BigBear phishing crew nets thousands of Microsoft 365 credentials
AI Signal Decode
The BigBear 2.0 operation, leveraging the Evilginx2 framework, has demonstrated significant success in exfiltrating Microsoft 365 credentials. Researchers from CloudSEK observed over 5,000 stolen records, encompassing both passwords and session cookies. The most alarming aspect is the capture of authenticated session cookies, which allow attackers to bypass multi-factor authentication (MFA) by replaying legitimate user sessions. This capability significantly increases the risk of account takeover, granting access to sensitive corporate data stored in services like OneDrive and SharePoint, and potentially serving as a pivot point for further network intrusion.
The technical sophistication of BigBear is notable, with custom JavaScript aimed at disabling FIDO2/WebAuthn authentication and a global residential proxy network designed to mask the origin of phishing attempts. These tactics make detection more challenging for both automated security tools and human analysts. The attackers' ability to conduct adversary-in-the-middle attacks via a proxied login flow, combined with the session hijacking capability, presents a potent threat to organizations relying heavily on Microsoft 365 for their operations. The operation's leasing model to multiple affiliates suggests a scalable and organized criminal enterprise.
The market implications are substantial, as compromised Microsoft 365 accounts can lead to severe business disruption, data breaches, and financial losses. Organizations must prioritize implementing robust security measures, including phishing-resistant authentication methods like FIDO2/WebAuthn, strict conditional access policies, and prompt revocation of compromised sessions. Continuous monitoring for unusual login activity and adherence to security best practices are crucial for mitigating the risks posed by such advanced phishing campaigns. The ongoing nature of BigBear 2.0 underscores the need for vigilance and proactive defense strategies in the current threat landscape.