Phishers Deploy BigBear 2.0 to Hijack Microsoft 365 Sessions, Sidestepping MFA
A new phishing operation known as BigBear 2.0 has been observed stealing proof of successful multi‑factor authentication (MFA) from Microsoft 365 users, allowing attackers to take control of already‑authenticated sessions without cracking the second factor.
The campaign relies on the open‑source tool Evilginx2 to act as a man‑in‑the‑middle proxy. Victims receive authentic‑looking sign‑in links that direct them to a replica of the Microsoft login page. After the user enters credentials and completes MFA, the proxy captures the session cookie that proves the user is logged in, then hands the cookie to the attacker.
By hijacking the session cookie, the threat actors bypass the protective layer that MFA provides. Rather than attempting to guess or brute‑force the second factor, they simply reuse the token that the legitimate service issues after the user has already been verified, effectively granting the same access rights as the original user.
Evilginx2 has been employed in previous phishing campaigns, but BigBear 2.0 refines the technique for Microsoft 365 environments, which are heavily used by enterprises for email, collaboration, and cloud services. The operation’s focus on Microsoft’s cloud suite makes it especially concerning for organizations that rely on MFA as a primary defense against credential theft.
Security analysts note that traditional phishing detection—such as spotting suspicious URLs or malformed emails—may not be enough, because the malicious links often appear to originate from legitimate Microsoft domains or trusted short‑link services. Once the victim’s browser completes the MFA step, the proxy silently extracts the session token, leaving little trace in the user’s activity log.
Experts advise a layered response: enforce conditional access policies that require device compliance, monitor for anomalous token usage, and employ browser‑based MFA prompts that bind the second factor to the specific device. Organizations are also urged to educate users about the risks of unsolicited sign‑in requests, even when they appear to come from Microsoft, and to deploy tools that can detect proxy‑based credential harvesting. As attackers continue to refine session‑cookie theft methods, continuous vigilance and adaptive security controls remain essential.
Comments (0)
Be the first to comment.
Join the discussion