BigBear 2.0 Phishing Campaign Steals Thousands of Microsoft Credentials
A new phishing-as-a-service (PhaaS) operation, dubbed BigBear 2.0, has been discovered by security researchers at CloudSEK. The campaign has already stolen over 5100 Microsoft 365 credential records from victims worldwide.
The PhaaS platform is based on the Evilginx2 adversary-in-the-middle framework and uses automation to improve the end-user experience. Stolen information from phishing pages is fed through to Telegram and into a cookie-replay system, enabling attackers to rapidly perform session hijacking.
The most-targeted countries were India, France, Saudi Arabia, New Zealand, and Germany. At least five affiliates are using the service, receiving stolen credentials through dedicated Telegram bots.
CloudSEK researcher Gagan Aggarwal warned that IT service providers are high-value targets because they manage client infrastructure - a single compromise can enable supply chain attacks against dozens of downstream clients.
The team found 5137 credential records exposed across 461 organizations, including 4148 session cookies, 1032 plaintext passwords, and 474 completed MFA-bypassed authentications. The platform uses geo-matched residential proxy pools, real-time Telegram exfiltration, and automated cookie replay to bypass MFA and maintain persistent access.