# BigBear PhaaS Bypasses Microsoft 365 MFA at 258 Orgs

> BigBear 2.0 PhaaS uses Evilginx2 AiTM to bypass Microsoft 365 MFA, stealing credentials and session cookies from 258 organizations.

- Published: 2026-09-08T02:04:22.000Z
- Severity: high
- Category: Threat Intel
- Tags: BigBear, Microsoft 365, MFA Bypass, Phishing as a Service, AitM
- Author: Runtime Rebel Intel
- Primary source: https://www.bleepingcomputer.com/news/security/bigbear-microsoft-365-phishing-service-bypassed-mfa-at-258-organizations/
- Canonical: https://runtimerebel.com/blog/bigbear-phaas-bypasses-microsoft-365-mfa-at-258-orgs

## Key points

- BigBear PhaaS bypasses MFA for Microsoft 365, leading to credential theft and session hijacking across hundreds of organizations.
- Microsoft 365 cloud productivity and identity ecosystem, including Exchange Online, Teams, SharePoint, OneDrive, and Entra ID are affected.
- Reset exposed passwords, revoke active sessions, force re-authentication, and enforce phishing-resistant FIDO2/WebAuthn.

## Overview of BigBear 2.0 [Phishing](/glossary#phishing)-as-a-Service

The BigBear 2.0 [phishing-as-a-service](/glossary#phishing-as-a-service) (PaaS) framework has successfully bypassed multi-factor authentication ([MFA](/glossary#mfa)) across 258 organizations, leading to the theft of over 5,000 Microsoft 365 credentials. This sophisticated operation leverages an adversary-in-the-middle (AiTM) technique to intercept authentication data and active session cookies, granting attackers unauthorized access to compromised accounts. The campaign, which was observed actively targeting Microsoft 365 environments, highlights the persistent threat posed by advanced phishing kits that circumvent traditional security measures.

## Technical Analysis: BigBear 2.0 Microsoft 365 MFA Bypass

CloudSEK researchers gained administrative access to the BigBear control panel, revealing an extensive infrastructure managing 42 Virtual Private Server (VPS) nodes specifically configured for Microsoft 365 targeting. The core of BigBear's effectiveness lies in its use of an Evilginx2-based AiTM framework. This setup, dubbed “offy” within BigBear's configuration, establishes a proxy between the victim and Microsoft's legitimate authentication services.

When a victim attempts to log into Microsoft 365, the AiTM proxy intercepts their credentials, including usernames, passwords, and the MFA tokens generated during the authentication process. Crucially, it also captures authenticated session cookies. These cookies are then replayed via an [API](/glossary#api), allowing attackers to hijack the victim's live session even after successful MFA completion. This means that once MFA is bypassed, subsequent access does not require re-authentication, making persistent access easier for threat actors.

The exposed control panel showed that the service had exfiltrated 5,137 credential records, which included 474 complete MFA-bypassed authentications, 1,032 plaintext passwords, and 4,148 session cookies. These compromises affected 3,331 unique victim IP addresses across more than 40 countries, indicating a broad global reach. CloudSEK observed that the operation remained active at the time of their report, with the multi-user PhaaS panel leased to at least five affiliate operators who received stolen credentials in real time via Telegram exfiltration bots.

To enhance its evasive capabilities, BigBear employs custom JavaScript that specifically interferes with FIDO2/WebAuthn authentication. This script disables browser functionalities that would normally accommodate these phishing-resistant methods, thereby forcing targets towards less secure authentication options. Furthermore, the platform utilizes geo-matched residential proxies for 69 countries. By aligning the victim's location with a residential IP address, BigBear significantly reduces the likelihood of Microsoft's authentication servers flagging the activity as suspicious, thereby increasing the success rate of the phishing attacks.

## Mitigations and Recommendations for AiTM Phishing Detection in Microsoft 365

Organizations must assume potential compromise if their users were targeted by the BigBear campaign. Immediate actions are necessary to mitigate ongoing risks and prevent future exploitation. According to [CloudSEK researchers](https://www.bleepingcomputer.com/news/security/bigbear-microsoft-365-phishing-service-bypassed-mfa-at-258-organizations/), the following remediation steps are critical:

*   **Reset Exposed Passwords**: For any accounts suspected of compromise, immediately initiate a password reset.
*   **Revoke Active Sessions and Refresh Tokens**: Terminate all active sessions for potentially compromised accounts. This can be done within the Microsoft 365 admin portal or via PowerShell. Refresh tokens should also be revoked to invalidate persistent access.
*   **Force Re-authentication**: Require high-privileged accounts to re-authenticate, ensuring any hijacked sessions are severed.
*   **Enforce Phishing-Resistant MFA**: Transition from traditional MFA methods (e.g., SMS, push notifications) to phishing-resistant FIDO2/WebAuthn. This type of authentication, which relies on hardware-bound biometrics or security keys, is highly effective against AiTM attacks that steal session cookies. By actively enforcing FIDO2/WebAuthn phishing resistance, organizations can significantly reduce their [attack surface](/glossary#attack-surface).
*   **Implement Conditional Access Policies**: Configure Microsoft Entra ID Conditional Access policies to mandate managed devices for accessing sensitive resources. Relying solely on geo-location signals for [access control](/glossary#access-control) is insufficient, as BigBear utilizes geo-matched proxies to bypass such checks. Policies requiring device compliance or hybrid Azure AD join can provide a stronger layer of assurance.
*   **Monitor for Anomalous Session Activity**: Implement continuous monitoring for unusual login patterns, impossible travel, and anomalous session activity, which could indicate a compromised session.

Proactive measures and a layered security approach, focusing on post-MFA compromise detection and prevention, are essential to defend against sophisticated AiTM phishing services like BigBear 2.0.

**Related:** [Forg365 PhaaS Leverages AI, AiTM for Microsoft 365 Account Compromise](/blog/forg365-phaas-leverages-ai-aitm-for-microsoft-365-account-compromise), [Evilginx Operations Exposed: Misconfigured Server Leaks M365 Phishing Kits](/blog/evilginx-operations-exposed-misconfigured-server-leaks-m365-phishing-kits)

---

AI-generated analysis from the primary source above; not human-reviewed before publication — verify anything operational against the original (https://runtimerebel.com/editorial). Quote with attribution and a link to the canonical URL: https://runtimerebel.com/blog/bigbear-phaas-bypasses-microsoft-365-mfa-at-258-orgs
