BigBear 2.0 Phishing Network Exposes Over 5,000 Credential Records Across 461 Organisations

Super Daddy
4 Min Read

A global Microsoft 365 phishing operation known as “BigBear 2.0” has been found to have exposed 5,137 credential records across 461 organizations, according to researchers at CloudSEK. The findings include 4,148 session cookies, 1,032 plaintext passwords and 474 completed multi-factor authentication (MFA) bypass instances.

The campaign affected 3,331 unique victim IP addresses spanning more than 40 countries, with India, France, Saudi Arabia, New Zealand and Germany identified as the most heavily affected regions. Investigators said the significance of the findings stems from the fact that CloudSEK researchers gained direct access to the attacker’s administrative panel, providing visibility into the operation’s infrastructure, affiliate network, credential collection process and session-hijacking workflow.

How BigBear 2.0 Works

BigBear 2.0 is built on open-source adversary-in-the-middle phishing framework ‘Evilginx2’ for targeting Microsoft 365 accounts; the platform is rented out to other threat actors as a service. Rather than simply harvesting passwords, the phishing infrastructure positions itself between the victim and Microsoft’s legitimate login service. Once a victim completes login and MFA verification, the attacker is able to capture the authenticated session cookie, potentially allowing account access without needing to trigger another MFA prompt.

According to the report, the panel managed 42 virtual private server (VPS) nodes throughout the campaign and used residential proxy infrastructure spanning 69 countries, designed to make malicious login traffic appear to originate closer to the victim’s actual location.

CloudSEK identified at least five active affiliate operators who received stolen credentials through dedicated Telegram bots. The panel supported separate user and administrator roles, with infrastructure distributed across different operators, indicating that BigBear 2.0 functioned as a phishing-as-a-service operation rather than a single, isolated campaign.

The platform also automated the transfer of stolen information from the phishing page to Telegram, feeding directly into a cookie-replay system that allowed attackers to move quickly from initial credential theft to session hijacking.

Targets & Impact

India recorded the highest volume of compromised records, accounting for 658 records, or 12.8% of the total dataset, followed by France with 463 records and Saudi Arabia with 353. By sector, IT services and managed service providers were the most frequently targeted, followed by SaaS and technology companies, oil and gas, pharmaceuticals and consulting firms.

Researchers noted this is particularly concerning given that compromised IT service providers can potentially grant attackers access to customer environments, cloud platforms, remote-management tools and other downstream systems. A hijacked Microsoft 365 session can expose access to email, Teams, SharePoint, OneDrive, Entra ID and other connected SaaS applications, which can then be leveraged for business email compromise, financial fraud, internal phishing, data theft and further intrusion into enterprise systems.

Researchers also observed signs that the operator was attempting to reduce the campaign’s visibility – since late July, 26 of the 42 VPS nodes identified during the campaign have been removed from the panel.

CloudSEK has recommended that affected organizations revoke suspicious session and refresh tokens, enforce re-authentication, reset compromised passwords, and adopt phishing-resistant authentication methods such as FIDO2 or WebAuthn. The firm also advised implementing stronger Conditional Access policies and compliant-device requirements to help reduce exposure to similar attacks.

Pokdepinion: MFA bypass via session hijacking is a good reminder that multi-factor authentication alone isn’t a silver bullet.

Share This Article
Leave a Comment

Leave a Reply

Your email address will not be published. Required fields are marked *