Phishing-as-a-Service Tool BigBear 2.0 Bypasses MFA to Hijack Microsoft 365 Sessions
Security researchers have identified a new phishing-as-a-service platform, dubbed BigBear 2.0, that can capture active Microsoft 365 sessions and grant attackers full account control even after victims complete multi‑factor authentication (MFA). The discovery, made by CloudSEK’s TRIAD team, highlights a growing ability of cybercriminals to subvert one of the industry’s most widely promoted defenses.
BigBear 2.0 is a rebranded incarnation of the open‑source Evilginx2 framework, which specializes in credential‑harvesting attacks that proxy login pages and siphon authentication tokens. By positioning itself as a legitimate Microsoft login portal, the service tricks users into entering their credentials and approving MFA prompts. Once the victim’s browser establishes a session, the tool extracts the session cookie and forwards it to the attacker, who can then reuse the token to access the account without needing the second‑factor code.
The TRIAD team’s analysis revealed that the platform is offered to affiliates on a subscription basis, complete with customizable phishing templates and automated campaign management. Investigators observed that the stolen session tokens remain valid for the duration of the user’s original login, allowing the attacker to perform actions such as reading emails, downloading files, or manipulating administrative settings before the session expires or the user logs out.
These capabilities undermine the security premise of MFA, which protects against credential reuse but does not safeguard the session itself once authentication succeeds. Enterprises that rely heavily on Microsoft 365 for collaboration, file sharing, and identity management are especially exposed, as a compromised session can bypass conditional access policies and exfiltrate sensitive data without triggering typical alerting mechanisms.
Experts advise organizations to augment MFA with additional controls, such as continuous authentication monitoring, strict session timeout policies, and the use of security‑aware browsers that can detect anomalous token usage. Microsoft has previously warned about “session hijacking” techniques and recommends enabling features like Conditional Access App‑Control and Azure AD Identity Protection. As phishing‑as‑a‑service ecosystems mature, security teams will need to adopt layered defenses and user education programs that emphasize the risks of credential‑phishing beyond the initial login prompt.
Comments (0)
Be the first to comment.
Join the discussion