BigBear phishing crew nets thousands of Microsoft 365 credentials

← Back to the feed

BigBear phishing crew nets thousands of Microsoft 365 credentials

The Register · 1 hour ago

Security researchers at CloudSEK gained access to the admin panel of BigBear 2.0, an active phishing-as-a-service operation targeting Microsoft 365 users, exposing thousands of stolen credentials and session tokens harvested from hundreds of organisations. The operation uses Evilginx2-based infrastructure to act as a man-in-the-middle proxy, capturing not just passwords but live authenticated session cookies that can let attackers bypass multi-factor authentication entirely, potentially opening the door to email, files, Teams data and wider cloud infrastructure via Entra ID.

The panel held 5,137 records tied to 461 organisations, including 1,032 plaintext passwords and 4,148 session cookies, of which 474 were classified as complete MFA-bypassed authenticated sessions. The kit includes custom features such as JavaScript to disable phishing-resistant FIDO2/WebAuthn logins, a residential proxy network spanning 69 countries to disguise login locations, and checks to block researchers and scanners; it is run by an operator known as "General Boss" and leased to at least five affiliates who receive stolen data via Telegram bots in real time. CloudSEK believes the campaign is financially motivated rather than state-sponsored, and recommends organisations adopt phishing-resistant authentication, conditional access policies and prompt revocation of compromised tokens.

  • Phishing kit BigBear 2.0 stole 5,137 Microsoft 365 credential records from 461 firms.
  • 474 sessions were fully hijacked, bypassing MFA via cookie theft.
  • Kit disables FIDO2 security keys and hides behind global residential proxies.

Cybersecurity Research Science Technology

Read the full article at the source →