A phishing-as-a-service (PhaaS) framework called BigBear 2.0 has bypassed multi-factor authentication at 258 organizations and exfiltrated more than 5,000 Microsoft 365 credentials, according to cybersecurity researchers at CloudSEK who accessed the service's control panel.

The campaign uses an Evilginx2-based adversary-in-the-middle (AiTM) attack that intercepts both passwords and authenticated session cookies. This allows attackers to hijack accounts even after victims complete multi-factor authentication.

The attack works through a configuration called "offy," which establishes an AiTM proxy between the victim and Microsoft's authentication systems. The proxy captures credentials, including MFA data and session cookies, then replays themI to hijack the victim's session.

CloudSEK's analysis of the exfiltrated data revealed 5,137 credential records: 474 complete MFA-bypassed authentications, 1,032 plaintext passwords and 4,148 session cookies. The operation targeted 3,331 unique victim IP addresses across more than 40 countries and remained active at the time of the report.

The PhaaS panel is leased to at least five distinct affiliate operators, identified through live Telegram exfiltration bots that delivered stolen credentials in real time. While 461 organizations appeared in the broader targeting dataset, 258 experienced at least one completed MFA-bypass compromise.

BigBear uses custom JavaScript to disable FIDO2/WebAuthn browser functionality, forcing targets toward weaker authentication methods. The platform also deploys geo-matched residential proxies for 69 countries, aligning victim locations with residential IP addresses to evade Microsoft's fraud detection.

A compromised authenticated Microsoft 365 session exposes Exchange Online, Teams, SharePoint, OneDrive and Entra ID data. Attackers gain access to sensitive emails and files, and can pivot to other applications linked through single sign-on.

CloudSEK notified law enforcement and affected organizations, providing exfiltrated credentials through responsible-disclosure reports. While BigBear's administration panel remains online, its core phishing infrastructure has been offline for nearly three weeks. Organizations potentially targeted should reset exposed passwords and revoke all active sessions.