Passkey-Themed Vishing and BigBear 2.0 PhaaS Bypass Microsoft 365 MFA to Feed Extortion Ecosystem
Three overlapping research efforts — Arctic Wolf's PREY-0058, CloudSEK's infiltration of the BigBear 2.0 phishing-as-a-service panel, and Microsoft's tracking of Storm-3121/Storm-3032 — document Microsoft 365 account takeovers that defeat MFA by stealing…
Reports published September 8–11, 2026 describe two converging Microsoft 365 account-takeover waves that both sidestep MFA by hijacking authenticated sessions rather than breaking cryptography. CloudSEK, having gained admin access in June 2026 to the BigBear 2.0 phishing-as-a-service panel, counted 5,137 stolen credential records across 461 organizations in more than 40 countries — comprising 1,032 plaintext passwords, 4,148 session cookies, and 474 completed MFA-bypassed authentications — tied to 3,331 unique victim IPs. The Evilginx2-based AiTM platform, run under the alias 'General Boss' with the 'offy' phishlet targeting Microsoft 365, was leased to at least five affiliates operating 42 VPS nodes (mostly on Vultr), routed logins through country-matched residential proxies to defeat location-based Conditional Access, used custom code to disable FIDO2/WebAuthn on phishing pages and steer victims toward phishable MFA, and exfiltrated stolen credentials via Telegram in real time. IT services and managed service providers were the most targeted sector (151 of 461 organizations per CSO Online), creating downstream supply-chain risk to client infrastructure and privileged Azure AD access; stolen cookies can be replayed into email, Teams, SharePoint, OneDrive, Entra ID, and federated SSO applications. In parallel, Microsoft Security Research has tracked passkey-themed intrusions since May 2026 attributed to Storm-3121 (feeding ShinyHunters and Falcon extortion operations) and Storm-3032 (the Helix operation descended from BlackFile). Attackers call or text employees' personal phones posing as IT helpdesk staff — exploiting BYOD exposure, per Dark Reading — urging fake passkey, MFA, or SSO updates via domains such as add-passkey[.]com and contoso[.]add-passkey[.]com, sometimes reinforced by Teams messages from compromised accounts. Lures lead to AiTM phishing pages or device-code authentication flows yielding credentials, session tokens, and OAuth tokens for attacker-controlled apps exposing Salesforce, Slack, Dropbox, and other SSO services; compromised sessions reached OfficeHome, SharePoint Online, Outlook Web, and internal applications within minutes. Attackers persist by registering their own phone, authenticator, and software-OTP MFA methods — which survive password resets and token expiry — then enumerate users, SharePoint sites, and OAuth grants via Microsoft Graph before collecting SharePoint, OneDrive, and Exchange Online data deliberately throttled…
- CloudSEK infiltrated the BigBear 2.0 PhaaS panel in June 2026: 5,137 credential records across 461 organizations in 40+ countries, including 1,032 plaintext passwords, 4,148 session cookies, and 474 completed MFA-bypassed authentications,…
- BigBear 2.0 is Evilginx2-based, uses the 'offy' phishlet against Microsoft 365, is operated under the alias 'General Boss', and was leased to at least five affiliates running 42 VPS nodes, mostly on Vultr.
- The kit uses geo-matched residential proxies to defeat location-based Conditional Access, Telegram bots for real-time exfiltration, automated cookie replay, and custom code that disables FIDO2/WebAuthn to push victims toward phishable MFA.
- IT services and managed service providers were the most targeted sector — 151 of the 461 organizations (CSO Online) — raising supply-chain risk to client infrastructure and privileged Azure AD access.
- Microsoft has tracked passkey-themed helpdesk vishing since May 2026, attributed to Storm-3121 (linked to ShinyHunters/Falcon) and Storm-3032 (Helix extortion operation descended from BlackFile); lure domains include add-passkey[.]com and…
- AiTM pages and device-code authentication flows yield credentials, session tokens, and OAuth tokens for attacker-controlled apps, exposing Salesforce, Slack, Dropbox and other SSO services; compromised sessions accessed OfficeHome,…
- Persistence comes from attacker-registered phone, authenticator, and software-OTP MFA methods that survive password resets and token expiry; Microsoft Graph is used for tenant reconnaissance.
- Data collection from SharePoint, OneDrive, and Exchange Online is deliberately throttled below 1,000 files or messages per hour to evade detection, with the python-httpx user agent seen in high-volume access.
Coverage timelineoldest first · each row is one article
- · 9d agoBigBear Microsoft 365 phishing service bypassed MFA at 258 organizations
DataBreaches.net· 52
The BigBear 2.0 phishing-as-a-service framework bypassed MFA to steal 5,000+ Microsoft 365 credentials across 258 organizations, CloudSEK researchers found.