Skip to main content
Emerging Threats

Microsoft Credentials Targeted in BigBear 2 PhaaS Campaign

Server room with rows of computer servers and networking equipment.

“The panel was observed managing 42 VPS nodes over the campaign lifecycle – primarily hosted by The Constant Company LLC (Vultr) – configured with the ‘offy’ phishlet targeting Microsoft 365 exclusively,” wrote CloudSEK researcher Gagan Aggarwal.

CloudSEK's admin access to the BigBear 2.0 panel

Security researchers at CloudSEK reported they were able to gain administrator-level access to the control panel used by the BigBear 2.0 phishing-as-a-service operation. That access allowed researchers to observe the infrastructure and live activity of the criminal service, including node counts, affiliate behavior and real-time exfiltration to messaging services.

Scale of compromise: 5,137 Microsoft 365 credential records and 3,331 unique victim IPs

CloudSEK said the BigBear 2.0 campaign has exposed more than 5,100 Microsoft 365 credential records. In its tally the research team identified 5,137 credential records across 461 organizations and observed 3,331 unique victim IP addresses spanning more than 40 countries. The dataset CloudSEK described included 4,148 session cookies, 1,032 plaintext passwords and 474 completed authentications where multi-factor authentication (MFA) had been bypassed.

Technique: Evilginx2-based adversary-in-the-middle PhaaS with Telegram exfiltration and cookie replay

CloudSEK attributes BigBear 2.0 to an operation built on the Evilginx2 adversary-in-the-middle framework. The platform ran a single phishlet, identified as “offy,” that targeted Microsoft 365 specifically. According to Aggarwal, the operator — using the alias “General Boss” — combined geo-matched residential proxy pools, automated cookie replay, and real-time exfiltration via Telegram.

CloudSEK described the service as a turnkey phishing-as-a-service (PhaaS) offering: stolen credentials and cookies captured by phishing pages were forwarded into Telegram and routed into a cookie-replay system, enabling attackers to rapidly perform session hijacking and maintain persistent access despite MFA protections.

Targets and sector-level risk: IT service providers most targeted

CloudSEK’s report highlighted that IT service and managed service providers were the most-targeted organizations. Aggarwal warned that IT staff frequently hold privileged access to systems such as Azure AD, on-premises Active Directory, remote monitoring and management (RMM) tools and password managers, and that a compromise of an IT provider could enable supply chain attacks against dozens of downstream clients.

CloudSEK also listed the most-targeted countries in the campaign: India, France, Saudi Arabia, New Zealand and Germany. The researchers reported at least five affiliates using the service, each receiving stolen credentials through dedicated Telegram bots.

CloudSEK's remediation recommendations

  • Revoke suspicious session and refresh tokens.
  • Force re-authentication for potentially impacted accounts.
  • Reset compromised passwords.
  • Adopt phishing-resistant authentication such as FIDO2 or WebAuthn.
  • Strengthen conditional access policies and compliant-device requirements.

What this means for technologists, affected enterprises, and end users

  • Technologists and security teams: Expect to need to identify and revoke active session cookies and refresh tokens rapidly; CloudSEK’s findings show cookie capture and automated replay can bypass MFA and deliver persistent access to email, Teams, SharePoint, OneDrive, Entra ID and connected SaaS applications.
  • Affected enterprises and procurement leaders: Organizations that rely on third-party IT service providers should assume elevated supply-chain risk when those providers possess broad administrative access; CloudSEK flagged IT service providers as high-value targets that can enable downstream compromise.
  • End users: Plaintext passwords and captured session cookies were part of the observed haul; CloudSEK recommends forcing re-authentication and moving to phishing-resistant authentication methods to limit the utility of credentials harvested by phishing pages and cookie-replay tools.

CloudSEK’s live access to the BigBear 2.0 panel provided a rare direct view into a commercialized phishing operation: an Evilginx2-based PhaaS delivering automated exfiltration to Telegram, coordinated affiliate distribution, and cookie-replay for rapid session hijacking. The immediate questions on the table are whether targeted organizations will revoke tokens and reset access quickly enough, and whether wider adoption of phishing-resistant authentication and stricter conditional access will blunt this model’s effectiveness.

Source: Infosecurity Magazine / CloudSEK report