BigBear 2.0 Phishing-as-a-Service Bypasses MFA, Steals 5,000+ Microsoft 365 Credentials Across 258 Organizations
According to BleepingComputer, a phishing-as-a-service (PhaaS) platform called BigBear 2.0 has been used to bypass multi-factor authentication (MFA) protections and steal more than 5,000 Microsoft 365 credentials from at least 258 organizations. BigBear operates as a subscription-style toolkit, lowering the technical bar for attackers to run convincing Microsoft 365 credential-phishing campaigns at scale.
Why It Matters
PhaaS kits like BigBear that specifically target Microsoft 365 and defeat MFA are significant because they undermine a control many organizations treat as a strong baseline defense. These platforms typically work as adversary-in-the-middle (AiTM) reverse proxies that relay a victim's live login session — including MFA challenges — back to the attacker, allowing session token theft rather than just password capture. Any organization relying on Microsoft 365 with traditional MFA (as opposed to phishing-resistant methods) is a potential target, and the scale reported here — 258 organizations and 5,000+ credentials — indicates broad, opportunistic targeting rather than a narrow, bespoke campaign.
What Defenders Should Watch For
- Hunt for anomalous Microsoft 365 sign-in patterns: impossible-travel logins, new device/user-agent combinations shortly after a successful MFA challenge, and session token reuse from unfamiliar IP ranges or ASNs.
- Review Entra ID / Azure AD sign-in and risk logs for token replay indicators, such as a session created via one IP and subsequently used from a different, geographically inconsistent IP.
- Inspect email gateway and URL-click telemetry for AiTM-style phishing infrastructure (reverse-proxy phishing pages mimicking Microsoft 365 login flows), and consider blocking known BigBear-associated infrastructure as it becomes available through threat intel feeds.
- Prioritize migration toward phishing-resistant authentication (FIDO2/WebAuthn security keys, certificate-based auth) for high-value accounts, since traditional push/OTP-based MFA is exactly what AiTM kits are built to bypass.
- Ensure conditional access policies enforce device compliance and session sign-in frequency, which can reduce the value of stolen session tokens.
This item is based on early reporting and is still developing — technical specifics of BigBear 2.0's infrastructure, indicators of compromise, and victim details have not yet been independently verified by df00tech. We will monitor for further disclosure and update or publish a dedicated detection if concrete indicators or technique details emerge. Read the original report at BleepingComputer.