A highly sophisticated Phishing-as-a-Service (PhaaS) operation, identified as BigBear 2.0, has demonstrated alarming efficacy in circumventing multi-factor authentication protocols across a significant number of organizations, resulting in the compromise of thousands of Microsoft 365 credentials and exposing critical corporate data.
The emergence of Phishing-as-a-Service platforms like BigBear 2.0 marks a concerning evolution in the cyber threat landscape, democratizing access to advanced attack capabilities for a broader range of malicious actors. These platforms provide ready-made infrastructure, tools, and support, enabling even less technically proficient individuals to launch large-scale, sophisticated phishing campaigns. In the case of BigBear 2.0, its deployment has led to the successful bypass of robust security measures, including multi-factor authentication (MFA), impacting at least 258 distinct organizations and facilitating the illicit acquisition of over 5,000 Microsoft 365 credential sets.
Detailed investigations conducted by cybersecurity researchers at CloudSEK unveiled the operational intricacies of BigBear 2.0 after gaining administrative access to its command-and-control infrastructure. This unprecedented access provided deep insights into the service’s methodology and scale. The researchers discovered that the platform leveraged an extensive network of 42 Virtual Private Server (VPS) nodes, each meticulously configured to specifically target the Microsoft 365 ecosystem. This dedicated infrastructure underscores the focused nature of the campaign, aiming squarely at the widely adopted cloud productivity suite.
The core of BigBear 2.0’s success lies in its sophisticated use of an Adversary-in-the-Middle (AiTM) framework, built upon the foundation of Evilginx2. This advanced technique allows attackers to interpose themselves between the victim and the legitimate authentication server. Unlike traditional phishing, which merely attempts to steal credentials, AiTM actively proxies the entire authentication process. When a victim attempts to log into their Microsoft 365 account, they are redirected through the attacker’s server, which acts as a transparent intermediary. This setup allows the attacker to intercept sensitive data, including both initial passwords and, crucially, authenticated session cookies, even after the victim has successfully completed their multi-factor authentication. The capture of these session cookies is paramount, as it enables attackers to hijack active user sessions without needing to re-authenticate, effectively bypassing the very MFA designed to protect against such compromises.

BigBear 2.0 specifically employs a configuration dubbed "offy," which establishes this Man-in-the-Middle (MiTM) proxy between the unsuspecting user and Microsoft’s legitimate authentication infrastructure. This strategic positioning allows for the real-time capture of credentials, including the one-time codes or prompts associated with MFA, alongside the critical session cookies. These intercepted artifacts can then be replayed through an API, enabling the threat actor to seize control of the victim’s authenticated session. This method effectively neutralizes the protective layer of MFA, rendering it ineffective against this class of attack.
Microsoft 365 represents a lucrative target for cybercriminals due to its pervasive adoption across industries and its integration of a vast array of critical business services. This cloud-based productivity and identity ecosystem encompasses essential applications such as Exchange Online for email, Teams for communication, SharePoint for collaboration, OneDrive for file storage, and Entra ID (formerly Azure Active Directory) for identity and access management. A successful compromise of an authenticated Microsoft 365 session can have cascading and severe consequences. It can immediately expose sensitive corporate emails and files, leading to significant data breaches. Furthermore, given the prevalence of single sign-on (SSO) integration within the Microsoft 365 environment, an attacker gaining access to one session can potentially gain unauthorized access to numerous other interconnected business applications, expanding the scope of compromise exponentially.
CloudSEK’s analysis unequivocally demonstrated the substantial success of the BigBear 2.0 operation, revealing its capacity to compromise hundreds of entities and exfiltrate thousands of sensitive data points. The administrative panel, which researchers accessed, documented the exfiltration of 5,137 credential records. This comprehensive dataset included 474 instances of complete MFA-bypassed authentications, indicating a direct and successful subversion of multi-factor security. Additionally, the panel recorded 1,032 plaintext passwords and 4,148 session cookies. These compromises collectively affected 3,331 unique victim IP addresses spanning more than 40 countries, with the operation reportedly still active at the time of the researchers’ discovery. This global reach highlights the widespread threat posed by such PhaaS offerings.
Further insights into BigBear 2.0’s operational model revealed that the multi-user PhaaS panel is leased to at least five distinct affiliate operators. These affiliates manage their respective campaigns, with stolen credentials being exfiltrated in real-time directly to their Telegram bots. This model underscores the commercialization of cybercrime, where specialized services provide infrastructure, and affiliates handle the distribution and monetization of stolen data. While the broader targeting dataset indicated 461 organizations were subjected to BigBear activity, CloudSEK confirmed that 258 distinct organizations had experienced at least one successful MFA-bypass compromise, illustrating the precise and impactful nature of the attacks.

The sophistication of BigBear 2.0 extends beyond its AiTM capabilities. Researchers also uncovered custom JavaScript code deployed by the platform specifically designed to interfere with FIDO2/WebAuthn authentication mechanisms. This malicious script actively disables the browser’s functionality that supports these stronger, phishing-resistant authentication methods. By doing so, BigBear 2.0 deliberately steers targets towards weaker or more traditional MFA methods that are susceptible to its AiTM bypass techniques, thereby increasing its overall success rate.
To further enhance its evasion capabilities and increase the likelihood of successful compromise, BigBear 2.0 employs geo-matched residential proxies for 69 different countries. This tactical use of proxies ensures that the phishing attempts appear to originate from an IP address geographically aligned with the victim’s actual location. This sophisticated trick is crucial for bypassing advanced security measures implemented by Microsoft’s authentication servers, which often flag unusual login attempts originating from disparate geographical locations as suspicious. By mimicking legitimate user behavior, BigBear 2.0 significantly reduces the chances of detection by anomaly-based security systems.
In response to their findings, CloudSEK initiated responsible disclosure protocols. The cybersecurity firm promptly notified relevant law enforcement agencies and several of the directly affected organizations. Additionally, the stolen credentials were included in these disclosure reports to aid in mitigation efforts. Despite these actions, the administration panel for BigBear 2.0 reportedly remained online at the time of reporting, although the active phishing infrastructure had been taken offline for nearly three weeks. This situation highlights the persistent challenge of fully dismantling cybercriminal operations, as infrastructure components can be reactivated or relocated.
For organizations that suspect or confirm exposure to BigBear 2.0 activity, immediate and decisive action is imperative. The primary recommendation is to reset all exposed passwords across affected accounts. Concurrently, all active sessions must be revoked, and any refresh tokens should be invalidated to prevent continued unauthorized access. For high-privileged accounts, a mandatory re-authentication process should be enforced to ensure legitimate control. Beyond reactive measures, a proactive shift towards more robust security postures is crucial. Organizations are strongly advised to enforce phishing-resistant authentication methods such as FIDO2/WebAuthn, which inherently protect against AiTM attacks by binding authentication to a specific origin. Furthermore, the implementation of Conditional Access policies that mandate the use of managed devices for accessing corporate resources, rather than relying solely on geographical location signals, can significantly bolster defenses against sophisticated bypass techniques.

The BigBear 2.0 campaign serves as a stark reminder of the evolving and increasingly sophisticated nature of cyber threats. The commercialization of advanced attack tools through PhaaS models means that organizations must continuously adapt their security strategies. Relying solely on traditional MFA methods is no longer sufficient against adversaries leveraging AiTM techniques. The emphasis must shift towards comprehensive, multi-layered security architectures that incorporate advanced threat intelligence, robust identity and access management, continuous monitoring, and employee education on recognizing and reporting highly evasive phishing attempts. The ongoing arms race between attackers and defenders necessitates a proactive, adaptive, and resilient security posture to safeguard critical digital assets in an increasingly perilous cyber landscape.







