BigBear 2.0 phishing campaign hijacks Microsoft 365 sessions after MFA
A phishing-as-a-service operation targeting Microsoft 365 users has harvested thousands of session cookies that could be used to hijack authenticated sessions after victims complete multifactor authentication, CloudSEK said. The cybersecurity firm said in a report that it uncovered the operation, known as BigBear 2.0, in June after gaining access to its administrative panel. The panel contained…
A phishing campaign known as BigBear 2.0 has been stealing Microsoft 365 session cookies, potentially allowing attackers to hijack authenticated sessions after victims complete multi-factor authentication, according to a report by CloudSEK. The operation, which targeted more than 40 countries across 461 organizations, harvested 4,148 session cookies and 1,032 plaintext passwords.
The phishing-as-a-service campaign, built on Evilginx2, intercepts authenticated session cookies issued after MFA to enable unauthorized access. Researchers found that the operation also disables FIDO2/WebAuthn authentication on phishing pages, potentially steering users towards weaker authentication methods. Enterprises need to move beyond protecting the authentication event itself and consider stolen session cookies and access and refresh tokens as high-value authentication material.
Phishing-resistant authentication methods, such as FIDO2/WebAuthn passkeys, should be enforced as primary defenses against this type of attack.
Written by urgent.news from Computerworld's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.