A phishing-as-a-service framework called BigBear 2.0 bypassed multi-factor authentication at 258 organizations and stole more than 5,000 Microsoft 365 credentials, according to researchers at CloudSEK.
CloudSEK gained administrator access to the service’s control panel and found 42 VPS nodes configured to target Microsoft 365. BigBear uses an “offy” configuration that places an AiTM proxy between victims and Microsoft’s legitimate authentication infrastructure.
The service targets authenticated Microsoft 365 sessions, which can expose email and files and may provide access to connected applications through single sign-on. CloudSEK said the panel was leased to at least five affiliate operators that received stolen credentials through live Telegram exfiltration bots.
Although the broader targeting dataset contained 461 organizations, CloudSEK said 258 distinct organizations had at least one completed MFA-bypass compromise.
BigBear also uses custom JavaScript to interfere with FIDO2/WebAuthn authentication and push targets toward weaker methods. Its infrastructure uses geo-matched residential proxies covering 69 countries, matching a victim’s location with a residential IP address to reduce the chance of detection by Microsoft’s authentication servers.
CloudSEK said it notified law enforcement and several affected organizations, including credentials in responsible-disclosure reports. At the time of reporting, the administration panel remained online.
Comments
0No comments yet. Be the first to comment.