Skip to content
Back to Guavy Wire
Stocks

BigBear 2.0 Phishing Campaign Compromises Over 3,300 Microsoft Accounts

Instruments
MSFT
Share

A phishing campaign known as BigBear 2.0 has compromised over 3,300 Microsoft 365 accounts protected by multi-factor authentication (MFA), according to a report from CloudSEK.

The operation, which began in late June and is believed to still be ongoing, uses an Evilginx2-based phishing-as-a-service (PhaaS) campaign dubbed BigBear 2.0.

Researchers gained access to the threat actor panel and found that the phishlet 'offy' adds custom JavaScript injections to target Microsoft 365 accounts for adversary-in-the-middle (AiTM) MFA phishing.

The phishing kit captures passwords, MFA session tokens, and forces users to fall back to phishable MFA methods by preventing the use of FIDO2/WebAuthn passkeys.

More on Stocks

Disclaimer: Guavy is a data and market intelligence provider, not an investment adviser. The information, signals, and market analysis provided by the Guavy API and related services are for informational purposes only and are not intended as financial advice, investment recommendations, or an endorsement of any particular trading strategy. Trading in volatile markets, including cryptocurrency, carries significant risk and may not be suitable for all investors. Past performance is not indicative of future results. Users should consult with a qualified financial professional before making any investment decisions. Guavy makes no guarantee of trading profits or financial returns.

Market sentiment intelligence for apps, funds & agents

Location

729 55 Ave SW
Calgary AB T2V 0G4
Canada

© 2026 Guavy Inc