Microsoft 365 hit by twin session-hijacking campaigns: BigBear 2.0 PhaaS steals 5,137 credentials, while Storm-3121/Storm-3032 run passkey-themed vishing
Two concurrent threat campaigns target Microsoft 365 authentication: CloudSEK infiltrated the BigBear 2.0 Evilginx2-based phishing-as-a-service operation, which stole 5,137 credential records from 461 organizations across 40+ countries, and Microsoft is…
Reports cover two distinct but related Microsoft 365 threats. First, BigBear 2.0: CloudSEK (The Register writes 'CloudSEC,' a naming discrepancy) gained admin access in June 2026 to a phishing-as-a-service panel built on Evilginx2 and operated under the alias 'General Boss,' using the 'offy' phishlet to proxy Microsoft sign-in pages. The panel contained 5,137 credential records tied to 461 organizations in over 40 countries: 4,148 session cookies, 1,032 plaintext passwords, and 474 completed MFA-bypassed authentications, linked to 3,331 unique victim IPs. The kit was leased to at least five affiliates running 42 VPS nodes (mostly on Vultr), used residential proxies matched to victims' countries (The Register describes a proxy pool spanning 69 countries) to defeat location-based Conditional Access, and custom JavaScript disabled FIDO2/WebAuthn on phishing pages to steer victims toward phishable MFA. IT services and managed service providers were the most targeted sector (151 of 461 organizations), creating downstream supply-chain risk; stolen cookies were replayed into email, Teams, SharePoint, OneDrive, and connected SSO apps, with potential pivot into Entra ID. Credentials were delivered in real time via Telegram bots. Second, Microsoft Security Research has tracked passkey/MFA/SSO-themed social engineering since May 2026, attributed to Storm-3121 (linked to ShinyHunters/Falcon) and Storm-3032 (tied to BlackFile members now operating as Helix); Google Threat Intelligence tracks related activity as UNC6671, linked to BlackFile, Helix, Falcon, Pink, and Redact extortion gangs. Attackers call or text employees' personal phones impersonating IT helpdesk staff, directing them to lure domains such as add-passkey[.]com, contoso[.]add-passkey[.]com, passkeyhelpdesk.com, and setupmypasskey.com, leading to adversary-in-the-middle phishing or device-code authentication flows that yield credentials, session tokens, and OAuth tokens even when MFA succeeds. Post-compromise, attackers register their own MFA methods for persistence, enumerate tenants via Microsoft Graph, and collect SharePoint, OneDrive, and Exchange Online data throttled below 1,000 files or messages per hour, with the python-httpx user agent observed in high-volume access; device-code phishing also exposes OAuth-connected SaaS apps like Salesforce, Slack, and Dropbox. Recommendations across both campaigns converge on phishing-resistant FIDO2/WebAuthn authentication, session and token revocation (not…
- BigBear 2.0 is an Evilginx2-based adversary-in-the-middle PhaaS using the 'offy' phishlet against Microsoft 365, operated under the alias 'General Boss'; CloudSEK gained admin access to its panel in June 2026 (The Register calls the firm…
- The panel held 5,137 credential records across 461 organizations in 40+ countries, comprising 4,148 session cookies, 1,032 plaintext passwords, 474 completed MFA-bypassed authentications, and 3,331 unique victim IPs.
- At least five affiliates operated 42 VPS nodes, mostly on Vultr; custom JavaScript disabled FIDO2/WebAuthn on phishing pages, and geo-matched residential proxies (a pool spanning 69 countries per The Register) defeated location-based…
- IT services and MSPs were the most targeted sector (151 of 461 organizations), raising supply-chain risk via client infrastructure and privileged Azure AD access; stolen sessions enabled replay into email, Teams, SharePoint, OneDrive, and…
- Stolen credentials were delivered to affiliates in real time via Telegram bots; defenders are urged to revoke sessions and tokens, not just reset passwords, and adopt FIDO2/WebAuthn passkeys.
- Microsoft has tracked passkey/MFA/SSO-themed vishing since May 2026, attributed to Storm-3121 (feeding ShinyHunters and Falcon extortion operations) and Storm-3032 (BlackFile members now operating as Helix); Google Threat Intelligence…
- Attackers impersonate IT helpdesk staff on calls, SMS, and Teams messages from compromised accounts, luring victims to domains including add-passkey[.]com, contoso[.]add-passkey[.]com, passkeyhelpdesk.com, and setupmypasskey.com.
- AiTM phishing and device-code authentication flows capture credentials, session tokens, and OAuth tokens despite MFA; device-code phishing exposes OAuth-connected SaaS apps including Salesforce, Slack, and Dropbox.
Coverage timelineoldest first · each row is one article
- · 8d agoBigBear 2.0 Evilginx2 Phishing Campaign Bypasses Microsoft 365 MFA With Session Cookie Theft
Cyber Security News· 74
CloudSEK identified BigBear 2.0, an Evilginx2-based AiTM phishing operation stealing Microsoft 365 MFA session cookies, hitting 461 organizations across 40-plus countries.