Microsoft 365 Under Siege on Three Fronts: BigBear 2.0 PhaaS Credential Theft, Storm-Actor Passkey Vishing, and Direct Send Spoofing
Ten reports detail three distinct Microsoft 365 threats: CloudSEK's infiltration of the Evilginx2-based BigBear 2.0 phishing-as-a-service panel (5,137 stolen credentials from 461 organizations), Microsoft's attribution of passkey-themed vishing active since…
This cycle surfaced three separate campaigns targeting Microsoft 365 users. First, CloudSEK (referred to as 'CloudSEC' in one report) gained admin access in June to the BigBear 2.0 phishing-as-a-service panel, an Evilginx2-based adversary-in-the-middle platform operated under the alias 'General Boss' using the 'offy' phishlet against Microsoft 365. The panel held 5,137 credential records across 461 organizations in more than 40 countries, including 4,148 session cookies, 1,032 plaintext passwords, and 474 completed MFA-bypassed authentications, alongside 3,331 unique victim IPs. The operation ran 42 VPS nodes (reported mostly on Vultr) and was leased to at least five affiliates; it used residential proxies to defeat location-based Conditional Access, delivered stolen data in real time via Telegram bots, replayed cookies automatically, and deployed custom code to disable FIDO2/WebAuthn on phishing pages. IT services and managed service providers were the most targeted sector (151 of 461 organizations per CSO Online), raising supply-chain risk since their compromise can expose client infrastructure and privileged Azure AD access. Second, Microsoft Security Research detailed cloud intrusions tracked since May 2026 in which attackers calling or texting employees' personal phones posed as IT helpdesk staff and urged fake passkey, MFA, or SSO updates via domains including add-passkey[.]com, contoso[.]add-passkey[.]com, passkeyhelpdesk.com, and setupmypasskey.com. Lures led to AiTM phishing pages or device-code authentication flows yielding credentials, session tokens, and OAuth tokens; phishable MFA was bypassed rather than the passkey standard itself. Attackers registered their own MFA methods (phone numbers, authenticator apps, software OTP) for persistence surviving resets, enumerated tenants via Microsoft Graph, and collected SharePoint, OneDrive, and Exchange Online data throttled below 1,000 items per hour, with the python-httpx user agent seen in high-volume access and compromised sessions reaching OfficeHome, SharePoint Online, and Outlook Web within minutes. Microsoft attributed the tradecraft to Storm-3121 (linked to ShinyHunters/Falcon) and Storm-3032 (BlackFile members now operating as Helix); Google Threat Intelligence tracks related activity as UNC6671, tied to the BlackFile, Helix, Falcon, Pink, and Redact extortion gangs. Third, KnowBe4 Threat Lab confirmed 29,785 phishing emails sent July–August 2026 abusing Microsoft 365's Direct Send feature…
- BigBear 2.0 is an Evilginx2-based PhaaS platform operated under the alias 'General Boss', using the 'offy' phishlet to target Microsoft 365; CloudSEK infiltrated its admin panel in June (one report, The Register, names the researcher…
- The panel contained 5,137 credential records across 461 organizations in 40+ countries: 4,148 session cookies, 1,032 plaintext passwords, and 474 completed MFA-bypassed authentications, plus 3,331 unique victim IPs.
- Infrastructure: 42 VPS nodes (mostly on Vultr per Infosecurity Magazine) operated by at least five affiliates; residential proxies described as geo-matched to victim countries in two reports and as a pool spanning 69 countries in a third.
- Custom code/JavaScript disables FIDO2/WebAuthn on phishing pages, steering victims to phishable authentication; stolen cookies are replayed automatically and exfiltrated in real time via Telegram bots.
- IT services and managed service providers were the most targeted sector (151 of 461 organizations per CSO Online), creating downstream supply-chain risk including privileged Azure AD/Entra ID and federated SaaS access.
- Microsoft has tracked passkey-themed vishing since May 2026, attributing initial access to Storm-3121 (linked to ShinyHunters/Falcon extortion) and Storm-3032 (BlackFile members now operating as Helix); Google Threat Intelligence tracks…
- Attackers impersonate IT helpdesk staff on calls, texts, and Teams messages from compromised accounts, using passkey/MFA/SSO lures on domains such as add-passkey[.]com, contoso[.]add-passkey[.]com, passkeyhelpdesk.com, and…
- AiTM phishing pages and device-code flows capture credentials, session tokens, and OAuth tokens even when MFA succeeds; device-code phishing exposes SSO apps including Salesforce, Slack, and Dropbox.
Coverage timelineoldest first · each row is one article
- · 9d agoBigBear 2 PhaaS Campaign Steals 5000+ Microsoft Credentials
Infosecurity Magazine· 70
CloudSEK researchers found the BigBear 2.0 PhaaS kit, built on Evilginx2, has stolen over 5,100 Microsoft 365 credentials across 461 organizations in 40+ countries.