Attackers have used a new phishing platform called “BigBear 2.0” to target hundreds of organizations across more than forty countries, according to researchers at CloudSEK. In about 10% of cases, the phishing attacks were able to bypass multifactor authentication.
“The panel has exfiltrated 5,137 credential records — including 474 complete MFA-bypassed authentications,” CloudSEK says. “1,032 plaintext passwords, and 4,148 session cookies — affecting 3,331 unique victim IPs across 40+ countries (India, France, Saudi Arabia, New Zealand, and Germany leading), with the operation still active at the time of writing. The multi-user PhaaS panel is leased to at least five affiliate operators identified through live Telegram exfiltration bots, each receiving stolen credentials in real time.”
The phishing attacks proceed as follows:
- “Step 1: Victim clicks the phishing link (typically delivered via email) and is proxied to the legitimate Microsoft login page.
- Step 2: Victim enters email → proxy captures it and passes it to Microsoft.
- Step 3: Victim enters password → proxy captures plaintext AND forwards to Microsoft.
- Step 4: Victim completes MFA (TOTP, push notification, SMS) → session token issued by Microsoft is captured by the proxy.
- Step 5: Attacker replays the captured session cookie to access the victim's mailbox, Teams, SharePoint, and all connected SaaS applications — without triggering re-authentication.”
While BigBear 2.0 isn’t unique in this attack flow, the phishing kit stands out for its success rate.
“80% of password entries resulted in session cookie capture, and the password-to-complete conversion rate exceeded 100%, indicating the AiTM relay captured session tokens even without explicit password entry in some cases,” CloudSEK says.
CloudSEK has the story: https://www.cloudsek.com/blog/tracking-bigbear-2-0-evilginx2-phishing-campaign
