Cyber Crime & ForensicPress Release

BigBear 2.0 Phishing Network Exposes 5,137 Credential Records Across 461 Organisations

Researchers Gained Access to the Attacker's Admin Panel, Uncovering a Microsoft 365 Phishing-as-a-Service Operation Spanning 40+ countries

A global Microsoft 365 phishing operation dubbed BigBear 2.0 has exposed 5,137 credential records across 461 organisations, including 4,148 session cookies, 1,032 plaintext passwords, and 474 completed MFA-bypassed authentications.

The BigBear 2.0 campaign affected 3,331 unique victim IPs across more than 40 countries, with India, France, Saudi Arabia, New Zealand and Germany among the leading geographies.

What makes the investigation particularly significant is that CloudSEK researchers gained access to the attacker’s administrative panel, giving them a rare inside view of how the operation was being run, including its infrastructure, affiliate network, credential collection and session-hijacking workflow.

A Phishing Service Built to Steal Authenticated Sessions

The platform, called BigBear 2.0, is built on the well-known open-source Evilginx2 adversary-in-the-middle phishing framework to target Microsoft 365 accounts and is rented out to other criminals.

Instead of simply stealing passwords, the phishing infrastructure sits between the victim and Microsoft’s legitimate login service. Once the victim completes the login and MFA process, the attacker can capture the authenticated session cookie and potentially reuse it to access the account without asking for the MFA code again.

The panel was observed managing 42 VPS nodes during the campaign lifecycle and using residential proxy infrastructure across 69 countries to make malicious login traffic appear closer to the victim’s real location. (For more information, read the Full Report.)

At Least Five Affiliate Operators Identified

The investigation into BigBear 2.0 also uncovered a wider phishing-as-a-service ecosystem.

CloudSEK identified at least five active affiliate operators receiving stolen credentials through dedicated Telegram bots. The panel supported separate user and admin roles, with infrastructure assigned to different operators, indicating that BigBear 2.0 was being operated as a service rather than as a single phishing campaign.

The platform also automated the flow of stolen information from the phishing page to Telegram and into a cookie-replay system, allowing attackers to move quickly from credential theft to session hijacking.

India Recorded the Highest Volume

India was the most heavily represented country in the BigBear dataset, with 658 records, or 12.8% of the total, followed by France with 463 records and Saudi Arabia with 353.

Among sectors, IT services and managed service providers were the most targeted, followed by SaaS and technology, oil and gas, pharmaceuticals and consulting.

This is particularly concerning because compromised IT service providers can potentially give attackers access to customer environments, cloud platforms, remote-management tools and other downstream systems.

Stolen Sessions Can Lead to Wider Enterprise Compromise

A hijacked Microsoft 365 session can potentially expose email, Teams, SharePoint, OneDrive, Entra ID and connected SaaS applications.

That access can then be used for business email compromise, financial fraud, internal phishing, data theft and further compromise of enterprise systems.

Researchers also observed signs that the operator was trying to reduce its footprint. Since late July, 26 of the 42 VPS nodes observed during the campaign had been deleted from the panel.

What Organisations Should Do

CloudSEK recommends that organisations revoke suspicious session and refresh tokens, force re-authentication, reset compromised passwords and adopt phishing-resistant authentication such as FIDO2 or WebAuthn. Stronger Conditional Access policies and compliant-device requirements can also reduce exposure.

CSA Editorial

Launched in Jan 2018, in partnership with Cyber Security Malaysia (an agency under MOSTI). CSA is a news and content platform focusing on key issues in cybersecurity in the region. CSA is targeted to serve the needs of cybersecurity professionals, IT professionals, Risk professionals and C-Levels who have an obligation to understand the impact of cyber threats.

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *