Skip to main content
Emerging ThreatsMalware & Ransomware

Microsoft 365 Phishing Op Exposes Thousands of Credentials

Business office setting with computers and papers, one screen showing a blurry login page.

5,137 records tied to 461 organizations — including 1,032 plaintext passwords and 4,148 session cookies — sat in an attacker admin panel, and CloudSEK's researchers say 474 of those records represented fully authenticated Microsoft 365 sessions that could be replayed without triggering multi‑factor prompts.

The haul: 5,137 records, 1,032 passwords, and 474 MFA‑bypassed sessions

CloudSEK reported that the BigBear 2.0 phishing-as-a-service operation’s admin panel contained 5,137 records associated with 461 organizations. Those records included 1,032 plaintext passwords and 4,148 session cookies. The researchers classified 474 records as complete MFA-bypassed authentications — authenticated Microsoft 365 sessions captured in a form an attacker could replay. CloudSEK warned that hijacked accounts can expose email, calendars, Teams conversations, SharePoint and OneDrive files, and, depending on permissions, Entra ID and federated SaaS applications.

Evilginx2 proxying and session‑cookie replay

BigBear 2.0 is built on Evilginx2 and operates as an adversary‑in‑the‑middle proxy. Victims who load the phishing site see Microsoft’s real login flow proxied through the attacker’s server; usernames and passwords are passed to Microsoft and the MFA exchange runs normally. When Microsoft responds with a session cookie, it traverses the attacker’s infrastructure on its way back to the user. By stealing that cookie, the attacker can replay the authenticated session and access Microsoft 365 services without prompting the victim to reauthenticate — at least until the token expires or is revoked.

Custom JavaScript, FIDO2 blocking, and global proxy routing

CloudSEK found that BigBear’s operators went beyond stock Evilginx2. Security researcher Gagan Aggarwal said the campaign included JavaScript designed to disable FIDO2/WebAuthn on the phishing page, steering users toward authentication methods such as SMS codes, push notifications, and TOTP that are vulnerable to proxy‑based interception. The operation also used a residential proxy pool covering 69 countries — for example, routing an Indian victim’s upstream Microsoft login through an Indian residential IP to reduce geographic anomalies — and included checks to block visitors arriving from datacenter, VPN, and proxy addresses to impede automated scanners and analysts.

Multi‑user panel, affiliates, Telegram delivery, and "General Boss"

CloudSEK observed that the infrastructure was managed through a multi‑user panel and leased to at least five affiliate operators. Stolen credentials were delivered in real time via separate Telegram bots. The researchers saw 42 VPS nodes over the campaign’s lifetime; 26 of those had been deleted from the panel since late July, and only one was active when CloudSEK examined it. Aggarwal said the person running BigBear goes by the handle "General Boss." CloudSEK has not linked the operation to any known state‑backed group and said it believes monetary profit is the motive.

What this means for security teams, affected enterprises, and end users

  • Security teams and technologists: CloudSEK’s recommendation centers on reducing the window in which stolen session material is useful — implement phishing‑resistant FIDO2/WebAuthn authentication where possible, enforce conditional access policies and compliant device requirements, and be prepared to revoke compromised session and refresh tokens.
  • Affected enterprises and procurement leaders: Organizations should assume that a captured Microsoft 365 session can expose more than mail — calendars, Teams, SharePoint, OneDrive, Entra ID, and federated SaaS applications may be reachable depending on permissions — and plan incident response and token‑revocation workflows accordingly.
  • End users: The campaign’s JavaScript attempts to disable FIDO2/WebAuthn and push users toward weaker second factors; users should be wary of authentication prompts reached via links and support moving to phishing‑resistant authenticators when their organization offers them.

CloudSEK emphasized that the operation was still active at the time of its investigation and that the default phishing template, named "offy," was specifically configured to intercept Microsoft 365 authentication. The researchers’ snapshot of the admin panel — including the count of captured tokens and the affiliate leasing model — provides a rare, concrete view of what such phishing‑as‑a‑service campaigns can harvest and how quickly that harvest can be monetized or abused. The central, practical question left by the record is simple: will defenders shorten token lifetimes, enforce phishing‑resistant authentication, and speed revocation fast enough to blunt the value of those 474 complete sessions?

Source: The Register — BigBear phishing crew nets thousands of Microsoft 365 credentials