A phishing-as-a-service platform called BigBear 2.0 has compromised Microsoft 365 accounts at 258 organizations. The operation collected more than 5,000 credential records by intercepting passwords and authenticated session cookies.

CloudSEK researchers gained administrator access to the service’s control panel. Their investigation uncovered 42 virtual private server nodes configured to target Microsoft 365 users.

The BigBear phishing operation remained active when researchers prepared their report. However, its phishing infrastructure had reportedly been offline for nearly three weeks.

BigBear intercepts authenticated sessions

BigBear uses an adversary-in-the-middle framework based on Evilginx2. The platform places a malicious proxy between the victim and Microsoft’s legitimate authentication service.

Victims interact with what appears to be the normal sign-in process. BigBear then relays the information to Microsoft while intercepting login credentials and session cookies.

The victim may successfully complete multi-factor authentication. However, the phishing platform captures the resulting authenticated session cookie.

Attackers can replay that cookie through an API and take control of the session. Therefore, they may access an account without completing the MFA process themselves.

A compromised Microsoft 365 session can expose email messages and cloud files. It may also provide access to applications connected through single sign-on.

Campaign stole thousands of credentials

CloudSEK found 5,137 credential records in the BigBear administration panel. The data included 474 complete authentications that had bypassed MFA protections.

Researchers also identified 1,032 plaintext passwords and 4,148 captured session cookies. The operation affected 3,331 unique victim IP addresses across more than 40 countries.

While the broader targeting data included 461 organizations, CloudSEK confirmed completed MFA-bypass compromises at 258 distinct organizations.

The platform reportedly supports multiple users and provides access to at least five affiliate operators. Telegram bots sent stolen credentials to these affiliates in real time.

This structure allows several criminals to run phishing campaigns through the same infrastructure. As a result, BigBear operates more like a commercial cybercrime service than a single attack campaign.

BigBear weakens phishing-resistant authentication

BigBear uses custom JavaScript to interfere with FIDO2 and WebAuthn authentication. These technologies offer stronger protection against phishing because they verify the legitimate website during sign-in.

The malicious code disables browser functionality needed for these methods. Consequently, victims may have to use a weaker authentication option that the attackers can intercept.

The platform also offers residential proxy connections across 69 countries. It can select an IP address near the victim’s location when replaying a stolen session.

This tactic helps the attacker’s login resemble the victim’s usual activity. It may also reduce the effectiveness of security controls that rely heavily on geographic location.

Organizations urged to revoke sessions

CloudSEK said it notified law enforcement and several affected organizations. The company also shared exposed credentials through responsible disclosure reports.

The BigBear administration panel remained online at the time of reporting. However, researchers said the phishing infrastructure itself had been unavailable for almost three weeks.

Potentially affected organizations should reset exposed passwords and revoke all active sessions. They should also refresh authentication tokens and require privileged users to sign in again.

In addition, security teams should enforce phishing-resistant FIDO2 or WebAuthn authentication. Conditional Access policies should require managed devices instead of relying mainly on location signals.

The BigBear phishing campaign shows that conventional MFA does not always stop account takeovers. Session theft can allow attackers to hijack an already authenticated account without directly defeating the second authentication factor.


0 responses to “BigBear phishing service bypassed MFA at 258 organizations”