A sophisticated phishing-as-a-service framework called BigBear 2.0 has been used to compromise the security of 258 organizations and steal over 5,000 Microsoft 365 credentials by bypassing multi-factor authentication (MFA). Researchers at CloudSEK gained access to the control panel of this malicious service and found that it was targeting Microsoft 365 users with a configuration called “offy”, which sets up a man-in-the-middle proxy between victims and Microsoft’s legitimate authentication infrastructure.
This phishing framework, known as Evilginx2-based adversary-in-the-middle (AiTM), intercepts passwords and authenticated session cookies, allowing attackers to hijack accounts even after victims complete the MFA process. BigBear uses geo-matched residential proxies for 69 countries, matching the victim’s location with a residential IP address so that Microsoft’s authentication servers don’t flag the activity as suspicious.
The campaign has captured thousands of cookies and stolen credentials, including 474 complete MFA-bypassed authentications, 1,032 plaintext passwords, and 4,148 session cookies. The panel has exfiltrated these records from hundreds of entities across 40+ countries, with the operation still active at the time of writing. CloudSEK notes that BigBear proved to be sufficiently successful in compromising the security of numerous organizations.
Moreover, researchers found that BigBear uses custom JavaScript to interfere with FIDO2/WebAuthn authentication, disabling browser functionality and forcing targets toward weaker authentication methods. This increases the effectiveness of the phishing platform by making it harder for victims to detect the attack. To make matters worse, once attackers have valid credentials, only 37% of their actions are blocked.
Organizations that were potentially affected by BigBear activity should take immediate action to protect themselves. This includes resetting exposed passwords, revoking active sessions, refreshing tokens, and forcing re-authentication for high-privileged accounts. It’s also advisable to enforce phishing-resistant FIDO2/WebAuthn authentication and use Conditional Access policies that require managed devices rather than relying on geo-location signals.
The incident highlights the ongoing threat of sophisticated phishing campaigns and the importance of maintaining robust security measures. Organizations must remain vigilant in protecting themselves from such attacks, which can compromise sensitive data and applications connected through single sign-on. As CloudSEK continues to monitor BigBear’s activity, it’s essential for affected organizations to take prompt action to mitigate potential damage.
In this case, prevention scores may not accurately reflect the effectiveness of security measures once attackers have gained valid credentials. It’s crucial for organizations to focus on implementing robust security protocols and regularly monitoring their systems for suspicious activity. With the right precautions in place, it’s possible to prevent or limit the impact of such attacks.
Source: Bleeping Computer — 2026-09-07