A large-scale phishing campaign leveraging a Phishing-as-a-Service (PhaaS) platform successfully bypassed multi-factor authentication (MFA) defenses at 258 organizations, resulting in the theft of over 5,000 Microsoft 365 credentials. The attacks were enabled by a tool called BigBear 2.0, which automates sophisticated adversary-in-the-middle (AitM) techniques.
Reported by BleepingComputer, the BigBear 2.0 framework acts as a turnkey service, significantly lowering the technical barrier for executing advanced session hijacking. Attackers deploy convincing replicas of Microsoft login portals. When users enter their credentials, the platform doesn't just steal them; it proxies the entire authentication session in real-time. Most critically, it intercepts the session token generated after a successful MFA challenge, giving attackers direct access to the compromised account without needing to bypass the second factor itself.
This incident highlights how advanced attack methodologies are becoming commoditized. Capabilities once requiring significant expertise are now available as subscription services, enabling widespread and scalable assaults. The direct theft of session tokens renders many standard MFA implementations ineffective for the duration of that session, potentially granting attackers access to sensitive emails, documents, and data.
The findings are a critical alert for IT teams, particularly in data-sensitive regions like Hong Kong, that standard MFA is not a silver bullet. Methods relying on SMS, phone calls, or push notifications are inherently vulnerable to these real-time proxy attacks. Defending the Microsoft 365 environment requires moving beyond initial authentication to a layered, zero-trust posture.
Effective hardening measures must address the entire session lifecycle. Organizations should urgently review their identity policies, focusing on controls that can prevent token theft or detect its abuse post-compromise. The shift is from a single gate-check to continuous validation of user and device trust throughout a session.
一場利用釣魚即服務(PhaaS)平台的大型釣魚攻擊活動,成功繞過了258間組織的多因素認證(MFA)防禦,導致超過5,000組Microsoft 365登入憑證被竊。這次攻擊使用了名為BigBear 2.0的工具,該工具自動化了複雜的中間人(AitM)攻擊技術。
據BleepingComputer報導,BigBear 2.0框架充當「即用型」服務,大幅降低了執行先進會話劫持的技術門檻。攻擊者部署了逼真的Microsoft登入門戶複製品。當用戶輸入其憑證時,該平台不僅僅是竊取它們;它還即時代理了整個認證會話。最關鍵的是,它能攔截在成功完成MFA挑戰後生成的會話令牌,使攻擊者無需繞過第二重認證因素本身,即可直接訪問被入侵的帳戶。
此事件突顯了先進攻擊方法論如何日益商品化。過去需要相當專業知識的能力,現在可作為訂閱服務獲取,從而促成廣泛且可擴展的攻擊。直接竊取會話令牌使得許多標準的MFA實現在該會話期間失效,可能讓攻擊者得以訪問敏感的電子郵件、文件和數據。
這些發現對IT團隊,特別是位於像香港這樣數據敏感地區的團隊,是一個關鍵警示:標準的MFA並非萬靈丹。依賴短訊、電話或推送通知的方法,在本質上容易受到這類即時代理攻擊。保護Microsoft 365環境需要超越初始認證,採取分層式、零信任的安全態勢。
有效的加固措施必須涵蓋整個會話生命週期。各組織應緊急檢討其身份驗證策略,專注於能夠防止令牌竊取或在入侵後檢測濫用的控制措施。轉變方向是從單次閘口檢查,轉變為在整個會話期間對用戶和設備信任的持續驗證。
