Summary
- CloudSEK says BigBear 2.0 targets Microsoft 365 through an Evilginx2-based phishing-as-a-service platform.
- Researchers gained access to its administration panel and observed stolen credentials and authenticated-session cookies.
- Captured session cookies can let attackers reuse a session created after the victim successfully completes MFA.
A phishing-as-a-service operation targeting Microsoft 365 has collected thousands of credentials and authenticated-session cookies, according to researchers who obtained access to the platform’s attacker administration panel.
CloudSEK says the operation, which it tracks as BigBear 2.0, uses Evilginx2-based adversary-in-the-middle infrastructure to intercept Microsoft 365 authentication sessions rather than relying solely on stolen passwords.
The researchers identified the campaign in June and later gained access to its administration interface. CloudSEK says the platform managed dozens of virtual private servers during its lifecycle and was configured specifically to target Microsoft 365 authentication.
The company says BigBear 2.0 has targeted hundreds of organisations across more than 100 countries and that the panel contained thousands of stolen credentials and session cookies.
The session-cookie theft is the key distinction from conventional phishing. An adversary-in-the-middle service operates as a proxy between the victim and the legitimate Microsoft login page. Credentials and authentication traffic pass through infrastructure controlled by the attacker before reaching Microsoft.
A victim can therefore enter the correct password and complete a multi-factor authentication challenge while the proxy captures the authenticated session produced afterwards.
The presence of MFA does not mean the control has failed. It has authenticated the user correctly. The problem is that the attacker may obtain the session artefact created after that successful authentication and replay it to inherit the victim’s access.
CloudSEK says the BigBear configuration is designed to capture Microsoft 365 session cookies after authentication and that the operation has recorded a high rate of session-token collection from victims who reached the relevant stage.
Microsoft 365 identities are particularly valuable because one compromised cloud session can expose several services. Depending on permissions, the same account may provide access to email, Teams, SharePoint, files, and other connected applications.
A criminal using a legitimate authenticated session can then search mailboxes, gather information about internal operations, impersonate the account holder, or attempt further compromise without presenting an obviously invalid password.
Phishing-as-a-service makes that capability available beyond operators able to build the infrastructure themselves. A service provider can maintain the proxy framework, domains, hosting, certificates, and control panel while affiliates concentrate on identifying targets and distributing lures.
The model resembles other parts of the cybercrime economy in which specialised capability is separated from the operators who ultimately use it.
The campaign also reinforces the difference between MFA adoption and phishing resistance. Authentication methods that rely on credentials and reusable session state can still be exposed to real-time interception, while phishing-resistant authentication technologies are designed to make credential replay considerably harder.
Session theft also changes detection. A login may begin with legitimate credentials and an approved MFA event, leaving defenders to identify anomalies in what happens after authentication rather than depending only on failed login attempts.
CloudSEK’s access to the attacker panel provides unusually direct visibility into the operation. The researchers were able to examine the infrastructure, affiliate model, and captured authentication data rather than infer the campaign solely from phishing domains.
BigBear 2.0 therefore represents both an identity-security problem and a service-economy problem: tooling designed to industrialise the interception of Microsoft 365 sessions and make a sophisticated phishing technique available as a repeatable criminal service.





