BigBear 2.0 Phishing Campaign Steals 5,000 Microsoft 365 Credentials After Bypassing MFA


microsoft arc stealer
Image credit: Microsoft

BigBear 2.0 phishing campaign operators have compromised 258 organizations and stolen more than 5,000 Microsoft 365 credentials using an adversary-in-the-middle framework that can bypass MFA.

CloudSEK researchers gained administrator access to the phishing-as-a-service platform’s control panel, giving them a detailed look at its infrastructure, victims, and techniques.

Researchers identified 42 VPS nodes configured specifically to target Microsoft 365 accounts. A broader dataset contained 461 targeted organizations, while 258 had suffered at least one completed MFA-bypass compromise. Victims spanned more than 40 countries.

BigBear 2.0 can hijack Microsoft 365 sessions after MFA

BigBear 2.0 uses an Evilginx2-based adversary-in-the-middle, or AiTM, framework. Its “offy” configuration places a malicious proxy between a victim and Microsoft’s legitimate authentication infrastructure.

The proxy can intercept usernames, passwords, MFA authentication data, and authenticated session cookies while the victim signs in.

Attackers can then replay stolen session cookies and take over an already authenticated Microsoft 365 session. This allows them to access accounts even after the legitimate user successfully completes MFA.

A hijacked session can expose services connected to the Microsoft 365 account, including Exchange Online, Teams, SharePoint, OneDrive, and other resources available to the compromised user.

BigBear also targets FIDO2 and WebAuthn authentication

The phishing framework includes custom JavaScript designed to interfere with FIDO2 and WebAuthn authentication.

The code disables browser functionality associated with phishing-resistant authentication, potentially preventing victims from using stronger authentication methods normally capable of stopping conventional credential phishing.

This technique gives attackers another way to weaken the authentication process before attempting to capture credentials or session information.

Residential proxies help BigBear avoid location-based detection

BigBear also uses geo-matched residential proxies covering 69 countries.

The infrastructure allows attackers to make malicious sign-in attempts appear to originate from the same country or region as the targeted user.

Matching the victim’s approximate geographic location can make suspicious authentication activity less likely to trigger security controls that rely heavily on unusual sign-in locations.

CloudSEK notified law enforcement and several affected organizations after investigating the campaign.

Organizations should revoke compromised Microsoft 365 sessions

Organizations that suspect exposure should reset affected passwords, revoke active sessions, refresh authentication tokens, and require high-privilege accounts to authenticate again.

Security teams should also enforce phishing-resistant FIDO2 or WebAuthn authentication and strengthen Conditional Access policies.

Requiring managed or compliant devices can provide stronger protection than relying primarily on geographic signals, especially when attackers can route traffic through residential proxies close to their victims.

In other security news, threat actors are hiding malware inside emails with invisible Unicode characters, while OpenAI admitted AI agents coordinated through a German programming wiki. Google has also confirmed active Chrome zero-day attacks as an emergency fix rolls out.

Via BleepingComputer

More about the topics: malware, Microsoft 365, security

Readers help support Windows Report. We may get a commission if you buy through our links. Tooltip Icon

Read our disclosure page to find out how can you help Windows Report sustain the editorial team. Read more

User forum

0 messages