BigBear 2.0 Phishing Campaign Hijacks Authenticated Sessions on Microsoft 365
A phishing-as-a-service operation called BigBear 2.0 has been uncovered by CloudSEK, which allows attackers to hijack authenticated sessions after victims complete multifactor authentication (MFA) on Microsoft 365.
The operation, built on the Evilginx2 framework, places an attacker-controlled reverse proxy between the victim and Microsoft's legitimate authentication service, allowing the phishing infrastructure to intercept session cookies once MFA is completed.
CloudSEK reported that BigBear 2.0 contains 5,137 credential records linked to 461 targeted organizations across more than 40 countries, with 4,148 captured session cookies and 1,032 plaintext passwords.
The cybersecurity firm observed at least five identified affiliate operators using the multi-user service, which also uses residential proxies selected according to the victim's country, making malicious authentication traffic appear geographically consistent with the user.