A commercial "phishing-as-a-service" platform has enabled widespread multi-factor authentication (MFA) bypass, compromising over 5,000 Microsoft 365 accounts across 258 organizations. The attack, detailed in a report from BleepingComputer, highlights the failure of conventional MFA methods against evolving, real-time threats and has sparked urgent calls for a security overhaul.
The attacker utilized a PhaaS framework named BigBear 2.0 to deploy adversary-in-the-middle (AiTM) attacks. This technique moves beyond credential theft. An AiTM proxy sits between the user and the legitimate login service, relaying the authentication exchange in real time. It captures the session cookie after MFA is successfully completed, allowing the attacker to hijack the active session. This renders time-based codes, SMS passcodes, and simple push notifications ineffective, as the attacker piggybacks on the authenticated session as it's created.
The campaign’s scale—orchestrated through a turnkey service—underscores the industrialization of cybercrime. PhaaS platforms like BigBear 2.0 lower the technical barrier, enabling attackers to launch sophisticated, high-volume campaigns without deep expertise. Consequently, organizations relying on standard MFA are operating with a false sense of security.
The report states that the industry's defense must now prioritize protocols that cryptographically bind authentication to the legitimate service domain. The primary recommendation is a strategic shift to FIDO2/WebAuthn standards. Typically implemented via hardware security keys or platform passkeys, these methods are inherently phishing-resistant because the cryptographic challenge is tied directly to the genuine website, defeating relay proxies.
For Hong Kong IT and security teams, the incident is a direct signal to review and harden identity governance. The mitigation path forward is multi-layered. The core action is planning a phased deployment of phishing-resistant authentication, prioritizing privileged and high-risk accounts. This must be accompanied by stricter security policies, including conditional access controls that evaluate sign-in risk based on device compliance, location, and impossible travel. Enhanced monitoring for anomalous session activity and known AiTM signatures is also critical.
Ultimately, the BigBear campaign demonstrates that legacy authentication is insufficient against modern threats. Transitioning to phishing-resistant protocols is no longer an optional upgrade but a foundational requirement for protecting cloud-based enterprise identities.
一個商業化「釣魚平台服務」導致大規模多重驗證被繞過,影響258個機構超過5,000個Microsoft 365帳戶。據BleepingComputer報導詳述,這次攻擊凸顯傳統多重驗證方法面對不斷演變的即時威脅時失效,並引發對安全改革的緊急呼籲。
攻擊者利用名為BigBear 2.0的釣魚平台服務框架部署中間人攻擊。這項技術超越了單純的憑證竊取——中間人代理伺服器位居用戶與合法登錄服務之間,即時轉傳驗證交換過程。它在多重驗證成功完成後擷取工作階段Cookie,使攻擊者能劫持當前工作階段。這令基於時間的驗證碼、簡訊驗證碼及簡單推送通知失效,因為攻擊者可在認證工作階段建立時進行搭載。
這次行動透過即選即用服務策劃,其規模突顯了網絡犯罪的工業化。像BigBear 2.0這樣的釣魚平台服務降低了技術門檻,使攻擊者無需深厚專業知識即可發動複雜、高量的攻擊行動。因此,依賴標準多重驗證的機構實際上處於虛假的安全感中。
報告指出,業界現時必須優先採用能將驗證以密碼學方式綁定到合法服務網域的協議。首要建議是策略性轉向FIDO2/WebAuthn標準。這些方法通常透過硬件安全密鑰或平台通行密鑰實現,因密碼學挑戰直接與真實網站綁定,從而固有地具備防釣魚特性,能擊敗中間人代理伺服器。
對香港資訊科技及安全團隊而言,此事件直接提示需檢視及加強身份治理。緩解路徑須多層次進行。核心行動是規劃分階段部署防釣魚驗證機制,優先處理特權及高風險帳戶。同時必須實施更嚴格的安全策略,包括根據設備合規性、地理位置及異常旅行評估登錄風險的條件式存取控制。強化監測異常工作階段活動及已知的中間人攻擊特徵亦至關重要。
最終,BigBear行動證明傳統驗證機制已不足以應對現代威脅。過渡到防釣魚協議不再是可選的升級,而是保護雲端企業身份認證的基本要求。
