BigBear 2.0 Phishing Service Bypasses MFA at 258 Organizations, Steals Over 5,000 Microsoft 365 Credentials

A sophisticated phishing-as-a-service (PhaaS) framework, dubbed BigBear 2.0, has achieved a significant breach, successfully circumventing multi-factor authentication (MFA) at 258 organizations and compromising over 5,000 Microsoft 365 credentials. This alarming development, uncovered by cybersecurity researchers at CloudSEK, highlights a critical vulnerability in common security protocols and the evolving tactics of cyber adversaries. The BigBear 2.0 service, operating through a network of compromised infrastructure, has demonstrated a disturbing proficiency in hijacking authenticated user sessions, thereby gaining access to sensitive corporate data and resources.

The Anatomy of the BigBear 2.0 Attack

Researchers at CloudSEK gained unauthorized access to the control panel of the BigBear 2.0 service, revealing its extensive operational capabilities. The analysis showed the framework managed 42 distinct Virtual Private Server (VPS) nodes, all meticulously configured to target Microsoft 365, a widely adopted suite of cloud-based productivity and identity services. These services include Exchange Online for email, Teams for communication, SharePoint and OneDrive for collaboration and file storage, and Entra ID (formerly Azure Active Directory) for authentication.

At the core of BigBear 2.0’s modus operandi is its utilization of an adversary-in-the-middle (AiTM) framework, specifically an adaptation of Evilginx2. This technique allows attackers to position themselves between the victim and the legitimate Microsoft 365 authentication servers. When a user attempts to log in, the phishing service intercepts their credentials, including the one-time codes or biometric prompts associated with MFA. Crucially, BigBear 2.0 doesn’t merely steal credentials; it captures authenticated session cookies. These cookies act as digital passports, allowing attackers to hijack the user’s active session without needing to re-authenticate, even after MFA has been ostensibly satisfied.

The service employs a specific configuration, referred to as "offy," to establish this man-in-the-middle proxy. This proxy effectively tricks the victim into interacting with a fraudulent authentication page that mirrors the legitimate Microsoft 365 login portal. Once the victim enters their username and password, and subsequently completes the MFA challenge, the attacker’s proxy captures both the credentials and the valid session cookie. This cookie is then replayed through an API, enabling the attacker to bypass security checks and gain access to the victim’s account as if they were the legitimate user.

BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations

Scale and Scope of the Compromise

The exfiltration data gathered by CloudSEK paints a stark picture of the campaign’s reach and impact. The control panel revealed a staggering haul of 5,137 credential records. This includes 474 instances where MFA was successfully bypassed, 1,032 plaintext passwords, and 4,148 session cookies. These compromised accounts belong to users across 3,331 unique IP addresses, spanning over 40 countries. At the time of CloudSEK’s reporting, the operation was still actively engaged in further attacks.

While a broader targeting dataset identified 461 organizations potentially subjected to BigBear 2.0’s efforts, CloudSEK’s detailed analysis confirmed that 258 distinct organizations suffered at least one completed MFA-bypass compromise. This indicates a highly effective and targeted campaign against entities utilizing Microsoft 365.

Advanced Evasion Techniques

BigBear 2.0 employs several advanced techniques to enhance its success rate and evade detection. To bypass the increasingly robust FIDO2/WebAuthn authentication methods, the platform injects custom JavaScript into the phishing pages. This malicious script interferes with the browser’s functionality, effectively disabling the browser-based prompts for FIDO2/WebAuthn, thereby coercing victims into resorting to weaker authentication methods like passwords and SMS-based MFA, which are more susceptible to phishing.

Furthermore, the service leverages geo-matched residential proxies to mask its malicious traffic. By utilizing IP addresses that correspond to the victim’s geographical location and are associated with legitimate residential internet connections, BigBear 2.0 makes it significantly harder for Microsoft’s authentication servers to flag the suspicious activity. This sophisticated proxying strategy helps the phishing infrastructure blend seamlessly with normal network traffic, reducing the likelihood of immediate detection. The control panel itself provides options for configuring these proxies, further illustrating the service’s user-friendly approach for its operators.

The Phishing-as-a-Service Model

The "Phishing-as-a-Service" (PhaaS) model underpinning BigBear 2.0 is a critical factor in its widespread impact. The multi-user panel is leased to multiple affiliate operators, identified by CloudSEK through live Telegram exfiltration bots. These bots receive stolen credentials in real-time, indicating a well-oiled criminal enterprise where stolen data is immediately monetized or exploited. This model democratizes sophisticated cybercrime, allowing individuals with limited technical expertise to launch large-scale, effective phishing campaigns.

BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations

Background and Chronology of the Campaign

The emergence of BigBear 2.0 builds upon a history of sophisticated phishing operations. Evilginx2, the underlying AiTM framework, has been in circulation for several years, continuously evolving to counter security measures. CloudSEK’s analysis of the BigBear 2.0 campaign, as depicted in their provided timeline, suggests a sustained period of activity. While the exact commencement date of this specific BigBear 2.0 iteration remains under investigation, the operational infrastructure’s recent offline status, lasting nearly three weeks at the time of reporting, implies a significant, albeit potentially temporary, disruption. The fact that the administration panel remained online while the phishing infrastructure was down suggests that the service operators may be migrating or rebuilding their attack infrastructure.

The broader context of this attack lies within the escalating threat landscape targeting cloud services. As organizations increasingly rely on platforms like Microsoft 365 for critical operations, these services become prime targets for cybercriminals seeking to gain access to valuable data and maintain persistent footholds within corporate networks. The bypass of MFA, long considered a cornerstone of modern security, signals a dangerous advancement in attacker capabilities.

Implications for Organizations and Users

The success of BigBear 2.0 in bypassing MFA has profound implications for cybersecurity strategies. It underscores that no security measure is infallible and that a layered approach is essential. Compromising an authenticated Microsoft 365 session can lead to severe consequences, including the exposure of sensitive emails, confidential files stored on OneDrive and SharePoint, and potentially access to other integrated applications through single sign-on. For organizations, this can translate to data breaches, financial losses, reputational damage, and regulatory penalties.

For individual users, the compromise of their accounts can lead to identity theft, financial fraud, and the misuse of their professional or personal communications. The ease with which session cookies can be hijacked means that even after a successful MFA prompt, an attacker can maintain access for an extended period, making detection and remediation more challenging.

Official Responses and Recommendations

CloudSEK has taken proactive steps by notifying law enforcement agencies and several of the affected organizations. They have also included the compromised credentials in responsible-disclosure reports, a standard practice in the cybersecurity community to allow for remediation before widespread public disclosure.

BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations

In response to such sophisticated attacks, cybersecurity experts recommend several critical actions for organizations:

  • Password Resets and Session Revocation: Immediately reset all passwords for accounts that may have been exposed. Additionally, revoke all active sessions and refresh authentication tokens to force users to re-authenticate.
  • Enforce Phishing-Resistant MFA: Prioritize the adoption of phishing-resistant MFA methods, such as FIDO2/WebAuthn security keys, over less secure options like SMS-based codes.
  • Implement Conditional Access Policies: Leverage Microsoft Entra ID’s Conditional Access policies to enforce stricter access controls. Requiring managed devices for access and implementing real-time risk detection can significantly bolster security.
  • User Education and Awareness: Continuous training and awareness programs for employees are crucial to help them recognize and report phishing attempts.
  • Security Monitoring and Threat Intelligence: Maintain robust security monitoring capabilities to detect anomalous login activity and unusual data access patterns. Subscribing to threat intelligence feeds can provide early warnings of emerging threats.

The Ongoing Battle

Despite the recent disruption to its phishing infrastructure, the BigBear 2.0 administration panel reportedly remained online at the time of CloudSEK’s report, indicating the resilience and adaptability of these cybercriminal operations. The continuous evolution of phishing techniques, particularly those targeting MFA, necessitates a constant vigilance and an adaptive security posture. The BigBear 2.0 campaign serves as a potent reminder that the digital battleground is constantly shifting, and staying ahead of threats requires ongoing innovation in both offensive and defensive cybersecurity strategies. The data from the "Blue Report 2026" further emphasizes this, indicating that once attackers gain valid credentials, the effectiveness of security defenses drops significantly, highlighting the critical importance of preventing initial access and robust post-compromise containment.

Related Posts

CenterPoint Energy Confirms Customer Data Stolen in Cyberattack

CenterPoint Energy has confirmed a significant data breach, acknowledging that a portion of its customers’ personal information was accessed by an unauthorized third party. The disclosure follows a public announcement…

VMware vCenter Vulnerability Now Actively Exploited by Ransomware Gangs, CISA Warns

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a grave alert, confirming that sophisticated ransomware operations are now actively exploiting a critical vulnerability within VMware’s vCenter Server, a…

Leave a Reply

Your email address will not be published. Required fields are marked *

You Missed

TikTok User Mila Detained by ICE During Green Card Interview in San Diego, Sparking Widespread Debate Over Immigration Enforcement Practices

TikTok User Mila Detained by ICE During Green Card Interview in San Diego, Sparking Widespread Debate Over Immigration Enforcement Practices

The Expanse Osiris Reborn Hands-On Preview: Owlcat Games Translates Hard Sci-Fi RPG Pedigree into Third-Person Action

  • By admin
  • September 15, 2026
  • 2 views
The Expanse Osiris Reborn Hands-On Preview: Owlcat Games Translates Hard Sci-Fi RPG Pedigree into Third-Person Action

The AI race has grown so frenzied that, by 2035, U.S. data centers are projected to consume more natural gas than Germany and Japan combined.

The AI race has grown so frenzied that, by 2035, U.S. data centers are projected to consume more natural gas than Germany and Japan combined.

Thatch Secures $108 Million in Funding at $1 Billion Valuation, Reshaping Health Benefits for Startups

Thatch Secures $108 Million in Funding at $1 Billion Valuation, Reshaping Health Benefits for Startups

CenterPoint Energy Confirms Customer Data Stolen in Cyberattack

CenterPoint Energy Confirms Customer Data Stolen in Cyberattack

Google’s Latest Pixel Drop Will Keep You More Connected To Your VIPs

Google’s Latest Pixel Drop Will Keep You More Connected To Your VIPs