BigBear 2.0 phishing campaign hijacks Microsoft 365 sessions after MFA

Chronological Source Flow
Back

AI Fusion Summary

CloudSEK uncovered BigBear 2.0, a phishing-as-a-service operation targeting Microsoft 365 users to hijack authenticated sessions after multifactor authentication. By accessing the administrative panel in June, the firm found 5,137 credential records from 461 organizations across 40 countries. The operation harvested 4,148 session cookies and 1,032 plaintext passwords. Specifically, 474 records confirmed completed logins where attackers captured session cookies post-MFA, allowing them to bypass security measures and gain unauthorized access to targeted corporate accounts.
Community Comments
Loading updates...
0