Cloudsek
BigBear 2.0 Phishing Campaign Bypasses MFA for 258 Organizations
Article Content
The BigBear 2.0 phishing-as-a-service framework has been used to bypass multi-factor authentication (MFA) at 258 organizations, stealing over 5,000 Microsoft 365 credentials. Researchers from CloudSEK gained admin access to the control panel, which managed 42 VPS nodes configured to target Microsoft 365. The campaign employs an Evilginx2-based adversary-in-the-middle technique to intercept passwords and session cookies, allowing attackers to hijack accounts post-MFA. The operation has exfiltrated 5,137 credential records, including 474 MFA-bypassed authentications and 4,148 session cookies, affecting 3,331 unique IPs across over 40 countries. The panel is leased to at least five affiliate operators who receive stolen credentials in real time. Custom JavaScript injections disable FIDO2/WebAuthn MFA, forcing victims to use weaker authentication methods. As of now, the phishing infrastructure has been offline for nearly three weeks, but the admin panel remains active.
Key Points: • BigBear 2.0 has bypassed MFA for 258 organizations. • The campaign has exfiltrated over 5,000 Microsoft 365 credentials. • Custom JavaScript injections disable stronger authentication methods.
Ask AI about this cluster
Answers cite the sources they use
Analyzing cluster data...
Referenced clusters
Something went wrong. Please try again.