ZeroHour
Infosecurity Magazinepublished ()ingested Phil Muncaster

BigBear 2 PhaaS Campaign Steals 5000+ Microsoft Credentials

highPhishing & fraud exploited in the wildimportance 70
AI summary · glm-5.3-flash

CloudSEK researchers found the BigBear 2.0 PhaaS kit, built on Evilginx2, has stolen over 5,100 Microsoft 365 credentials across 461 organizations in 40+ countries.

CloudSEK gained admin access to the BigBear 2.0 phishing-as-a-service panel, an Evilginx2-based adversary-in-the-middle platform operated by someone using the alias 'General Boss'. The team observed 3,331 unique victim IPs across more than 40 countries, 42 VPS nodes mostly on Vultr, and 5,137 credential records across 461 organizations, including 4,148 session cookies, 1,032 plaintext passwords, and 474 completed MFA-bypassed authentications. IT and managed service providers were the most targeted sector, raising supply-chain risk since their compromise can expose client infrastructure and privileged Azure AD access.

  • BigBear 2.0 is Evilginx2-based PhaaS using the 'offy' phishlet targeting Microsoft 365.
  • 5,137 credential records stolen across 461 organizations, including 4,148 session cookies.
  • Geo-matched residential proxies, Telegram exfiltration, and automated cookie replay bypass MFA.
  • IT/MSPs most targeted, creating downstream supply-chain attack risk.
  • CloudSEK advises token revocation, password resets, and FIDO2/WebAuthn adoption.
Full article371 words · extracted from infosecurity-magazine.com · click to collapse

Security researchers have uncovered a new phishing-as-a-service (PhaaS) operation which they claim has already exfiltrated more than 5100 Microsoft 365 credential records from victims.

Bigbear 2.0 is based on adversary-in-the-middle framework Evilginx2, according to CloudSEK.

The research outfit managed to gain admin access to the BigBear 2.0 threat actor panel, enabling it to observe 3331 unique victim IPs across more than 40 countries.

“The panel was observed managing 42 VPS nodes over the campaign lifecycle – primarily hosted by The Constant Company LLC (Vultr) – configured with the ‘offy’ phishlet targeting Microsoft 365 exclusively,” wrote CloudSEK researcher Gagan Aggarwal.

“The operator, using the alias ‘General Boss,’ deployed geo-matched residential proxy pools, real-time Telegram exfiltration, and automated cookie replay to bypass MFA and maintain persistent access.”

Read more on PhaaS: MFA Bypass Kits Account for One Million Monthly Messages.

In total, the CloudSEK team found 5137 credential records exposed across 461 organizations, including 4148 session cookies, 1032 plaintext passwords and 474 completed MFA-bypassed authentications.

The most-targeted countries were India, France, Saudi Arabia, New Zealand and Germany.

The report revealed at least five affiliates using the service, receiving stolen credentials through dedicated Telegram bots.

The platform itself uses automation to improve the end-user experience: stolen information from phishing pages is fed through to Telegram and into a cookie-replay system, enabling attackers to rapidly perform session hijacking.

Wider Compromise Possible

Most concerning is the fact that IT service and managed service providers were the most targeted organizations by sector.

“IT service providers are high-value targets because they manage client infrastructure – a single IT provider compromise can enable supply chain attacks against dozens of downstream clients,” Aggarwal warned. “IT staff also often have privileged access to Azure AD, on-prem AD, RMM tools and password managers.”

With session cookies in hand, threat actors could theoretically access email, Teams, SharePoint, OneDrive, Entra ID and connected SaaS applications.

This kind of access provides a useful foundation for business email compromise (BEC), financial fraud, phishing, data theft, and compromise of additional enterprise systems, Aggarwal claimed.

CloudSEK recommended that potentially impacted organizations:

  • Revoke suspicious session and refresh tokens
  • Force re-authentication
  • Reset compromised passwords
  • Adopt phishing-resistant authentication such as FIDO2 or WebAuthn
  • Strengthen conditional access policies and compliant-device requirements

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/bigbear-2-phaas-5000-microsoft/