PhaaS Campaign Targets IT Providers via M365 Phishing
CloudSEK reports BigBear 2.0 phishing operation stole over 5,100 Microsoft credentials, hitting IT firms hardest.
A newly documented phishing-as-a-service operation has already siphoned more than 5,100 Microsoft 365 credentials, with IT service providers emerging as the primary targets. The campaign, dubbed BigBear 2.0 by researchers, signals a shift toward using stolen session data to sidestep multi-factor authentication.
Security firm CloudSEK said it infiltrated the threat actor's management panel and tracked the operation's reach across more than 40 countries. The researchers observed 3,331 unique victim IP addresses, suggesting a wide and automated assault on enterprise email systems.
BigBear 2.0's Evilginx2 Foundation
BigBear 2.0 is built on Evilginx2, an adversary-in-the-middle framework that intercepts authentication traffic in real time. Unlike traditional credential phishing, which simply captures passwords, this approach snags session cookies and other tokens that can be replayed later.
CloudSEK's report details how the platform managed 42 VPS nodes over the course of the campaign, mostly hosted by The Constant Company LLC (Vultr). The nodes ran an "offy" phishlet designed to target Microsoft 365 exclusively, according to CloudSEK researcher Gagan Aggarwal.
During the investigation, CloudSEK recorded 5,137 exposed credential records across 461 organizations. That haul included 4,148 session cookies, 1,032 plaintext passwords, and 474 completed MFA-bypassed authentications.
Automated Bypass and Cookie Replay
The operator, using the alias "General Boss," deployed geo-matched residential proxy pools to avoid detection, alongside real-time Telegram exfiltration and automated cookie replay, according to CloudSEK. This automation strips away much of the manual effort typically required to turn stolen credentials into active sessions.
"The panel was observed managing 42 VPS nodes over the campaign lifecycle – primarily hosted by The Constant Company LLC (Vultr) – configured with the 'offy' phishlet targeting Microsoft 365 exclusively," wrote CloudSEK researcher Gagan Aggarwal.
— Gagan Aggarwal, researcher at CloudSEK
Stolen data flows from phishing pages into Telegram, feeding a cookie-replay system that lets attackers hijack sessions swiftly. The result is a service that treats session theft as a streamlined pipeline, not a one-off exploit.
Affiliates and Global Targets
The campaign attracted at least five affiliates who received stolen credentials through dedicated Telegram bots. This affiliate structure turns the operation into a distributed enterprise, with multiple groups leveraging the same infrastructure.
The most-targeted countries were India, France, Saudi Arabia, New Zealand, and Germany. That geographic spread aligns with the use of residential proxy pools, which allow attackers to mask their origin while appearing local to victims.
IT Providers in the Crosshairs
What most concerned CloudSEK was the sector breakdown: IT service and managed service providers topped the list of targeted organizations. These firms are attractive because they manage client infrastructure and often hold privileged access to Azure AD, on-prem AD, remote management tools, and password managers.
"IT service providers are high-value targets because they manage client infrastructure – a single IT provider compromise can enable supply chain attacks against dozens of downstream clients," Aggarwal warned. "IT staff also often have privileged access to Azure AD, on-prem AD, RMM tools and password managers."
With valid session cookies, attackers could access email, Teams, SharePoint, OneDrive, Entra ID, and connected SaaS applications. This level of access opens the door to business email compromise, financial fraud, phishing, data theft, and further compromise of enterprise systems, Aggarwal claimed.
Minimizing the Damage
CloudSEK's findings hinge on its own access to the BigBear 2.0 panel, which offered a rare inside look at the operation's scale and mechanics. The firm has urged potentially affected organizations to take specific steps to blunt the impact.
- Revoke suspicious session and refresh tokens
- Force re-authentication
- Reset compromised passwords
- Adopt phishing-resistant authentication such as FIDO2 or WebAuthn
- Strengthen conditional access policies and compliant-device requirements
These actions aim to invalidate stolen tokens and reduce the chance of future adversary-in-the-middle attacks. For IT providers, the stakes extend beyond their own networks to every client they support.
Why BigBear 2.0 Matters for Enterprises
The effectiveness of this campaign shows how phishing services have matured into sophisticated, automated operations that can bypass widely deployed security controls. For IT providers, the risk is compounded: a single breach could cascade across dozens of client organizations, turning one incident into a supply-chain event.
For any organization running Microsoft 365, the targeting of IT providers is a reminder that your security posture is only as strong as your partners'. External IT vendors often hold keys to your infrastructure, making them a logical entry point for attackers.
This report suggests that traditional password-based defenses may no longer be sufficient. It could be prudent to review current authentication policies, consider phishing-resistant MFA methods such as FIDO2, and ensure session tokens are tightly controlled. The threat is active, and the window for proactive defense may be closing.
Sources
- Infosecurity Magazine Original source
Continue Reading
Windows Server 2016 hit by 0xc0000409 after August updates
Microsoft says August 2026 security updates trigger 0xc0000409 errors on Windows Server 2016 when Compatibility Appraiser is enabled.
Google Warns on AI Coding Tool Threats
Google Threat Intelligence Group warns AI coding tools are prime targets for supply chain attacks.
Adobe Commerce bug exploited before hotfix
Sansec reports active attacks on a max-severity Magento flaw, with backdoors and secondary access found.