BigBear phishing crew nets thousands of Microsoft 365 credentials

A sophisticated phishing-as-a-service operation, dubbed BigBear 2.0, has successfully compromised thousands of Microsoft 365 credentials. Researchers gained access to the attackers' administrative panel, revealing 5,137 stolen records from 461 organizations, including over 1,000 plaintext passwords and more than 4,000 session cookies. Critically, 474 of these records represent complete, MFA-bypassed authenticated sessions, enabling attackers to hijack accounts and gain access to sensitive data within Microsoft 365, potentially extending to cloud infrastructure and federated applications. This operation, based on Evilginx2, employs advanced techniques like JavaScript to disable certain MFA methods and utilizes a global residential proxy pool to evade detection. The motive is believed to be financial, with stolen credentials likely sold on the dark web or used for business email compromise attacks. The ongoing campaign highlights a persistent threat to cloud-based productivity suites and the evolving tactics of cybercriminals.

AI Signal Decode

The BigBear 2.0 operation, leveraging the Evilginx2 framework, has demonstrated significant success in exfiltrating Microsoft 365 credentials. Researchers from CloudSEK observed over 5,000 stolen records, encompassing both passwords and session cookies. The most alarming aspect is the capture of authenticated session cookies, which allow attackers to bypass multi-factor authentication (MFA) by replaying legitimate user sessions. This capability significantly increases the risk of account takeover, granting access to sensitive corporate data stored in services like OneDrive and SharePoint, and potentially serving as a pivot point for further network intrusion.

The technical sophistication of BigBear is notable, with custom JavaScript aimed at disabling FIDO2/WebAuthn authentication and a global residential proxy network designed to mask the origin of phishing attempts. These tactics make detection more challenging for both automated security tools and human analysts. The attackers' ability to conduct adversary-in-the-middle attacks via a proxied login flow, combined with the session hijacking capability, presents a potent threat to organizations relying heavily on Microsoft 365 for their operations. The operation's leasing model to multiple affiliates suggests a scalable and organized criminal enterprise.

The market implications are substantial, as compromised Microsoft 365 accounts can lead to severe business disruption, data breaches, and financial losses. Organizations must prioritize implementing robust security measures, including phishing-resistant authentication methods like FIDO2/WebAuthn, strict conditional access policies, and prompt revocation of compromised sessions. Continuous monitoring for unusual login activity and adherence to security best practices are crucial for mitigating the risks posed by such advanced phishing campaigns. The ongoing nature of BigBear 2.0 underscores the need for vigilance and proactive defense strategies in the current threat landscape.