Phishing-as-a-Service operation harvests over 5,000 Microsoft 365 credentials
Security researchers infiltrated the admin panel of the BigBear 2.0 phishing service and found more than 5,000 stolen Microsoft 365 records from hundreds of organizations.
Researchers from CloudSEK breached the backend of the BigBear 2.0 phishing-as-a-service platform, which leverages Evilginx2 to target Microsoft 365 users. Their investigation revealed a database of 5,137 records tied to 461 distinct organizations, comprising 1,032 plaintext passwords and 4,148 session cookies, of which 474 were identified as complete MFA-bypassed authentications. The stolen session cookies allow attackers to hijack active Microsoft 365 sessions, exposing email, calendars, Teams chats, and files stored in SharePoint and OneDrive, and potentially granting access to Entra ID and other cloud services.
The operation employs a phishing page that proxies the genuine Microsoft login flow, capturing credentials and MFA challenges before relaying them to Microsoft, then extracting the returned session token. Custom JavaScript disables FIDO2/WebAuthn on the fake login page, steering victims toward less secure MFA methods. A residential proxy pool covering 69 countries, including location-specific routing, helps evade detection.
The service is managed through a multi-user panel, leased to at least five affiliates, and delivers stolen data via Telegram bots. The campaign is still ongoing, with only one VPS node active at the time of analysis.
Why it matters
Compromised Microsoft 365 sessions can give attackers broad access to corporate data and cloud resources.
In this story
