
BigBear 2.0 Phishing Service Skips MFA Across 258 Microsoft 365 Organizations
A CloudSEK report details BigBear 2.0, a phishing-as-a-service framework, bypassing MFA for 258 Microsoft 365 organizations and stealing 5,137 credentials (including 474 MFA-bypassed authentications) plus 4,148 session cookies across 3,331 victims in 40+ countries. The operation used a Evilginx2-based MITM setup with an 'offy' proxy, geo-matched residential proxies, and custom JavaScript to weaken FIDO2/WebAuthn, enabling attackers to hijack sessions after victims authenticated. The admin panel remained online while the phishing infrastructure was offline for ~three weeks. Recommendations include resetting exposed passwords, revoking active sessions, refreshing tokens, enforcing phishing-resistant FIDO2/WebAuthn, and applying Conditional Access with managed devices.


