Bugle Blast — News that hits hard

Bugle Blast

YOUR WORK MFA CAN STILL GET PROXIED! | BigBear PhaaS bypassed Microsoft 365 MFA at 258 orgs — lookalike pages steal the session

Written by

in

If your day job runs on Microsoft 365, “I got the MFA prompt, so I’m safe” is not enough. BleepingComputer reported Sept. 7 that the BigBear 2.0 phishing-as-a-service (PhaaS) kit — built on Evilginx2 adversary-in-the-middle proxying — completed MFA bypasses at 258 organizations.

CloudSEK researchers who reached the control panel said the operation exfiltrated 5,137 credential records, including 474 complete MFA-bypassed authentications, 1,032 plaintext passwords, and 4,148 session cookies across 40+ countries. Custom JavaScript interferes with FIDO2/WebAuthn to nudge victims toward weaker methods. Residential proxies matched to ~69 countries help the fake login look local to Microsoft’s checks.

Frame it for normals: If you type your work email and password into a lookalike Microsoft page, the proxy can capture the session after you finish MFA — and then ride your cookie into Outlook, Teams, and OneDrive. Prefer phishing-resistant passkeys/FIDO2 hardware where IT allows it. If you suspect you phished yourself, tell IT immediately, revoke sessions / sign out everywhere, and reset the password from a known-good device.

Sources: BleepingComputer (CloudSEK)


Discover more from Bugle Blast

Subscribe to get the latest posts sent to your email.

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *