CloudSEK, a cybersecurity firm, gained administrator access to the control panel of a phishing-as-a-service operation called BigBear 2.0, which uses an Evilginx2-based adversary-in-the-middle (AiTM) framework to intercept passwords and authenticated session cookies. The campaign targets Microsoft 365 users, capturing credentials even when victims complete MFA, by stealing the session cookie returned after successful authentication.
The panel contained 5,137 credential records, including 474 complete MFA-bypassed authentications, 1,032 plaintext passwords, and 4,148 session cookies. The affected records spanned 461 organizations, with at least 258 organizations confirmed to have suffered a completed MFA-bypass compromise. CloudSEK reported that 3,331 unique victim IPs across more than 40 countries were impacted, and the operation remained active at the time of investigation.
The infrastructure used 42 VPS nodes over the campaign's lifetime, though 26 had been deleted from the panel since late July. When CloudSEK examined the panel, only one VPS was active, and the phishing infrastructure has been offline for approximately three weeks. The administrative panel, however, remains accessible online.
BigBear uses a configuration called “offy” to set up a proxy between the victim and Microsoft’s legitimate authentication servers. Custom JavaScript on the phishing pages disables FIDO2/WebAuthn authentication, pushing victims toward weaker methods such as SMS codes or TOTP tokens. A residential proxy pool covering 69 countries routes traffic through IP addresses matching the victim's geographic location, making the login appear less suspicious to Microsoft's systems.
CloudSEK identified the platform operator as an individual using the alias “General Boss.” The service was leased to at least five affiliate operators who received stolen credentials in real time via separate Telegram bots. The researchers said they notified law enforcement and affected organizations and included compromised credentials in responsible-disclosure reports.
CloudSEK recommends organizations adopt phishing-resistant FIDO2/WebAuthn authentication, implement conditional access policies, enforce compliant device requirements, and revoke compromised session and refresh tokens to mitigate the threat.