BigBear 2.0 Phishing Campaign Bypasses MFA-Protected Microsoft Accounts

www.news4hackers.com-bigbear-2-0-phishing-campaign-bypasses-mfa-protected-microsoft-accounts-bigbear-2-0-phishing-campaign-bypasses-mfa-protected-microsoft-accounts

A phishing-as-a-service (PhaaS) operation named BigBear 2.0 has successfully breached Microsoft 365 accounts for over 3,300 victims, including those secured with multi-factor authentication (MFA), according to findings from CloudSEK.

Discovery of BigBear 2.0

According to findings from CloudSEK. The campaign was detected when researchers from CloudSEK’s Threat Research and Information Analytics Division (TRIAD) gained access to the threat actor’s control panel, exposing details about the BigBear 2.0 phishing toolkit, its targets, and infrastructure.

The operation leverages a phishlet called “offy,” a configuration for the Evilginx2 phishing reverse proxy that integrates three custom JavaScript injections. This phishlet is designed to target Microsoft 365 accounts through adversary-in-the-middle (AiTM) MFA phishing techniques. When a user interacts with a phishing link, login traffic is routed through the attacker’s proxy, capturing credentials and MFA session tokens before relaying them to the genuine Microsoft login portal.

PhaaS Model and Affiliates

CloudSEK’s analysis revealed that BigBear 2.0 operates as a PhaaS model under the alias “General Boss,” with at least five affiliates using Telegram bot tokens to receive stolen data in real time. The researchers identified 5,137 stolen records across all affiliates, including 474 fully authenticated MFA sessions, 1,032 captured passwords, and 4,148 session cookies linked to 3,331 unique IP addresses.

Victims and Impact

The victims spanned 461 organizations across 40 countries, with India as the primary target and IT services and managed service providers as the most affected sector. IT service providers are prioritized due to their access to client infrastructure, which enables supply chain attacks against multiple downstream entities. Additionally, these providers often hold elevated privileges in Azure AD, on-premises AD, remote monitoring tools, and password managers, making them high-value targets.

Infrastructure and Tactics

The campaign utilized 42 virtual private server (VPS) nodes hosted via Vultr’s infrastructure to proxy traffic through residential IP addresses matching the geolocation of victims. Each phishing domain employed valid Let’s Encrypt TLS certificates to terminate connections before establishing a new encrypted link to Microsoft’s login portal. This method bypassed Microsoft’s geolocation anomaly detection, making the login process appear legitimate.

Timeline and Current Status

Threat actors began decommissioning VPS nodes around July 27, likely as a counter-forensic measure after CloudSEK accessed the control panel. However, 14 nodes remained active as of July 30. The campaign, which started in late June, is still operational, with the control panel and all five affiliate Telegram bots active. However, activity declined significantly after mid-July, with no new victims reported after July 29.

Recommendations and Mitigation

CloudSEK advised organizations to revoke suspicious session and refresh tokens, enforce re-authentication, reset compromised passwords, and implement phishing-resistant authentication methods such as FIDO2 and WebAuthn. Strengthening conditional access policies and enforcing device compliance were also recommended to mitigate risks.

The attack highlights the evolving tactics of threat actors, who are increasingly targeting MFA enrollment processes and leveraging infrastructure to evade detection. Security teams are urged to adopt advanced monitoring and adaptive authentication strategies to counter such threats.



About Author

en_USEnglish