If your day job runs on Microsoft 365, “I got the MFA prompt, so I’m safe” is not enough. BleepingComputer reported Sept. 7 that the BigBear 2.0 phishing-as-a-service (PhaaS) kit — built on Evilginx2 adversary-in-the-middle proxying — completed MFA bypasses at 258 organizations.
CloudSEK researchers who reached the control panel said the operation exfiltrated 5,137 credential records, including 474 complete MFA-bypassed authentications, 1,032 plaintext passwords, and 4,148 session cookies across 40+ countries. Custom JavaScript interferes with FIDO2/WebAuthn to nudge victims toward weaker methods. Residential proxies matched to ~69 countries help the fake login look local to Microsoft’s checks.
Frame it for normals: If you type your work email and password into a lookalike Microsoft page, the proxy can capture the session after you finish MFA — and then ride your cookie into Outlook, Teams, and OneDrive. Prefer phishing-resistant passkeys/FIDO2 hardware where IT allows it. If you suspect you phished yourself, tell IT immediately, revoke sessions / sign out everywhere, and reset the password from a known-good device.
Sources: BleepingComputer (CloudSEK)


Leave a Reply