BigBear 2.0 phishing campaign hijacks Microsoft 365 sessions after MFA
Brief
A phishing-as-a-service operation targeting Microsoft 365 users has harvested thousands of session cookies that could be used to hijack authenticated sessions after victims complete multifactor authentication, CloudSEK said.
The cybersecurity firm said in a report that it uncovered the operation, known as BigBear 2.0, in June after gaining access to its administrative panel.
The panel contained 5,137 credential records linked to 461 targeted organizations across more than 40 countries. CloudSEK also reported 4,148 captured session cookies and 1,032 plaintext passwords. The firm said 474 records showed completed logins in which attackers captured the authenticated session created after MFA.
BigBear 2. 0 is built on Evilginx2, a framework that places an attacker-controlled reverse proxy between the victim and Microsoft’s legitimate authentication service.
