CloudSEK Warns About BigBear 2.0 AiTM Phishing Targeting Microsoft 365 Accounts

According to CloudSEK research, the BigBear 2.0 platform captures Microsoft 365 passwords and authenticated session cookies. This may give attackers access to an account even after standard MFA is completed.

Security firm CloudSEK published findings on September 7, 2026, about the BigBear 2.0 phishing service targeting Microsoft 365 login accounts. It is a renamed platform based on the Evilginx2 tool. According to CloudSEK, it uses adversary-in-the-middle (AiTM) techniques, in which a fraudulent server intermediates communication between the victim and the legitimate login service.

The goal is not only to obtain a password. The platform is also said to capture an authenticated session cookie, which allows an already verified session to continue. If the victim completes the login, including the second factor, on the fraudulent page, the attacker may reuse that session without requesting MFA again.

What CloudSEK found about BigBear 2.0 phishing

CloudSEK said it obtained administrator access to the platform’s panel. Based on its telemetry, the company recorded 5,137 stolen records: 1,032 passwords, 4,148 session cookies, and 474 full authentications after MFA.

According to the researchers, 461 organizations were targeted in the campaign data. At least one successful post-MFA session takeover was reportedly recorded at 258 different organizations. However, these figures come from CloudSEK’s research and have not been independently confirmed by Microsoft or the affected organizations.

CloudSEK attributes operation of the service to an actor using the nickname “General Boss” and at least five affiliate operators. The identities of these individuals have not been independently verified.

Why standard MFA may not be enough

An AiTM attack works like a reverse proxy server placed between the user and the real login page. The victim may see a credible-looking login prompt, enter a password, and successfully approve the second factor. The attacker then captures not only the login credentials but also the token or cookie created after successful verification.

Microsoft warns that this type of attack may bypass traditional multifactor authentication methods through the theft and reuse of tokens. This is therefore not a new vulnerability in Microsoft 365, but a phishing technique that abuses the legitimate login process and the user’s trust in a fraudulent page.

For an attacker, a stolen session cookie may be particularly useful because it can provide access to email and cloud services without requiring the second factor again. CloudSEK has not published confirmation of which specific organizations were compromised, or whether the recorded cases led to data leaks, financial losses, or malware deployment.

Recommended steps for organizations

CloudSEK published indicators of compromise for organizations to check in their own environments. If an account takeover is suspected, the company recommends resetting passwords, revoking active sessions and refresh tokens, and forcing users to sign in again.

Microsoft recommends deploying phishing-resistant authentication methods, such as passkeys and FIDO2, and using Conditional Access policies. For Microsoft 365 administrators, it is important to handle such an incident as a possible takeover of an already authenticated session, not merely as a compromised password.

Further developments will show whether action against BigBear 2.0 infrastructure is confirmed by Microsoft, hosting providers, or law enforcement authorities. It will also be important to monitor new domains, IP addresses, and campaigns that may be associated with the platform, as well as any independently verifiable information about its impact.

Sources

  • CloudSEK – The primary research describes the BigBear 2.0 panel, AiTM methodology, reported numbers of records and organizations, IOCs, and recommended response steps.
  • Microsoft Learn – Microsoft states that AiTM attacks can bypass traditional MFA through token theft and recommends phishing-resistant authentication and Conditional Access.
  • BleepingComputer – Independent news coverage of CloudSEK’s publication and its main findings.

Verified and updated: 09/07/2026 20:33

Sharing