BigBear 2.0 Phishing Campaign Hijacks Microsoft 365 Sessions After MFA
13 Articles
13 Articles
Microsoft 365 users hit by two major threat campaigns - fake IT calls and phishing emails target users across the world
BigBear 2.0 and PREY-0058 are wreaking havoc across businesses as they scam employees into handing over login credentials and MFA codes.
BigBear phishing crew nets thousands of Microsoft 365 credentials
A Microsoft 365 phishing operation targeting hundreds of organizations captured thousands of passwords and session cookies, including hundreds of authenticated sessions that could be hijacked to bypass MFA, according to researchers who accessed the crooks' own admin panel. Security researchers at CloudSEK say they accessed the admin panel behind BigBear 2.0, an Evilginx2-based phishing-as-a-service operation targeting Microsoft 365 users, giving…
BigBear 2.0 phishing campaign hijacks Microsoft 365 sessions after MFA
A phishing-as-a-service operation targeting Microsoft 365 users has harvested thousands of session cookies that could be used to hijack authenticated sessions after victims complete multifactor authentication, CloudSEK said. The cybersecurity firm said in a report that it uncovered the operation, known as BigBear 2.0, in June after gaining access to its administrative panel. The panel contained 5,137 credential records linked to 461 targeted org…
BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations
A phishing-as-a-service framework called BigBear 2.0 has been used to bypass multi-factor authentication at 258 organizations and steal more than 5,000 Microsoft 365 credentials. [...]
BigBear 2.0: Microsoft 365 AiTM Phishing and Session Theft
1. Basic Information Report Title: Tracking BigBear 2.0 Evilginx2 phishing campaign Source: CloudSEK Date Published: 2026-09-07 Original Source: CloudSEK Related Source: BleepingComputer: BigBear Microsoft 365 phishing service bypassed MFA Related Source: Microsoft Learn: Authentication strengths Associated Malware / Threat Groups / CVEs / Products: BigBear 2.0, Evilginx2, BigBear affiliates, Microsoft 365, Microsoft Entra ID, WebAuthn, FI…
A phishing operation as a service linked to BigBear accumulated thousands of Microsoft 365 credentials and session cookies, including seemingly complete MFA authentication. Access to the attackers' panel allowed us to observe how the campaign uses Evilginx2, residential proxies and Telegram bots to convert business accounts into criminal merchandise.
Coverage Details
Bias Distribution
- 100% of the sources are Center
Factuality
To view factuality data please Upgrade to Premium












