MobbleOpen in Mobble ⇢
Technology · Cybersecurity · published 2026-09-07 · via BleepingComputer

Phishing-as-a-service platform BigBear 2.0 steals MFA-protected Microsoft 365 accounts

Image via BleepingComputer
Image via BleepingComputer

Researchers at CloudSEK gained access to the control panel of BigBear 2.0, a phishing-as-a-service framework that has compromised 258 distinct organizations by bypassing multi-factor authentication. The service uses an adversary-in-the-middle proxy based on Evilginx2 to intercept credentials and session cookies, even after victims complete MFA. The operation has exfiltrated over 5,000 credential records and is leased to at least five affiliate operators who receive stolen data in real time via Telegram.

Expanded Detail

CloudSEK's investigation revealed the platform's technical architecture, including 42 virtual private servers and a custom "offy" configuration that proxies traffic through Microsoft's legitimate authentication flow. The service also deployed residential proxies matched to victim geographies across 69 countries to mask suspicious login attempts.

Beyond credential theft, the toolkit actively sabotages stronger security measures by injecting JavaScript that disables FIDO2/WebAuthn, pushing users toward less secure methods. While the phishing infrastructure has been offline for nearly three weeks, the administration panel remains accessible, and CloudSEK has already alerted law enforcement and impacted organizations.

Context

The proliferation of PhaaS platforms like BigBear 2.0 could significantly erode trust in standard multi-factor authentication, as attackers increasingly bypass it with relative ease. Organizations relying solely on MFA may find their security posture insufficient, potentially exposing sensitive corporate data and personal information. This trend could force a broader shift toward phishing-resistant authentication methods, such as hardware security keys, and may increase the burden on IT teams to implement stricter device-based access controls.

Expanded detail and Context are AI-generated analysis; the linked article remains the authoritative source.
Read the full article at BleepingComputer →
This summary is AI-generated and original to Mobble; the linked article is the authoritative source. Original headline: “BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations.” Browse more stories.