BigBear Microsoft 365 Phishing Campaign Bypasses MFA at 258 Organizations
A phishing-as-a-service platform named BigBear 2.0 has been utilized to circumvent multi-factor authentication mechanisms across 258 organizations, resulting in the theft of over 5,000 Microsoft 365 credentials.
Discovery of BigBear 2.0 Phishing Campaign
Security researchers from CloudSEK discovered administrator access to the control panel of the BigBear 2.0 operation, which managed 42 virtual private server nodes specifically configured to target Microsoft 365 environments. The campaign leverages an Evilginx2-based adversary-in-the-middle framework to intercept login credentials and authenticated session cookies, enabling attackers to take over user accounts after victims complete the multi-factor authentication process.
Evilginx2 and Offy Configuration
The service employs a configuration known as “offy” to establish a man-in-the-middle proxy between the victim and Microsoft’s authentication infrastructure. This setup allows threat actors to capture credentials, including MFA tokens, and session cookies, which are then replayed via an API to hijack active authentication sessions.
Impact and Scope of the Attack
CloudSEK’s analysis revealed that BigBear successfully compromised hundreds of entities, collecting 5,137 credential records. These included 474 instances of MFA-bypassed authentications, 1,032 plaintext passwords, and 4,148 session cookies. The operation impacted 3,331 unique IP addresses across 40+ countries, with the campaign remaining active at the time of the report.
PhaaS Platform and Affiliate Operators
The PhaaS platform is leased to at least five affiliate operators, identified through live Telegram exfiltration bots that distribute stolen credentials in real time. While 461 organizations appeared in the broader targeting dataset, CloudSEK confirmed that 258 distinct entities experienced at least one completed MFA-bypass incident.
Technical Methods and Evasion Tactics
The platform employs custom JavaScript to interfere with FIDO2/WebAuthn authentication, disabling browser support for these protocols and forcing users to rely on weaker authentication methods. To enhance its effectiveness, BigBear utilizes geo-matched residential proxies across 69 countries, aligning the attacker’s IP address with the victim’s geographic location to avoid detection by Microsoft’s authentication servers.
Response and Mitigation Measures
CloudSEK reported the findings to law enforcement and affected organizations, including detailed credentials in responsible-disclosure reports. At the time of writing, the administration panel remained operational, while the phishing infrastructure had been offline for nearly three weeks. Organizations impacted by BigBear activity are advised to reset compromised passwords, revoke active sessions, refresh authentication tokens, and enforce re-authentication for high-privilege accounts.
Security Recommendations
Security measures should include adopting phishing-resistant FIDO2/WebAuthn protocols and implementing Conditional Access policies that mandate managed devices rather than relying on geo-location signals. Research indicates that only 37% of malicious actions are blocked once attackers gain valid credentials.
Related Articles
- Entra passkey enrollment vishing targets Microsoft 365 users
- AnonyMousKIT PhaaS uses voice AI agents to phish iPhone passcodes
- Phishing service spoofs RingCentral to steal Microsoft 365 accounts
- Police dismantle Kratos phishing platform, arrest developer
- Bluekit phishing kit adopts browser-in-the-middle for login theft
- Account Takeover MFA MFA Bypass Microsoft 365 Phishing Phishing Kit Phishing-as-a-Service Proxy
