Back Infosecurity-Magazine BigBear 2 PhaaS Campaign Steals 5000+ Microsoft Credentials
Security researchers have uncovered a new phishing-as-a-service (PhaaS) operation which they claim has already exfiltrated more than 5100 Microsoft 365 credential records from victims.
Bigbear 2.0 is based on adversary-in-the-middle framework Evilginx2, according to CloudSEK.
The research outfit managed to gain admin access to the BigBear 2.0 threat actor panel, enabling it to observe 3331 unique victim IPs across more than 40 countries.
“The panel was observed managing 42 VPS nodes over the campaign lifecycle – primarily hosted by The Constant Company LLC (Vultr) – configured with the ‘offy’ phishlet targeting Microsoft 365 exclusively,” wrote CloudSEK researcher Gagan Aggarwal.
“The operator, using the alias ‘General Boss,’ deployed geo-matched residential proxy pools, real-time Telegram exfiltration, and automated cookie replay to bypass MFA and maintain persistent access.”
In total, the CloudSEK team found 5137 credential records exposed across 461 organizations, including 4148 session cookies, 1032 plaintext passwords and 474 completed MFA-bypassed authentications.
The most-targeted countries were India, France, Saudi Arabia, New Zealand and Germany.
The report revealed at least five affiliates using the service, receiving stolen credentials through dedicated Telegram bots.
The platform itself uses automation to improve the end-user experience: stolen information from phishing pages is fed through to Telegram and into a cookie-replay system, enabling attackers to rapidly perform session hijacking.
Wider Compromise Possible
Most concerning is the fact that IT service and managed service providers were the most targeted organizations by sector.
“IT service providers are high-value targets because they manage client infrastructure – a single IT provider compromise can enable supply chain attacks against dozens of downstream clients,” Aggarwal warned. “IT staff also often have privileged access to Azure AD, on-prem AD, RMM tools and password managers.”
With session cookies in hand, threat actors could theoretically access email, Teams, SharePoint, OneDrive, Entra ID and connected SaaS applications.
This kind of access provides a useful foundation for business email compromise (BEC), financial fraud, phishing, data theft, and compromise of additional enterprise systems, Aggarwal claimed .
CloudSEK recommended that potentially impacted organizations:
Revoke suspicious session and refresh tokens
Force re-authentication
Reset compromised passwords
Adopt phishing-resistant authentication such as FIDO2 or WebAuthn
Strengthen conditional access policies and compliant-device requirements
UK Police Lead Disruption of £1m Phishing-as-a-Service Site LabHost News 18 April 2024
UK Police Lead Disruption of £1m Phishing-as-a-Service Site LabHost
Microsoft Warns of Adversary-in-the-Middle Uptick on Phishing Platforms News 29 August 2023
Microsoft Warns of Adversary-in-the-Middle Uptick on Phishing Platforms
FBI Publishes 42,000 LabHost Phishing Domains News 1 May 2025
FBI Publishes 42,000 LabHost Phishing Domains
Crafting Scams with AI: a Devastating New Vector Blog 29 March 2023
Crafting Scams with AI: a Devastating New Vector
Interpol Dismantles SniperDz Phishing-as-a-Service Platform News 11 June 2026
Interpol Dismantles SniperDz Phishing-as-a-Service Platform
What’s Hot on Infosecurity Magazine?
Researcher Publishes CrowdStrike Privilege Escalation Zero Day
Multiple Class Action Lawsuits Filed Against IDScan
North Korea’s Lazarus Operates Through Six Distinct Cyber Clusters
Rhysida Publishes Berlin Government Data After €2m Extortion Demand Refused
FulcrumSec Claims Responsibility for Manchester Airport Group Breach
FBI Probes Possible Breach of 153 Million Driver’s Licenses
CREST Onboards First Cohort for AI-Enabled Pentesting Accreditation
Attackers Steal METR API Key and Burn $600,000 in AI Credits
New CREST AI Standards to Deliver AI-Enabled Pentesting Accreditation
65% of Enterprises Have Seen AI Agents Act Out of Scope
Hiring for the AI Era: A New Challenge for CISOs
Gambling Goblin Turns Brazilian Government Sites Into SEO Weapons
Understanding Frontier AI Defense: What Cyber and IT Leads Need to Know
Human Risk in Cybersecurity: Protecting Your Organization Beyond Technology
Same Front Door, New Visitors: Securing Humans and AI Agents at the Browser
Securing M365 Data and Identity Systems Against Modern Adversaries
Behind the Curtain of Microsoft 365 Cybersecurity: Lessons from Overlooked Resilience Gaps
Predicting and Prioritizing Cyber Attacks Using Threat Intelligence
How Faster Cyber-Attacks Are Reshaping Enterprise Cybersecurity Strategies
Researchers Claim First Fully Agentic Ransomware: JadePuffer
AI is Already Powering Cyber-Attacks. Can it Power Cyber Defense?
Google Cloud's New CISO Chris Betz on Integrating AI in Cyber Defenses
How World Cup Password Trends Can Increase Active Directory Risk
New CISA Guide Helps Agencies Adopt SASE For Zero Trust
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
