BigBear Phishing Service Hijacks MFA-Protected Microsoft 365 Accounts at 258 Organizations
Researchers at CloudSEK gain administrator access to the control panel of BigBear 2.0, a phishing-as-a-service framework that bypasses multi-factor authentication and steals Microsoft 365 credentials at scale. The investigation reveals that the service manages 42 VPS nodes, all configured to target Microsoft 365 environments, and operates across more than 40 countries while remaining active.
BigBear relies on an Evilginx2-based adversary-in-the-middle framework that places a proxy between victims and Microsoft's legitimate authentication infrastructure. This setup allows attackers to intercept passwords, MFA tokens, and authenticated session cookies, which they replay through an API to hijack accounts even after victims complete the full MFA process. The panel has exfiltrated 5,137 credential records, including 474 complete MFA-bypassed authentications, 1,032 plaintext passwords, and 4,148 session cookies from 3,331 unique victim IPs.
CloudSEK identifies at least five affiliate operators who lease the multi-user panel and receive stolen credentials in real time through live Telegram exfiltration bots. While 461 organizations appear in the broader targeting dataset, 258 distinct organizations suffer at least one completed MFA-bypass compromise. The researchers also find that BigBear deploys custom JavaScript that interferes with FIDO2/WebAuthn authentication, disabling browser functionality to push victims toward weaker authentication methods.