SecurityDeveloping

BigBear 2.0 phishing panel still online but infrastructure dark for three weeks, researchers say

CloudSEK gains admin access, reveals 5,137 stolen credentials from 258 organizations in Microsoft 365 campaign

edit
By LineZotpaper
Published
Updated
Read Time2 min
Sources2 outlets
A phishing-as-a-service platform targeting Microsoft 365 users has had its phishing infrastructure offline for nearly three weeks, though its administrative panel remains accessible, according to security researchers who infiltrated the operation's control system. CloudSEK researchers obtained administrator access to the BigBear 2.0 panel, uncovering a campaign that bypassed multi-factor authentication (MFA) at 258 organizations and captured more than 5,000 credentials.

CloudSEK, a cybersecurity firm, gained administrator access to the control panel of a phishing-as-a-service operation called BigBear 2.0, which uses an Evilginx2-based adversary-in-the-middle (AiTM) framework to intercept passwords and authenticated session cookies. The campaign targets Microsoft 365 users, capturing credentials even when victims complete MFA, by stealing the session cookie returned after successful authentication.

The panel contained 5,137 credential records, including 474 complete MFA-bypassed authentications, 1,032 plaintext passwords, and 4,148 session cookies. The affected records spanned 461 organizations, with at least 258 organizations confirmed to have suffered a completed MFA-bypass compromise. CloudSEK reported that 3,331 unique victim IPs across more than 40 countries were impacted, and the operation remained active at the time of investigation.

The infrastructure used 42 VPS nodes over the campaign's lifetime, though 26 had been deleted from the panel since late July. When CloudSEK examined the panel, only one VPS was active, and the phishing infrastructure has been offline for approximately three weeks. The administrative panel, however, remains accessible online.

BigBear uses a configuration called “offy” to set up a proxy between the victim and Microsoft’s legitimate authentication servers. Custom JavaScript on the phishing pages disables FIDO2/WebAuthn authentication, pushing victims toward weaker methods such as SMS codes or TOTP tokens. A residential proxy pool covering 69 countries routes traffic through IP addresses matching the victim's geographic location, making the login appear less suspicious to Microsoft's systems.

CloudSEK identified the platform operator as an individual using the alias “General Boss.” The service was leased to at least five affiliate operators who received stolen credentials in real time via separate Telegram bots. The researchers said they notified law enforcement and affected organizations and included compromised credentials in responsible-disclosure reports.

CloudSEK recommends organizations adopt phishing-resistant FIDO2/WebAuthn authentication, implement conditional access policies, enforce compliant device requirements, and revoke compromised session and refresh tokens to mitigate the threat.

§

Analysis

Why This Matters

  • The campaign demonstrates that MFA alone is not sufficient protection; AiTM phishing can capture session cookies even after a user completes authentication.
  • With credentials and hijacked sessions sold or used for business email compromise, organizations face risks of data theft, lateral movement, and further attacks.
  • The operation's partial offline period suggests either the attackers are retooling, have moved targets, or have been disrupted — but the admin panel remaining online means activity could resume rapidly.

Background

BigBear 2.0 is a phishing-as-a-service framework built on Evilginx2, an open-source tool that enables adversary-in-the-middle attacks against authentication flows. Unlike traditional credential harvesting, AiTM attacks allow attackers to bypass MFA by intercepting session cookies. The campaign exclusively targeted Microsoft 365, a widely used cloud platform that provides email, collaboration tools, and identity services. Phishing-as-a-service operations have grown increasingly common, lowering the technical barrier for cybercriminals.

Key Perspectives

CloudSEK: The firm accessed the operation's internal panel, providing rare visibility into the scale and methods of the campaign. They emphasize the need for hardware-based MFA and session token revocation as countermeasures. Affiliate operators: At least five affiliates used BigBear’s infrastructure to conduct their own phishing campaigns, receiving stolen credentials in real time — indicating a commercial relationship between the operator and customers. Critics/Skeptics: While the numbers are significant, some may question whether the captured session cookies were all successfully used before expiry. The infrastructure being offline for weeks suggests the operator may be reducing activity or preparing an update.

What to Watch

  • Whether the BigBear admin panel is eventually taken down or relaunches with new infrastructure.
  • Adoption of phishing-resistant authentication methods (FIDO2/WebAuthn) among targeted organizations.
  • Further disclosures from law enforcement or additional campaigns using similar techniques.

Sources

newspaper

Zotpaper

Articles published under the Zotpaper byline are synthesized from multiple source publications by our AI editor and reviewed by our editorial process. Each story combines reporting from credible outlets to give readers a balanced, comprehensive view.