BigBear 2.0 Phishing Bypasses MFA, Hits 258 Organizations Worldwide

Security researchers have identified a large-scale phishing-as-a-service platform that successfully bypassed multi-factor authentication protections across hundreds of organizations worldwide. The platform, tracked as BigBear 2.0, targeted Microsoft 365 accounts exclusively, stealing thousands of credentials and session cookies.

Analysts at CloudSEK gained full administrative access to the operation's control panel during their investigation into the campaign. Their findings reveal how modern phishing kits routinely defeat authentication methods once widely considered reliable security safeguards for organizations.

 BigBear 2.0 Phishing Bypasses MFA, Hits 258 Organizations Worldwide

CloudSEK's Threat Research and Information Analytics Division first discovered BigBear 2.0 back in June 2026 while actively tracking related phishing infrastructure online. The kit is built on Evilginx2, an open-source adversary-in-the-middle framework designed to proxy traffic between unsuspecting victims and legitimate login pages.

Researchers found the panel actively managing 42 virtual private server nodes, each one configured with a phishlet named "offy" for targeting. That specific configuration was built to intercept Microsoft 365 authentication flows that run through Azure Active Directory and Microsoft Entra ID.

The operator, using the online alias "General Boss," leased access to the panel out to at least five separate affiliate operators. Each affiliate received a steady stream of stolen credentials in real time through dedicated Telegram bots identified during CloudSEK's investigation.

This multi-tenant structure allowed the operation to scale rapidly while distributing stolen data among several independent criminal groups. CloudSEK described the arrangement as a fully functioning, multi-tenant phishing-as-a-service business rather than the work of a single lone actor.

Evilginx2 phishlets function as a proxy positioned directly between the victim and the legitimate Microsoft login portal throughout an entire session. When a victim clicks the phishing link, the platform relays their entered credentials and one-time codes directly to Microsoft's authentic servers.

Once the victim completes multi-factor authentication, Microsoft issues an authenticated session cookie that then travels back through the same malicious proxy. BigBear then captures that cookie and replays it later, granting attackers full account access without ever needing the original MFA code.

CloudSEK reported that the panel's internal metrics showed striking effectiveness across the observed phishing infrastructure and campaigns. 80% of submitted passwords resulted in a captured session cookie, confirming that the proxy consistently intercepted fully authenticated tokens.

The panel also included a keepalive function that refreshed stolen cookies automatically by reusing each victim's previously captured refresh token. This extended the attackers' window of access well beyond the typical one to twenty-four-hour lifespan of a Microsoft session token.

Custom Code Defeats Phishing-Resistant Hardware Keys

Investigators found custom JavaScript code injected into every proxied Microsoft 365 login page served through the entire BigBear infrastructure network. One script disabled the browser's native WebAuthn functionality, effectively preventing FIDO2 hardware security keys from completing the authentication process. This forced victims toward weaker, phishable authentication methods, such as SMS codes, authenticator app prompts, or simple one-time passcodes instead.

A second script quietly blocked Microsoft's anti-phishing telemetry and canary tokens, helping the entire operation evade automated detection systems longer:

  • FIDO2/WebAuthn blocking script that disables hardware key support and forces phishable MFA fallback methods
  • Telemetry-blocking script that silently drops requests to Microsoft's canary token and anti-phishing detection endpoints
  • Auto "Keep Me Signed In" script that maximizes stolen session cookie lifetime without victim interaction

A third injected script automatically selected the "Keep Me Signed In" option on the victim's behalf after every single login attempt. CloudSEK noted that this maximized the usable lifespan of every stolen session cookie without requiring any further interaction from the victim. Researchers concluded that FIDO2 remains the only multi-factor authentication method that is structurally resistant to this style of proxy-based phishing attack.

BigBear 2.0 also deployed geo-matched residential proxy pools spanning 69 different countries to disguise malicious login attempts as legitimate activity. When a victim in a specific country accessed the phishing page, the platform routed outgoing traffic through a matching residential IP address.

This technique helped defeat Microsoft's built-in geo-anomaly detection and undermined conditional access policies that rely heavily on location-based signals. It also bypassed anti-bot checks tied to the ipapi.is service, blocking most independent security researchers from directly analyzing the live panel.

CloudSEK's report, shared directly with BleepingComputer, detailed the full extent of the stolen data recovered throughout the investigation into the campaign. The panel exfiltrated 5,137 credential records overall, including 474 complete MFA-bypassed authentications, over one thousand plaintext passwords, and thousands of cookies.

Those stolen records affected 3,331 unique victim IP addresses spanning more than forty countries by the time researchers published their findings. CloudSEK described the campaign as "still active at the time of writing," underscoring the urgency facing potentially exposed organizations everywhere.

CloudSEK identified 461 organizations in the broader targeting dataset collected from the compromised administrative panel over recent months. Researchers clarified, however, that 258 of those organizations experienced at least one fully completed multi-factor authentication bypass event during the campaign.

India, France, and Saudi Arabia emerged as the most heavily targeted countries throughout the entire observed campaign period, CloudSEK's data showed. IT services and managed service providers represented the single largest targeted sector, given their broad access to numerous downstream client networks:

  • India recorded the highest victim concentration, followed closely by France, Saudi Arabia, New Zealand, and Germany
  • IT services and managed service providers accounted for the largest share of targeted organizations overall

CloudSEK noted that the platform functioned as a "multi-user PhaaS panel," leased out to separate criminal groups rather than run by a single operator. That leasing structure suggests session cookies harvested through BigBear could feed additional attacks, including business email compromise or ransomware deployment. Compromising a single authenticated Microsoft 365 session can expose sensitive email, files, and other connected single sign-on applications to attackers.

CloudSEK stated that it notified law enforcement agencies and several affected organizations directly, as part of its responsible disclosure process. Investigators also observed the threat actor deleting dozens of virtual private server nodes from the panel since late July 2026. That pattern suggests active counter-forensic behavior, likely triggered by growing awareness of the ongoing investigation surrounding the entire criminal campaign. Despite this cleanup effort, the administrative panel itself remained fully accessible online when this report was published.

The underlying phishing infrastructure, however, had already been completely offline for nearly three weeks, CloudSEK's report recently confirmed. Security teams should treat any Microsoft 365 environment as potentially exposed if unusual sign-in activity has recently been observed anywhere.

Organizations are strongly advised to reset exposed passwords, revoke active sessions, and refresh authentication tokens for high-privilege accounts without delay. Forcing re-authentication across all privileged accounts helps limit the damage from any session cookies that attackers may have already captured successfully.

Enforcing phishing-resistant FIDO2 or WebAuthn authentication today remains the single most effective defense against this particular category of adversary-in-the-middle attack. Conditional access policies that require managed, compliant devices offer noticeably stronger protection than those relying solely on simple location-based signals.

As phishing kits increasingly mimic legitimate infrastructure while defeating standard MFA methods, layered defenses become essential for protecting cloud accounts. Organizations using Microsoft 365 should review authentication logs regularly and treat unexplained account activity as genuinely suspicious.

Share:

facebook
X (Twitter)
linkedin
copy link
Karolis Liucveikis

Karolis Liucveikis

Experienced software engineer, passionate about behavioral analysis of malicious apps

Author and general operator of PCrisk's News and Removal Guides section. Co-researcher working alongside Tomas to discover the latest threats and global trends in the cyber security world. Karolis has experience of over 8 years working in this branch. He attended Kaunas University of Technology and graduated with a degree in Software Development in 2017. Extremely passionate about technical aspects and behavior of various malicious applications.

▼ Show Discussion

PCrisk security portal is brought by a company RCS LT.

Joined forces of security researchers help educate computer users about the latest online security threats. More information about the company RCS LT.

Our malware removal guides are free. However, if you want to support us you can send us a donation.

Donate