BigBear 2.0 Steals M365 Sessions After MFA

CSO Online · High sophistication
Last updated September 8, 2026

CloudSEK reported a phishing-as-a-service operation (“BigBear 2.0”) that tricks Microsoft 365 users into signing in and completing MFA on a lookalike login page. Even though MFA succeeds, the attackers capture the authenticated session cookie and reuse it to access the victim’s Microsoft 365 session without needing another MFA prompt. The campaign targeted hundreds of organizations globally, with IT services and managed service providers heavily represented.

Key findings

  • CloudSEK found thousands of stolen Microsoft 365 session cookies and over a thousand plaintext passwords tied to 461 organizations across 40+ countries.
  • The operation uses an attacker-in-the-middle (AiTM) reverse proxy (Evilginx2) to capture authenticated session cookies after the victim completes MFA.
  • Residential proxies are used to make attacker traffic appear to come from the victim’s country, potentially weakening location-based Conditional Access checks.
  • Researchers found code intended to disable FIDO2/WebAuthn options on phishing pages, pushing victims toward easier-to-phish MFA methods.
  • IT services and managed service providers were the most represented sector in CloudSEK’s data (151 organizations).

Who’s being targeted

  • Commonly targeted roles: All Microsoft 365 users, Executives, Finance, IT Helpdesk, IT administrators, Managed service provider staff.
  • Affected industries: IT services, Managed service providers (MSPs).
  • Attack channels: email, website.
  • Impersonated: Microsoft 365 sign-in / Microsoft authentication service, Microsoft 365 sign-in page (proxied).

Awareness takeaways

  • Train users that ‘MFA succeeded’ does not always mean the session is safe, report unexpected sign-in prompts immediately.
  • Teach staff to check the URL carefully on Microsoft 365 sign-in pages and to avoid signing in from emailed links when possible (navigate directly).
  • Promote and enforce phishing-resistant authentication (FIDO2/WebAuthn/passkeys) and warn users if those options are missing on a login page.
  • Coach incident responders and IT to treat this as ‘session compromise’ (revoke sessions/tokens), not just a password reset.

Red flags to watch for

  • Login page URL/domain is not Microsoft, even though it looks identical
  • Unexpected sign-in prompt not initiated by the user
  • MFA succeeds but is immediately followed by unusual account activity
  • Security key/passkey options (FIDO2/WebAuthn) appear missing or disabled on the login page
  • The sign-in experience looks slightly “off” or behaves unusually (extra prompts/redirects)
  • Sign-in appears to come from a “normal” location but device/app behavior is unfamiliar
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

You sign in to Microsoft 365, approve MFA, everything looks fine… but someone else is now in your mailbox too. That’s BigBear 2.0. You get an email: “Action required: Sign in to Microsoft 365 to continue.” The link opens a perfect-looking login, but the URL isn’t Microsoft. You sign in, complete MFA, and an Evilginx2 attacker-in-the-middle proxy quietly steals your authenticated session cookie. CloudSEK found thousands of stolen Microsoft 365 session cookies from 461 organizations. BigBear even tries to hide FIDO2 and WebAuthn options to push you into easier-to-phish OTP or push MFA. Residential proxies then replay your cookie from your country, so the login looks normal in logs. Here’s the move: if you ever get an unexpected Microsoft 365 sign-in or MFA prompt, do not click the email link, go to office.com yourself, sign in, and if you didn’t start it, report it immediately as a suspicious sign-in.

Similar attacks

BlackFile Crew Vishing Hits PE and Finance Firms

BlackFile Crew Vishing Hits PE and Finance Firms

Google and Reuters report a real vishing-led intrusion campaign tied to the extortion crew behind the retired “BlackFile” brand (tracked as UNC6671). Attackers call employees on personal phones spoofing the corporate IT help desk, push a same-day “passkey/MFA update,” and send them to a look‑alike…

August 12, 2026
BigBear 2.0 Steals M365 Sessions to Bypass MFA

BigBear 2.0 Steals M365 Sessions to Bypass MFA

Researchers say the “BigBear 2.0” phishing-as-a-service operation compromised Microsoft 365 accounts by stealing authenticated session cookies after users completed MFA normally. This let attackers replay the session and access accounts without triggering another MFA prompt, impacting 258…

September 8, 2026
BigBear 2.0 PhaaS Steals 5,100+ M365 Logins

BigBear 2.0 PhaaS Steals 5,100+ M365 Logins

Researchers say the “BigBear 2.0” phishing-as-a-service operation stole over 5,100 Microsoft 365 credential records across 461 organizations by capturing passwords and session cookies. The campaign used an adversary-in-the-middle setup to bypass MFA and maintain access, with stolen data sent to…

September 8, 2026
Mirage2FA Phishing Kit Steals Microsoft 365 Sessions

Mirage2FA Phishing Kit Steals Microsoft 365 Sessions

A phishing-as-a-service toolkit called Mirage2FA has been targeting organizations by abusing real Microsoft 365 login pages through a man-in-the-middle proxy. The attackers capture usernames, passwords, and live two-factor authentication codes, then take over the user’s session using stolen session…

August 31, 2026
Fake SSO + MFA Push Used in Real Breaches

Fake SSO + MFA Push Used in Real Breaches

This weekly roundup includes two real social-engineering-driven incidents. Attackers used social engineering to access Apollo Global Management’s cloud platforms and steal sensitive personal data, and separately attempted a ShinyHunters phishing attack against ReliaQuest using a fake SSO login page…

August 28, 2026
Browser Trust Scams: Fake Updates, BitB, ClickFix

Browser Trust Scams: Fake Updates, BitB, ClickFix

Cofense reports multiple real-world campaigns where attackers don’t hack the browser, they trick employees by copying normal browser experiences like login pop-ups, software update prompts, and “verification” checks. The goal is to get users to enter credentials, approve attacker sessions, or run…

August 26, 2026