A phishing-as-a-service operation known as BigBear 2.0 bypassed multi-factor authentication at 258 organisations and stole thousands of Microsoft 365 credentials, according to cybersecurity researchers.
CloudSEK said it gained administrator access to the service’s control panel, which was managing 42 virtual private servers configured to target Microsoft 365 users.
The platform uses an adversary-in-the-middle attack, based on the Evilginx2 framework, to place a proxy between victims and Microsoft’s genuine sign-in infrastructure. This enables attackers to capture passwords, authentication codes and session cookies as users log in.
Stolen session cookies can then be replayed through an application programming interface, allowing criminals to take over an already authenticated account even after the victim has completed multi-factor authentication.
BigBear 2.0 captured thousands of authentication records
CloudSEK said its investigation identified 5,137 exfiltrated credential records, including 474 completed MFA-bypass authentications, 1,032 plaintext passwords and 4,148 session cookies. The records were linked to 3,331 unique victim IP addresses across more than 40 countries.
The researchers said 461 organisations appeared in the wider targeting data, but confirmed that 258 distinct organisations had suffered at least one completed MFA-bypass compromise.
The service was being leased to at least five affiliate operators, who received stolen credentials through Telegram bots in real time, according to CloudSEK.
Microsoft 365 accounts can provide access to email, files and services including Exchange Online, Teams, SharePoint, OneDrive and Entra ID. A hijacked session may also open the door to other applications linked through single sign-on.
BigBear’s “offy” configuration is designed to make the fraudulent sign-in page operate as a proxy to Microsoft’s authentication process. CloudSEK also found custom JavaScript intended to disrupt FIDO2 and WebAuthn security functions, pushing targets towards less resistant authentication methods.
The service used residential proxies matched to victims’ locations in 69 countries, a tactic intended to make suspicious sign-ins less likely to trigger Microsoft’s security checks.
CloudSEK said it had alerted law enforcement and several affected organisations, providing exposed credentials through responsible-disclosure reports. While the phishing infrastructure had been offline for almost three weeks at the time of the investigation, the operation’s administration panel remained accessible.
Organisations that may have been targeted have been advised to reset exposed passwords, revoke active sessions, invalidate tokens and require high-privileged users to authenticate again.
Security teams should also consider enforcing phishing-resistant FIDO2 or WebAuthn authentication and using Conditional Access policies requiring managed devices, rather than relying primarily on location-based signals.
