A sophisticated Phishing-as-a-Service (PhaS) framework known as BigBear 2.0 has successfully bypassed multi-factor authentication (MFA) at 258 organizations, stealing over 5,000 Microsoft 365 credentials.
- BigBear 2.0 framework breached 258 distinct organizations via MFA bypass.
- Over 5,100 credential records, including session cookies, were exfiltrated.
- Attackers used 'Adversary-in-the-Middle' (AiTM) proxy techniques.
- The operation spanned across 40+ countries using residential proxies.
In a major escalation of cyber threats, a phishing-as-a-service (PhaS) framework dubbed BigBear 2.0 has been identified bypassing multi-factor authentication (MFA) at 258 organizations. Cybersecurity firm CloudSEK uncovered the operation after gaining administrator access to the service's control panel, revealing a massive-scale campaign targeting Microsoft 365 ecosystems.
The campaign utilizes an Evilginx2-based 'Adversary-in-the-Middle' (AiTM) framework. By deploying a configuration known as "offy," the attackers set up a proxy between the victim and Microsoft’s legitimate authentication infrastructure. This allows them to intercept not just passwords, but also authenticated session cookies, enabling them to hijack entire user sessions even after a successful MFA challenge.
Why This Matters
BozokMedia analysis shows that this attack represents a critical shift in the threat landscape. Traditional MFA, which relies on SMS or app-based codes, is increasingly vulnerable to AiTM attacks. Once an attacker captures a session cookie, they effectively become the user, rendering subsequent security checks moot until the session expires or is revoked.
The ability of BigBear to intercept authenticated session cookies means that even the most common forms of MFA are no longer a silver bullet against sophisticated phishing.
The scale of the theft is staggering. CloudSEK reported that the panel exfiltrated 5,137 credential records, which included 474 complete MFA-bypassed authentications and 4,148 session cookies. The operation affected 3,331 unique IP addresses across more than 40 countries. To evade detection, the attackers used geo-matched residential proxies to make their malicious traffic appear as if it originated from the victim's own location.
Historical Background
Phishing has evolved from simple deceptive emails to highly automated 'as-a-service' models. The emergence of PhaaS allows low-level cybercriminals to rent sophisticated tools like BigBear, significantly lowering the barrier to entry for large-scale corporate espionage and data theft.
Frequently Asked Questions
Q1: How can organizations protect themselves from AiTM attacks?
Organizations should implement phishing-resistant MFA, such as FIDO2/WebAuthn security keys, and use Conditional Access policies.
Q2: What should I do if my credentials were leaked?
Immediately reset your passwords, revoke all active sessions, and refresh your authentication tokens.