ZeroHour
Threat actor

BigBear 2.0

0 mentions in 7 days · 2 in 30 days · 2 total · first seen · last

Timeline

BigBear 2.0 phishing campaign hijacks Microsoft 365 sessions after MFA

CloudSEK uncovered BigBear 2.0, a PhaaS operation that captured 4,148 Microsoft 365 session cookies, hijacking authenticated sessions after MFA via AiTM proxy.

CloudSEK infiltrated the BigBear 2.0 phishing-as-a-service panel in June, finding 5,137 credential records tied to 461 organizations in over 40 countries, including 4,148 captured session cookies and 474 completed post-MFA logins. The operation, built on Evilginx2, uses an attacker-controlled reverse proxy to steal authenticated session cookies and residential proxies to defeat location-based Conditional Access checks, while custom code disables FIDO2/WebAuthn on phishing pages. At least five affiliates operated 42 VPS nodes, with IT services and managed service providers the most targeted sector.

CSO Online · 8d agoPhishing & fraud in the wild1

BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations

The BigBear 2.0 phishing-as-a-service framework bypassed MFA to steal 5,000+ Microsoft 365 credentials across 258 organizations, CloudSEK researchers found.

CloudSEK researchers gained administrator access to the BigBear 2.0 control panel, finding the phishing-as-a-service operation ran 42 VPS nodes all configured to target Microsoft 365. The framework has been used to bypass multi-factor authentication at 258 organizations and harvest more than 5,000 credentials, indicating an active credential-theft campaign against enterprise tenants.

DataBreaches.net · 9d agoPhishing & fraud in the wild1

Appears with

Entities are extracted by the model from each article. Watching an entity keeps it in this browser only (no account); the watchlist page and dashboard alerts use it.