BigBear 2.0 is a phishing-as-a-service framework that bypassed MFA at 258 organizations and stole over 5,000 Microsoft 365 credentials using an Evilginx2-based adversary-in-the-middle setup. CloudSEK found the operation used geo-matched residential proxies, FIDO2/WebAuthn interference, and live exfiltration bots to capture passwords and session cookies in real time. #BigBear20 #Microsoft365 #CloudSEK #Evilginx2
Keypoints
- BigBear 2.0 bypassed MFA at 258 organizations.
- The campaign stole more than 5,000 Microsoft 365 credentials.
- It used an Evilginx2-based adversary-in-the-middle framework.
- CloudSEK found 42 VPS nodes and live Telegram exfiltration bots.
- The platform used geo-matched residential proxies and disabled FIDO2/WebAuthn to improve success.