New Phishing Service 'BigBear 2.0' Bypasses MFA, Steals Over 5,000 Microsoft Logins
Researchers at CloudSEK have identified a phishing-as-a-service (PhaaS) platform called BigBear 2.0 that has already stolen over 5,100 Microsoft 365 credential records from 461 organisations. The service is built on an adversary-in-the-middle framework, meaning it sits between a victim and a real login page to intercept both passwords and session cookies. This allows attackers to bypass multi-factor authentication by reusing stolen session data rather than needing a one-time code.
After gaining access to the platform's control panel, researchers found the operator running dozens of servers, real-time data theft via Telegram, and automated tools that let affiliates replay stolen cookies to hijack accounts. The most targeted countries included India, France, Saudi Arabia, New Zealand and Germany. Worryingly, IT service and managed service providers were the most frequently targeted sector, likely because compromising one provider can open the door to many of their clients through shared access to systems like Azure AD, RMM tools and password managers.
With stolen session cookies, attackers can access email, Teams, SharePoint, OneDrive and other connected business apps without needing to log in again, giving them a strong foothold for business email compromise, financial fraud and further data theft.