BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations
AI Summary
The BigBear 2.0 phishing-as-a-service platform has been used to bypass multi-factor authentication (MFA) and steal over 5,000 Microsoft 365 credentials from 258 organizations. The service leverages an Evilginx2-based adversary-in-the-middle (AiTM) framework to intercept passwords, session cookies, and MFA tokens by proxying traffic between victims and Microsoft's legitimate authentication infrastructure. Attackers use the 'offy' configuration to capture credentials and session data, which is then exfiltrated in real time to affiliate operators via Telegram bots. The platform also employs custom JavaScript to disable FIDO2/WebAuthn support in browsers, forcing users toward weaker authentication methods, and uses geo-matched residential proxies across 69 countries to evade detection.
AI-extracted · verify before operational use