Skip to content
BigBear 2 PhaaS Campaign Steals 5000+ Microsoft Credentials

BigBear 2 PhaaS Campaign Steals 5000+ Microsoft Credentials

Infosecurity-Magazine September 8, 2026

Security researchers have uncovered a new phishing-as-a-service (PhaaS) operation which they claim has already exfiltrated more than 5100 Microsoft 365 credential records from victims.

Bigbear 2.0 is based on adversary-in-the-middle framework Evilginx2, according to CloudSEK.

The research outfit managed to gain admin access to the BigBear 2.0 threat actor panel, enabling it to observe 3331 unique victim IPs across more than 40 countries.

“The panel was observed managing 42 VPS nodes over the campaign lifecycle – primarily hosted by The Constant Company LLC (Vultr) – configured with the ‘offy’ phishlet targeting Microsoft 365 exclusively,” wrote CloudSEK researcher Gagan Aggarwal.

“The operator, using the alias ‘General Boss,’ deployed geo-matched residential proxy pools, real-time Telegram exfiltration, and automated cookie replay to bypass MFA and maintain persistent access.”

In total, the CloudSEK team found 5137 credential records exposed across 461 organizations, including 4148 session cookies, 1032 plaintext passwords and 474 completed MFA-bypassed authentications.

The most-targeted countries were India, France, Saudi Arabia, New Zealand and Germany.

The report revealed at least five affiliates using the service, receiving stolen credentials through dedicated Telegram bots.

The platform itself uses automation to improve the end-user experience: stolen information from phishing pages is fed through to Telegram and into a cookie-replay system, enabling attackers to rapidly perform session hijacking.

Wider Compromise Possible

Most concerning is the fact that IT service and managed service providers were the most targeted organizations by sector.

“IT service providers are high-value targets because they manage client infrastructure – a single IT provider compromise can enable supply chain attacks against dozens of downstream clients,” Aggarwal warned. “IT staff also often have privileged access to Azure AD, on-prem AD, RMM tools and password managers.”

With session cookies in hand, threat actors could theoretically access email, Teams, SharePoint, OneDrive, Entra ID and connected SaaS applications.

This kind of access provides a useful foundation for business email compromise (BEC), financial fraud, phishing, data theft, and compromise of additional enterprise systems, Aggarwal claimed .

CloudSEK recommended that potentially impacted organizations:

Revoke suspicious session and refresh tokens

Force re-authentication

Reset compromised passwords

Adopt phishing-resistant authentication such as FIDO2 or WebAuthn

Strengthen conditional access policies and compliant-device requirements

UK Police Lead Disruption of £1m Phishing-as-a-Service Site LabHost News 18 April 2024

UK Police Lead Disruption of £1m Phishing-as-a-Service Site LabHost

Microsoft Warns of Adversary-in-the-Middle Uptick on Phishing Platforms News 29 August 2023

Microsoft Warns of Adversary-in-the-Middle Uptick on Phishing Platforms

FBI Publishes 42,000 LabHost Phishing Domains News 1 May 2025

FBI Publishes 42,000 LabHost Phishing Domains

Crafting Scams with AI: a Devastating New Vector Blog 29 March 2023

Crafting Scams with AI: a Devastating New Vector

Interpol Dismantles SniperDz Phishing-as-a-Service Platform News 11 June 2026

Interpol Dismantles SniperDz Phishing-as-a-Service Platform

What’s Hot on Infosecurity Magazine?

Researcher Publishes CrowdStrike Privilege Escalation Zero Day

Multiple Class Action Lawsuits Filed Against IDScan

North Korea’s Lazarus Operates Through Six Distinct Cyber Clusters

Rhysida Publishes Berlin Government Data After €2m Extortion Demand Refused

FulcrumSec Claims Responsibility for Manchester Airport Group Breach

FBI Probes Possible Breach of 153 Million Driver’s Licenses

CREST Onboards First Cohort for AI-Enabled Pentesting Accreditation

Attackers Steal METR API Key and Burn $600,000 in AI Credits

New CREST AI Standards to Deliver AI-Enabled Pentesting Accreditation

65% of Enterprises Have Seen AI Agents Act Out of Scope

Hiring for the AI Era: A New Challenge for CISOs

Gambling Goblin Turns Brazilian Government Sites Into SEO Weapons

Understanding Frontier AI Defense: What Cyber and IT Leads Need to Know

Human Risk in Cybersecurity: Protecting Your Organization Beyond Technology

Same Front Door, New Visitors: Securing Humans and AI Agents at the Browser

Securing M365 Data and Identity Systems Against Modern Adversaries

Behind the Curtain of Microsoft 365 Cybersecurity: Lessons from Overlooked Resilience Gaps

Predicting and Prioritizing Cyber Attacks Using Threat Intelligence

How Faster Cyber-Attacks Are Reshaping Enterprise Cybersecurity Strategies

Researchers Claim First Fully Agentic Ransomware: JadePuffer

AI is Already Powering Cyber-Attacks. Can it Power Cyber Defense?

Google Cloud's New CISO Chris Betz on Integrating AI in Cyber Defenses

How World Cup Password Trends Can Increase Active Directory Risk

New CISA Guide Helps Agencies Adopt SASE For Zero Trust