BigBear 2.0 Phishing Campaign Compromises Over 3,300 Microsoft Accounts
A phishing campaign known as BigBear 2.0 has compromised over 3,300 Microsoft 365 accounts protected by multi-factor authentication (MFA), according to a report from CloudSEK.
The operation, which began in late June and is believed to still be ongoing, uses an Evilginx2-based phishing-as-a-service (PhaaS) campaign dubbed BigBear 2.0.
Researchers gained access to the threat actor panel and found that the phishlet 'offy' adds custom JavaScript injections to target Microsoft 365 accounts for adversary-in-the-middle (AiTM) MFA phishing.
The phishing kit captures passwords, MFA session tokens, and forces users to fall back to phishable MFA methods by preventing the use of FIDO2/WebAuthn passkeys.