AuraTracer智迹闻
中文

EVENT DOSSIER

BigBear phishing crew nets thousands of Microsoft 365 credentials

2026-09-08 21:26 Cybersecurity 🔥 42.2 heat score
1sources
1days unfolding
42.2heat score
4mentions
SummaryAI generated

“Microsoft 365 phishing group BigBear 2.0 is still active, using Evilginx2 man-in-the-middle infrastructure to hijack user logins. The group uses a residential proxy pool covering 69 countries to avoid geographical detection and uses the default “offy” template to intercept login pages and disable FIDO2/WebAuthn authentication through JavaScript. CloudSEK researchers infiltrated its backend management panel and obtained data, showing that the group has captured 5,137 records involving 461 organizations, including 1,032 plaintext passwords, 4,148 session cookies, and 474 complete credentials that can bypass multi-factor authentication (MFA). These stolen credentials and session cookies can be used to access data such as emails, calendars, and SharePoint, and may also be used for lateral movement to Entra ID.”

Related eventsRELATED EVENTS
Key entitiesKEY ENTITIES
BigBearCloudSEKGagan AggarwalMicrosoft

Coverage · reports per dayLANGUAGE SPLIT

Entity relations
BigBear × CloudSEK1BigBear × Gagan Aggarwal1BigBear × Microsoft1CloudSEK × Gagan Aggarw…1CloudSEK × Microsoft1Gagan Aggarwal × Micros…1

SignalsSIGNALS

Keyword heat
  • Microsoft1
  • CloudSEK1
  • BigBear1
  • Gagan Aggarwal1

All reports (1)SOURCES

T The Register en 2026-09-08 21:26

BigBear phishing crew nets thousands of Microsoft 365 credentials

微软 365 钓鱼团伙 BigBear 2.0 捕获数千条凭证及会话 Cookie,其中包含可绕过多因素认证(MFA)的数百个已认证会话。CloudSEK 研究人员通过入侵其后台管理面板获取了详细数据:涉及 461 家组织,记录数达 5,137 条,含 1,032 个明文密码和 4,148 个会话 Cookie,其中 474 条为完整 MFA 绕过认证。该团伙利用 Evilginx2 基础设施作为中间人代理,劫持会话 Cookie 以访问邮件、日历及 SharePoint 等数据,并可能横向移动至 Entra ID。此操作仍在运行,默认模板"offy"专门拦截微软 365 登录,并通过 JavaScript 禁用 FIDO2/WebAuthn 认证,同时使用覆盖 69 个国家的住宅代理池以规避地理检测。基础设…