Phishing Operation BigBear 2.0 Hijacks Microsoft 365 Sessions After MFA
A phishing-as-a-service operation called BigBear 2.0 has been uncovered by cybersecurity firm CloudSEK, which harvests session cookies to hijack authenticated sessions in Microsoft 365 after victims complete multifactor authentication.
The operation uses Evilginx2, a framework that places an attacker-controlled reverse proxy between the victim and Microsoft's legitimate authentication service, allowing the attackers to intercept the session cookie and reuse it without completing the authentication process again.
CloudSEK discovered 5,137 credential records linked to 461 targeted organizations across more than 40 countries, including 4,148 captured session cookies and 1,032 plaintext passwords.