Phishing-as-a-service platform BigBear 2.0 steals MFA-protected Microsoft 365 accounts

Researchers at CloudSEK gained access to the control panel of BigBear 2.0, a phishing-as-a-service framework that has compromised 258 distinct organizations by bypassing multi-factor authentication. The service uses an adversary-in-the-middle proxy based on Evilginx2 to intercept credentials and session cookies, even after victims complete MFA. The operation has exfiltrated over 5,000 credential records and is leased to at least five affiliate operators who receive stolen data in real time via Telegram.
CloudSEK's investigation revealed the platform's technical architecture, including 42 virtual private servers and a custom "offy" configuration that proxies traffic through Microsoft's legitimate authentication flow. The service also deployed residential proxies matched to victim geographies across 69 countries to mask suspicious login attempts.
Beyond credential theft, the toolkit actively sabotages stronger security measures by injecting JavaScript that disables FIDO2/WebAuthn, pushing users toward less secure methods. While the phishing infrastructure has been offline for nearly three weeks, the administration panel remains accessible, and CloudSEK has already alerted law enforcement and impacted organizations.
The proliferation of PhaaS platforms like BigBear 2.0 could significantly erode trust in standard multi-factor authentication, as attackers increasingly bypass it with relative ease. Organizations relying solely on MFA may find their security posture insufficient, potentially exposing sensitive corporate data and personal information. This trend could force a broader shift toward phishing-resistant authentication methods, such as hardware security keys, and may increase the burden on IT teams to implement stricter device-based access controls.