BigBear 2.0 PhaaS Steals 5,100+ M365 Logins

Infosecurity Magazine · High sophistication
Last updated September 8, 2026

Researchers say the “BigBear 2.0” phishing-as-a-service operation stole over 5,100 Microsoft 365 credential records across 461 organizations by capturing passwords and session cookies. The campaign used an adversary-in-the-middle setup to bypass MFA and maintain access, with stolen data sent to Telegram bots and used for automated cookie replay. IT service providers and managed service providers were highlighted as the most-targeted sector, increasing supply-chain risk.

Key findings

  • Researchers report BigBear 2.0 exfiltrated “more than 5100 Microsoft 365 credential records from victims.”
  • The operation is described as a phishing-as-a-service (PhaaS) platform built on Evilginx2 (adversary-in-the-middle) to capture credentials and bypass MFA.
  • CloudSEK observed “42 VPS nodes” (primarily hosted at Vultr) configured with an “‘offy’ phishlet targeting Microsoft 365 exclusively.”
  • Stolen data was routed to “dedicated Telegram bots,” and then into “a cookie-replay system,” enabling rapid session hijacking and persistent access.
  • Impact described includes exposure of “4148 session cookies, 1032 plaintext passwords and 474 completed MFA-bypassed authentications.”
  • IT service providers/MSPs were the “most targeted organizations by sector,” raising downstream/supply-chain compromise risk.

Who’s being targeted

  • Commonly targeted roles: IT, Managed Service Provider (MSP) teams, Helpdesk/Service Desk, Microsoft 365/Entra ID administrators, All employees using Microsoft 365.
  • Affected industries: IT services, Managed service providers (MSPs), Any organization using Microsoft 365 / Entra ID.
  • Attack channels: email, website.
  • Impersonated: Microsoft 365 sign-in / organization Microsoft 365 login.

Awareness takeaways

  • Treat unexpected Microsoft 365 sign-in links as high risk; go to Microsoft 365 using a saved bookmark instead of clicking.
  • MFA alone may not stop modern phishing, prioritize phishing-resistant MFA (FIDO2/WebAuthn) for high-risk users like IT/MSPs.
  • If compromise is suspected, respond quickly by revoking sessions/tokens and forcing re-authentication (cookie theft can keep attackers logged in).
  • Give extra training and tighter access controls to IT providers/MSPs because one compromise can cascade to clients.

Red flags to watch for

  • Unexpected sign-in prompt delivered via email/link rather than via the normal Microsoft 365 portal bookmark
  • Lookalike or unfamiliar sign-in URL (AITM phishing infrastructure)
  • MFA prompts that appear when you weren’t actively signing in
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

You get an email: “Action required: Microsoft 365 sign-in needed to continue.” Looks normal, right? Behind that link is BigBear 2.0, a phishing-as-a-service built on Evilginx2. It shows you a perfect Microsoft 365 page, steals your password and session cookie, and then replays it to bypass your MFA. Researchers say BigBear 2.0 already grabbed over 5100 Microsoft 365 credential records, more than 4000 session cookies and hundreds of MFA-bypassed logins, hitting IT and managed service providers hardest, which then puts their clients at risk too. Here’s your move: if you get a Microsoft 365 sign-in link by email, don’t click it, close the email, open your saved Microsoft 365 bookmark, and sign in there instead.

Similar attacks

BigBear 2.0 Steals M365 Sessions to Bypass MFA

BigBear 2.0 Steals M365 Sessions to Bypass MFA

Researchers say the “BigBear 2.0” phishing-as-a-service operation compromised Microsoft 365 accounts by stealing authenticated session cookies after users completed MFA normally. This let attackers replay the session and access accounts without triggering another MFA prompt, impacting 258…

September 8, 2026
BlackFile Crew Vishing Hits PE and Finance Firms

BlackFile Crew Vishing Hits PE and Finance Firms

Google and Reuters report a real vishing-led intrusion campaign tied to the extortion crew behind the retired “BlackFile” brand (tracked as UNC6671). Attackers call employees on personal phones spoofing the corporate IT help desk, push a same-day “passkey/MFA update,” and send them to a look‑alike…

August 12, 2026
Mirage2FA Phishing Kit Steals Microsoft 365 Sessions

Mirage2FA Phishing Kit Steals Microsoft 365 Sessions

A phishing-as-a-service toolkit called Mirage2FA has been targeting organizations by abusing real Microsoft 365 login pages through a man-in-the-middle proxy. The attackers capture usernames, passwords, and live two-factor authentication codes, then take over the user’s session using stolen session…

August 31, 2026
DocuSign Share Lure Steals Microsoft 365 Sessions

DocuSign Share Lure Steals Microsoft 365 Sessions

Researchers described an active phishing operation using real DocuSign notifications to trick employees into opening a fake “remittance-advice” document and clicking a hidden malicious link. The attack routes victims through legitimate Microsoft/Google pages before landing on an…

August 28, 2026
Phish Adds Passkey That Survives Reset

Phish Adds Passkey That Survives Reset

Researchers described iAuthFlow v2, a phishing toolkit that steals a live Google login session and then uses that access to enroll an attacker-controlled passkey. Because passkeys are separate login methods, the attacker can often get back into the account even after the victim changes their…

August 24, 2026
Hackers Could Weaponize Email AI to Impersonate CEOs

Hackers Could Weaponize Email AI to Impersonate CEOs

Barracuda researchers simulated how an attacker who already compromised one employee mailbox could use the account’s built-in email AI assistant to hide evidence, learn org context, and draft convincing internal phishing emails. In their proof of concept, the attacker used an invoice-themed link to…

August 4, 2026