BigBear phishing crew nets thousands of Microsoft 365 credentials
2026-09-08 21:26Cybersecurity🔥 42.2 heat score
1sources
1days unfolding
42.2heat score
4mentions
SummaryAI generated
“Microsoft 365 phishing group BigBear 2.0 is still active, using Evilginx2 man-in-the-middle infrastructure to hijack user logins. The group uses a residential proxy pool covering 69 countries to avoid geographical detection and uses the default “offy” template to intercept login pages and disable FIDO2/WebAuthn authentication through JavaScript. CloudSEK researchers infiltrated its backend management panel and obtained data, showing that the group has captured 5,137 records involving 461 organizations, including 1,032 plaintext passwords, 4,148 session cookies, and 474 complete credentials that can bypass multi-factor authentication (MFA). These stolen credentials and session cookies can be used to access data such as emails, calendars, and SharePoint, and may also be used for lateral movement to Entra ID.”