logo

BigBear phishing crew nets thousands of Microsoft 365 credentials

ID: d5068ef1-ff6a-5aff-a628-f88cdc022313

STIX ID: report--d5068ef1-ff6a-5aff-a628-f88cdc022313

Feed Name: The Register (Security)

Threat Score
78/100

Date Published: 2026-09-08

Date Updated: 2026-09-10

...
...

BigBear 2.0 is an active Evilginx2-based phishing-as-a-service campaign targeting Microsoft 365 users; researchers who accessed the operation's admin panel found 5,137 stolen records from 461 organizations (1,032 plaintext passwords, 4,148 session cookies) including 474 authenticated sessions that enable MFA bypass. The infrastructure uses JavaScript to discourage FIDO2/WebAuthn, a global residential proxy pool to mask geolocation, multi-user leasing to affiliates, and real-time exfiltration via Telegram, posing high risk for account takeover, business email compromise, data theft, and lateral access to cloud resources.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.