ZeroHour
Story · 1 source · 1 articlefirst updated ()1

Microsoft 365 account takeover wave: BigBear 2.0 AiTM phishing panel exposed, passkey-themed vishing feeds extortion gangs, and Direct Send abused in 29,785 spoofed emails

highPhishing & fraudexploited in the wildimportance 78
What's new: First merged summary for this story (no previous summary). New this cycle: (1) September 8 — infiltration of the BigBear 2.0 PhaaS panel revealed scale of AiTM session-cookie theft against Microsoft 365 (4,148 cookies, 461 organizations, 474 MFA-bypassed logins); (2) September 10–11 — Microsoft detailed passkey-themed vishing and device-code phishing by Storm-3121/Storm-3032 active since May…
Merged summary · glm-5.3 · rewritten as coverage arrives

Three concurrent Microsoft 365 attack campaigns surfaced this week: CloudSEK infiltrated the BigBear 2.0 phishing-as-a-service panel (5,137 stolen records across 461 organizations, including 4,148 session cookies and 474 MFA-bypassed logins); Microsoft…

Three distinct but related Microsoft 365 attack campaigns were reported between September 8 and 11, 2026. First, researchers (reported as CloudSEK by CSO Online and CloudSEC by The Register — sources disagree on the name) infiltrated the admin panel of BigBear 2.0, an Evilginx2-based phishing-as-a-service operation run by an actor known as 'General Boss'. The panel held 5,137 credential records tied to 461 organizations in more than 40 countries, including 4,148 captured session cookies, 1,032 plaintext passwords, and 474 completed post-MFA logins. The adversary-in-the-middle reverse proxy steals replayable session cookies bypassing MFA without defeating it, uses custom JavaScript to disable FIDO2/WebAuthn on phishing pages, and routes logins through residential proxies spanning 69 countries to defeat location-based Conditional Access. At least five affiliates operated 42 VPS nodes; IT services and MSPs were the most-targeted sector (151 of 461 organizations), and stolen credentials were delivered in real time via Telegram bots. Second, Microsoft Security Research detailed passkey-themed vishing active since May 2026: attackers calling or texting employees' personal phones while posing as IT helpdesk staff urge fake passkey, MFA, or SSO updates via lure domains such as add-passkey[.]com, contoso[.]add-passkey[.]com, passkeyhelpdesk.com, and setupmypasskey.com. Lures lead to AiTM phishing pages or device-code authentication flows yielding credentials, session tokens, and OAuth tokens; attackers then register their own MFA methods for persistence, enumerate tenants via Microsoft Graph, and collect SharePoint, OneDrive, and Exchange Online data at deliberately low rates (below 1,000 files or messages per hour), with the python-httpx user agent observed in high-volume access. Microsoft attributes the tradecraft to Storm-3121 (linked to ShinyHunters/Falcon) and Storm-3032 (BlackFile members now operating as Helix); Google Threat Intelligence tracks related activity as UNC6671, linked to the BlackFile, Helix, Falcon, Pink, and Redact extortion gangs. Third, KnowBe4 Threat Lab observed 29,785 confirmed phishing emails between July and August 2026 abusing Microsoft 365 Direct Send to spoof trusted internal senders (HR, accounting), peaking Monday–Tuesday during US Eastern business hours with near-zero weekend volume; roughly 35% carried malicious attachments and 4,023 used cross-domain reply-to addresses. Recommended defenses across all reports include…

  • BigBear 2.0 PhaaS panel (infiltrated in June): 5,137 Microsoft 365 records across 461 organizations in 40+ countries, including 4,148 session cookies, 1,032 plaintext passwords, and 474 completed post-MFA logins
  • BigBear 2.0 is built on Evilginx2, run by 'General Boss', operated by at least five affiliates across 42 VPS nodes, with a residential proxy pool spanning 69 countries and Telegram-based real-time credential delivery
  • Custom JavaScript disables FIDO2/WebAuthn on BigBear phishing pages, steering victims to phishable authentication; IT services and MSPs account for 151 of the 461 targeted organizations
  • Sources disagree on the researcher name: CSO Online reports CloudSEK, The Register reports CloudSEC
  • Microsoft's passkey-themed campaign has been active since May 2026, attributed to Storm-3121 (linked to ShinyHunters/Falcon) and Storm-3032 (BlackFile members now operating as Helix); Google Threat Intelligence tracks related activity as…
  • Vishing lures via calls/SMS to personal phones and Teams messages from compromised accounts use domains including add-passkey[.]com, contoso[.]add-passkey[.]com, passkeyhelpdesk.com, and setupmypasskey.com, leading to AiTM phishing or…
  • Post-compromise: attacker-registered MFA methods for persistence (surviving password resets and token expiry), Microsoft Graph tenant enumeration, and SharePoint/OneDrive/Exchange Online collection throttled below 1,000 files or emails per…
  • KnowBe4 tracked 29,785 phishing emails abusing Microsoft 365 Direct Send during July–August 2026, spoofing internal senders, bypassing gateways via direct Exchange Online MX connections; ~35% carried malicious attachments and 4,023 used…

Coverage timeline

  1. · 8d ago
    CSO Online· 74
    BigBear 2.0 phishing campaign hijacks Microsoft 365 sessions after MFA

    CloudSEK uncovered BigBear 2.0, a PhaaS operation that captured 4,148 Microsoft 365 session cookies, hijacking authenticated sessions after MFA via AiTM proxy.