BigBear Microsoft 365 phishing service bypasses MFA at 258 organizations
Phishing-as-a-service framework BigBear 2.0 bypassed MFA at 258 organizations, stealing over 5,000 Microsoft 365 credentials.
Intelligence analysis by Qwen 2.5 (3B)

Phishing-as-a-service tool BigBear 2.0 compromised 258 organizations, stealing over 5,000 Microsoft 365 credentials.
A bad guy used a special tool to trick people into giving away their passwords. This tool tricked 258 companies and got over 5,000 passwords. It's like a game where the bad guy pretends to be the company to get the passwords.
Analysis
{"heading_1":"Phishing-as-a-Service Framework","paragraph_1":"BigBear 2.0 is a phishing-as-a-service (PhaaS) framework that uses an Evilginx2-based adversary-in-the-middle (AiTM) framework to intercept passwords and authenticated session cookies.","paragraph_2":"The service manages 42 virtual private servers (VPS) nodes, all configured to target Microsoft 365 as part of the observed operation.","paragraph_3":"The service uses a configuration called 'offy' to set up a man-in-the-middle (AiTM) proxy between the victim and Microsoft's legitimate authentication infrastructure.","paragraph_4":"This allows the attacker to capture credentials, including MFA, and session cookies and replay them through an API to hijack the victim's authentication session.","paragraph_5":"The service uses geo-matched residential proxies for 69 countries to match the victim's location with a residential IP address, making the activity less suspicious to Microsoft's authentication servers."}
Key points
- BigBear 2.0 phishing tool was used to steal over 5,000 Microsoft 365 credentials.
- The tool used a man-in-the-middle (AiTM) proxy to intercept passwords and session cookies.
- The tool used geo-matched residential proxies to make the activity less suspicious to Microsoft's servers.
Organizations can improve their security by using stronger authentication methods and educating their employees about phishing.
The bad guy can still find ways to trick people, so organizations need to keep improving their security.



