BigBear 2.0 phishing panel reveals thousands of stolen Microsoft sessions

CloudSEK says it reached the admin panel of a phishing service holding thousands of session cookies stolen from Microsoft 365 users after MFA.

CSBadmin
2 Min Read

CloudSEK researchers say they reached the management panel of BigBear 2.0, a phishing operation that collects authenticated Microsoft 365 sessions. The panel logged 5,137 credential records across 461 organizations in more than 40 countries, plus 4,148 session cookies and 1,032 passwords stored in plaintext.

Of those records, 474 captured the authenticated session that exists only after a user finishes MFA, the point where most defenses stop watching.

The operation rides Evilginx2, which positions an attacker-owned proxy in front of Microsoft’s real sign-in flow. Users type their password and approve their second factor normally; the proxy simply copies the session cookie Microsoft hands back, and that token then works without another credential or approval. Traffic exits through residential proxies matched to each victim’s country, so the sign-ins look geographically normal and often sail past location-based Conditional Access rules. Custom code on the phishing pages disables FIDO2 and WebAuthn enrollment, pushing users toward weaker second factors.

CloudSEK counts at least five affiliate operators on the service and watched 42 virtual private server nodes come and go, 26 of them deleted from the panel since late July. Managed service providers made up 151 of the victim organizations, a worrying concentration given their privileged reach into customer tenants. The takeaway: a completed MFA prompt no longer proves a session belongs to the user, and phishing-resistant authentication should be enforced where the option exists.

CSBadmin

The latest in cybersecurity news and updates.

Share This Article
Follow:
The latest in cybersecurity news and updates.