BigBear 2.0 Phishing-as-a-Service Bypasses MFA, Compromises 258 Organizations
A sophisticated phishing-as-a-service (PhaaS) framework, dubbed **BigBear 2.0**, has been actively used to bypass multi-factor authentication (MFA) and steal over 5,000 **Microsoft 365** credentials from 258 organizations globally. Cybersecurity researchers at **CloudSEK** gained administrative access to the threat actor's control panel, revealing the scale and technical prowess of this ongoing campaign.

The **BigBear 2.0** framework leverages an **Evilginx2**-based adversary-in-the-middle (AiTM) technique, effectively intercepting both passwords and authenticated session cookies. This allows attackers to hijack accounts even after victims successfully complete their multi-factor authentication processes.
### How BigBear Operates
The PhaaS platform employs a configuration known as βoffy,β which establishes an AiTM proxy between the victim and **Microsoft**βs legitimate authentication infrastructure. This strategic positioning enables the capture of credentials, including MFA tokens, and session cookies. These stolen artifacts are then replayed via an API to hijack the victim's authentication session, granting attackers illicit access to **Microsoft 365** services.
**CloudSEK**βs investigation revealed that the service managed 42 Virtual Private Server (VPS) nodes, all specifically configured to target **Microsoft 365** environments.

**Campaign timeline**
*Source: CloudSEK*
### Widespread Compromises
**Microsoft 365** encompasses a broad ecosystem of cloud productivity and identity services, including **Exchange Online**, **Teams**, **SharePoint**, **OneDrive**, and **Entra ID** authentication. A compromise of an authenticated **Microsoft 365** session can expose sensitive emails and files, and potentially provide access to other applications linked through single sign-on.
According to **CloudSEK**'s report, the **BigBear 2.0** operation has proven highly effective:
"The panel has exfiltrated 5,137 credential records - including 474 complete MFA-bypassed authentications, 1,032 plaintext passwords, and 4,148 session cookies - affecting 3,331 unique victim IPs across 40+ countries with the operation still active at the time of writing," **CloudSEK** stated in its report.
The researchers clarified that while 461 organizations appeared in the broader targeting dataset, 258 distinct organizations experienced at least one completed MFA-bypass compromise.
### Advanced Evasion Techniques
**BigBear 2.0** incorporates several advanced features to enhance its success rate and evade detection:
* **FIDO2/WebAuthn Interference:** The platform uses custom JavaScript to interfere with **FIDO2/WebAuthn** authentication, disabling browser functionality to force targets towards less robust authentication methods.
* **Geo-Matched Residential Proxies:** To avoid flagging by **Microsoft**βs authentication servers, **BigBear** utilizes geo-matched residential proxies across 69 countries. This tactic ensures that the attacker's IP address aligns with the victimβs location, making the activity appear legitimate.

**Configuring proxying in the BigBear panel**
*Source: CloudSEK*
### Mitigation and Response
**CloudSEK** has notified law enforcement agencies and several affected organizations, providing responsible-disclosure reports with compromised credentials. While the administration panel for **BigBear** remains online, its phishing infrastructure has been offline for approximately three weeks at the time of reporting.
Organizations potentially affected by **BigBear** activity are strongly advised to:
* Reset all exposed passwords.
* Revoke active sessions and refresh tokens.
* Force re-authentication for all high-privileged accounts.
* Enforce phishing-resistant **FIDO2/WebAuthn** authentication.
* Implement Conditional Access policies that require managed devices, rather than solely relying on geo-location signals for security decisions.
This incident underscores the critical need for robust security postures that go beyond traditional MFA, especially in the face of evolving AiTM phishing tactics.