Researchers say the “BigBear 2.0” phishing-as-a-service operation stole over 5,100 Microsoft 365 credential records across 461 organizations by capturing passwords and session cookies. The campaign used an adversary-in-the-middle setup to bypass MFA and maintain access, with stolen data sent to Telegram bots and used for automated cookie replay. IT service providers and managed service providers were highlighted as the most-targeted sector, increasing supply-chain risk.
Key findings
- Researchers report BigBear 2.0 exfiltrated “more than 5100 Microsoft 365 credential records from victims.”
- The operation is described as a phishing-as-a-service (PhaaS) platform built on Evilginx2 (adversary-in-the-middle) to capture credentials and bypass MFA.
- CloudSEK observed “42 VPS nodes” (primarily hosted at Vultr) configured with an “‘offy’ phishlet targeting Microsoft 365 exclusively.”
- Stolen data was routed to “dedicated Telegram bots,” and then into “a cookie-replay system,” enabling rapid session hijacking and persistent access.
- Impact described includes exposure of “4148 session cookies, 1032 plaintext passwords and 474 completed MFA-bypassed authentications.”
- IT service providers/MSPs were the “most targeted organizations by sector,” raising downstream/supply-chain compromise risk.
Who’s being targeted
- Commonly targeted roles: IT, Managed Service Provider (MSP) teams, Helpdesk/Service Desk, Microsoft 365/Entra ID administrators, All employees using Microsoft 365.
- Affected industries: IT services, Managed service providers (MSPs), Any organization using Microsoft 365 / Entra ID.
- Attack channels: email, website.
- Impersonated: Microsoft 365 sign-in / organization Microsoft 365 login.
Awareness takeaways
- Treat unexpected Microsoft 365 sign-in links as high risk; go to Microsoft 365 using a saved bookmark instead of clicking.
- MFA alone may not stop modern phishing, prioritize phishing-resistant MFA (FIDO2/WebAuthn) for high-risk users like IT/MSPs.
- If compromise is suspected, respond quickly by revoking sessions/tokens and forcing re-authentication (cookie theft can keep attackers logged in).
- Give extra training and tighter access controls to IT providers/MSPs because one compromise can cascade to clients.
Red flags to watch for
- Unexpected sign-in prompt delivered via email/link rather than via the normal Microsoft 365 portal bookmark
- Lookalike or unfamiliar sign-in URL (AITM phishing infrastructure)
- MFA prompts that appear when you weren’t actively signing in
Read the video transcript
You get an email: “Action required: Microsoft 365 sign-in needed to continue.” Looks normal, right? Behind that link is BigBear 2.0, a phishing-as-a-service built on Evilginx2. It shows you a perfect Microsoft 365 page, steals your password and session cookie, and then replays it to bypass your MFA. Researchers say BigBear 2.0 already grabbed over 5100 Microsoft 365 credential records, more than 4000 session cookies and hundreds of MFA-bypassed logins, hitting IT and managed service providers hardest, which then puts their clients at risk too. Here’s your move: if you get a Microsoft 365 sign-in link by email, don’t click it, close the email, open your saved Microsoft 365 bookmark, and sign in there instead.