BigBear 2.0 Phishing Operation Bypasses Microsoft 365 MFA With Session Cookie Theft
A sophisticated phishing operation called BigBear 2.0 has been identified by CloudSEK analysts, targeting Microsoft 365 accounts and bypassing multi-factor authentication (MFA) with session cookie theft.
The campaign uses an adversary-in-the-middle setup, sitting between the victim and the real Microsoft login service. It captures the email address and password, lets Microsoft validate the request, and waits for the victim to complete their normal approval or code challenge.
When sign-in succeeds, Microsoft sends an authenticated session cookie to the browser. The proxy can copy that cookie before forwarding the response, allowing the attacker to replay it in another browser and access email, Teams, SharePoint, OneDrive, and connected single sign-on applications as the victim.