started · updated
BigBear 2.0 phishing network exposes 5,000 credentials
A widespread phishing-as-a-service operation known as ‘BigBear 2.0’ has compromised over 5,000 credential records across 461 organizations. Utilizing the ‘Evilginx2’ adversary-in-the-middle framework, the campaign targets Microsoft 365 accounts by positioning itself between users and legitimate login services to capture authenticated session cookies.
Researchers at CloudSEK identified that the operation successfully bypassed multi-factor authentication (MFA) in 474 instances. The campaign has impacted more than 3,300 unique IP addresses across 40 countries, with significant activity noted in India, France, Saudi Arabia, New Zealand, and Germany. The infrastructure utilized 42 virtual private server nodes and residential proxies spanning 69 countries to mask malicious traffic.
Parallel security reports from Microsoft highlight similar sophisticated social engineering tactics. Threat actors are impersonating IT support to trick employees into updating Passkeys or Single Sign-On (SSO) configurations. These attacks allow hackers to hijack sessions and gain access to sensitive data within SharePoint Online, OneDrive, and Outlook, often using automated systems to slowly exfiltrate data and avoid detection.
Entities
BigBear 2.0 · CloudSEK · Evilginx2 · Microsoft · Microsoft 365