv" -NoTypeInformation
} else {
Write-Host "`n[+] No indicators found on this host." -ForegroundColor Green
}
Response Priorities
Immediate (0–4 hours)
- Block all Mirage2FA and BlackCore domains/hostnames at DNS resolver (RPZ), secure web gateway, and EDR network protection layers — hostname-level, not just registrable domain.
- Execute the KQL hunt across 90 days of telemetry; any hit on Mirage2FA infrastructure is a presumed credential/session compromise until proven otherwise.
- Alert on any browser process establishing WebSocket connections to domains on
.store,.shop,.site,.infoTLDs with office/login/adp/benefits-themed labels.
24 Hours (Identity Response — Mandatory for Any Hit)
- Revoke all active sessions and refresh tokens for any user whose device resolved Mirage2FA infrastructure — password resets alone are insufficient against stolen session cookies (T1539).
- Audit Entra ID sign-in logs for anomalous session reuse: impossible travel, token replay from unfamiliar ASN/ISP, and
OfficeHome/Office365Shell WCSS-Clientuser agents inconsistent with the user's baseline. - Audit for attacker-registered MFA methods, new inbox rules, and OAuth consent grants in the affected window — the standard post-AiTM BEC staging trifecta.
- If your organization operates in Government or Media: brief comms and public affairs teams on BlackCore-style influence operations; flag coordinated engagement anomalies on official social channels to platform trust & safety teams.
1 Week (Architecture Hardening)
- Deploy phishing-resistant MFA (FIDO2/passkeys, certificate-based auth) for all users, prioritizing Finance, HR/payroll, and executives — Mirage2FA's ADP/benefits lures specifically target payroll-adjacent staff. This is the only control that structurally defeats AiTM relay.
- Enable conditional access token protection (token binding) where licensing permits; stolen cookies become non-replayable outside the originating device.
- Block or sandbox-detonate HTML attachments at the email gateway; deploy browser isolation for uncategorized domains to neutralize HTML smuggling delivery.
- Implement CT-log monitoring for lookalike domain patterns matching the
*certlive.*/*bertlive.*/office.*conventions to catch Mirage2FA domain rotation pre-pulse.
Related Resources
Security Arsenal Incident Response Managed SOC & MDR Services AlertMonitor Threat Detection From The Dark Side Intel Hub
Is your security operations ready?
Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.