Back to feed

BigBear phishing service bypassed MFA at 258 organizations

2 min
BigBear phishing service bypassed MFA at 258 organizations

This digest was compiled by AI from multiple sources — links to the originals are below.

A phishing-as-a-service framework called BigBear 2.0 bypassed multi-factor authentication at 258 organizations and stole more than 5,000 Microsoft 365 credentials. CloudSEK researchers gained administrator access to the control panel and found 42 VPS nodes targeting Microsoft 365. The operation remains active, with the administration panel still online.

Key Facts

  • BigBear 2.0 exfiltrated 5,137 credential records, including 474 complete MFA-bypassed authentications, 1,032 plaintext passwords, and 4,148 session cookies.
  • The campaign affected 3,331 unique victim IPs across more than 40 countries.
  • CloudSEK identified at least five affiliate operators leasing the multi-user phishing panel, each receiving stolen credentials in real time via Telegram bots.
  • BigBear uses custom JavaScript to interfere with FIDO2/WebAuthn authentication, forcing targets toward weaker authentication methods.
  • The platform uses geo-matched residential proxies for 69 countries to avoid triggering Microsoft's suspicious activity flags.

BigBear Phishing Infrastructure

BigBear 2.0 is an Evilginx2-based adversary-in-the-middle framework that intercepts passwords and authenticated session cookies. The service managed 42 VPS nodes, all configured to target Microsoft 365. A configuration called "offy" sets up a man-in-the-middle proxy between the victim and Microsoft's legitimate authentication infrastructure. This allows attackers to capture credentials, including MFA, and session cookies, then replay them through an API to hijack the victim's authentication session.

Campaign Impact

CloudSEK found that 258 distinct organizations had at least one completed MFA-bypass compromise, out of 461 organizations in the broader targeting dataset. Compromising an authenticated Microsoft 365 session can expose email and files while potentially providing access to other applications connected through single sign-on. The panel exfiltrated 5,137 credential records, affecting 3,331 unique victim IPs across more than 40 countries. The multi-user phishing panel is leased to at least five affiliate operators identified through live Telegram exfiltration bots.

Evasion Techniques

BigBear uses custom JavaScript that interferes with FIDO2/WebAuthn authentication, disabling browser functionality to force targets toward weaker authentication methods. The platform uses geo-matched residential proxies for 69 countries, matching the victim's location with a residential IP address so Microsoft's authentication servers don't flag the activity as suspicious. CloudSEK notified law enforcement and several affected organizations, including credentials in responsible-disclosure reports. At the time of writing, the administration panel remains online, while the phishing infrastructure has been offline for nearly three weeks.

1 source

Time · lag behind first