bleeping-computer · Crawled Sep 7, 2026

BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations

2 IoCs
Read original article ↗

AI Summary

The BigBear 2.0 phishing-as-a-service platform has been used to bypass multi-factor authentication (MFA) and steal over 5,000 Microsoft 365 credentials from 258 organizations. The service leverages an Evilginx2-based adversary-in-the-middle (AiTM) framework to intercept passwords, session cookies, and MFA tokens by proxying traffic between victims and Microsoft's legitimate authentication infrastructure. Attackers use the 'offy' configuration to capture credentials and session data, which is then exfiltrated in real time to affiliate operators via Telegram bots. The platform also employs custom JavaScript to disable FIDO2/WebAuthn support in browsers, forcing users toward weaker authentication methods, and uses geo-matched residential proxies across 69 countries to evade detection.

AI-extracted · verify before operational use

Indicators of Compromise 2 extracted

Type Value Detail
Domain offy Details →
GitHub Repo Evilginx2 Details →