A phishing-as-a-service platform known as BigBear 2.0 has successfully circumvented multi-factor authentication (MFA) for 258 organizations, resulting in the theft of over 5,000 Microsoft 365 credentials.
Researchers from the cybersecurity firm CloudSEK gained administrative access to the control panel and discovered that the service operated 42 VPS nodes, all specifically configured to target Microsoft 365 during the observed activities.
The researchers noted that the campaign employs an Evilginx2-based adversary-in-the-middle framework to capture passwords and authenticated session cookies, enabling attackers to take over accounts after victims have completed the MFA process.
BigBear utilizes a configuration referred to as “offy,” which establishes a man-in-the-middle (AiTM) proxy between the victim and Microsoft’s legitimate authentication system.
This setup allows the attacker to collect credentials, including MFA and session cookies, and replay them via an API to seize the victim’s authentication session.
Microsoft 365 represents Microsoft’s cloud productivity and identity ecosystem, encompassing services like Exchange Online, Teams, SharePoint, OneDrive, and Entra ID authentication.
Gaining access to an authenticated Microsoft 365 session can lead to exposure of emails and files, while also potentially granting access to other applications linked through single sign-on.
According to CloudSEK, BigBear has proven to be highly effective, compromising hundreds of entities and capturing thousands of cookies.
“The panel has exfiltrated 5,137 credential records – including 474 complete MFA-bypassed authentications, 1,032 plaintext passwords, and 4,148 session cookies – impacting 3,331 unique victim IPs across over 40 countries, with the operation still active at the time of this report,” CloudSEK stated in a document shared with BleepingComputer.
“The multi-user PhaaS panel is leased to at least five affiliate operators identified through active Telegram exfiltration bots, each receiving stolen credentials in real time.”
While 461 organizations were included in the broader targeting dataset, CloudSEK clarified that 258 distinct organizations experienced at least one successful MFA-bypass compromise.
CloudSEK also discovered that BigBear employs custom JavaScript that disrupts FIDO2/WebAuthn authentication, disabling the browser features that support it, thereby pushing targets towards less secure authentication methods.
To enhance its effectiveness, the platform utilizes geo-matched residential proxies across 69 countries, aligning the victim’s location with a residential IP address to prevent Microsoft’s authentication servers from flagging the activity as suspicious.
CloudSEK reported that it has informed law enforcement and several impacted organizations, including credentials in responsible-disclosure reports.
As of the time of this writing, the administration panel remains operational, while the phishing infrastructure has been inactive for nearly three weeks.
Organizations that may have been affected by BigBear’s activities are advised to reset compromised passwords, revoke active sessions, refresh tokens, and enforce re-authentication for high-privileged accounts.
It is also recommended to implement phishing-resistant FIDO2/WebAuthn and utilize Conditional Access policies that mandate managed devices instead of relying solely on geo-location signals.
Once attackers possess valid credentials, only 37% of their actions are blocked.
Overall prevention metrics can obscure what occurs after initial access. Once attackers gain valid credentials, prevention effectiveness declines significantly.
The Blue Report 2026 evaluates defense techniques through 338 million simulations conducted in customer production environments.
Get the report
Source: Original article
