The commoditization of sophisticated phishing is fueling a surge in credential theft, with the BigBear 2.0 phishing-as-a-service (PhaaS) platform exemplifying the trend. In a recent campaign, the framework successfully bypassed multi-factor authentication (MFA) across 258 organizations, harvesting over 5,000 Microsoft 365 credentials.

At the heart of the attack is a real-time man-in-the-middle technique. Rather than merely harvesting login details, BigBear 2.0 operates as an adversarial proxy. When a user is lured to a fraudulent portal and enters credentials, the kit relays the authentication request directly to Microsoft's legitimate servers. The user then completes their standard MFA challenge, such as approving a push notification, unaware of any compromise.

The critical flaw is exposed at this stage. Because the authentication flows through the attacker's proxy, the kit captures the valid session cookie Microsoft issues upon successful login. This cookie grants access without requiring the user to authenticate again, effectively neutralizing the MFA step against this particular attack vector.

This incident highlights the escalating threat posed by commercialized attack tools. Platforms like BigBear 2.0 package advanced AiTM phishing into subscription-based services, providing turnkey solutions to threat actors. The model dramatically scales attacks, enabling simultaneous campaigns against hundreds of enterprises with minimal technical expertise.

For defenders, this signals a necessary shift in security strategy. The traditional approach of hardening only the login moment is no longer sufficient. Organizations must adopt layered, continuous defense.

The primary recommendation is deploying phishing-resistant authentication. Standards such as FIDO2 and WebAuthn, implemented via security keys or platform authenticators, establish a cryptographic binding between the login and the legitimate domain. This binding prevents AiTM proxies from successfully hijacking the authentication process.

Equally critical are complementary controls. Security teams should enforce stringent conditional access policies—requiring compliant devices, specific applications, or approved locations for resource access—and bolster post-login monitoring. Detecting anomalous activity such as impossible travel or unusual access patterns enables disruption even after a session token has been stolen.

As threat actors productize advanced techniques, the security imperative extends beyond the initial login. Protecting digital identities now demands continuous validation of user session legitimacy and context throughout their entire lifecycle. ```

```yaml

title: "BigBear 2.0 釣魚即服務攻擊繞過 258 家組織的 MFA,竊取逾 5,000 個 Microsoft 365 憑證" date: 2026-09-14 author: HKLUG Team source_url: https://www.bleepingcomputer.com/news/security/bigbear-microsoft-365-phishing-service-bypassed-mfa-at-258-organizations/ tags: [MFA Bypass, Microsoft 365, Phishing-as-a-Service, FIDO2, Conditional Access, Cybersecurity]


精密釣魚攻擊的普及化正催生新一輪憑證竊取潮,BigBear 2.0 釣魚即服務(PhaaS)平台正是典型例子。在一場近期發動的攻擊行動中,此框架成功繞過了 258 家組織的多因素驗證(MFA),竊取了超過 5,000 個 Microsoft 365 帳戶憑證。

此次攻擊的核心在於即時中間人(Man-in-the-Middle)技術。BigBear 2.0 套件並非單純截取登入資訊,而是充當對抗性代理伺服器。被引導至偽造入口網站的用戶輸入憑證後,該套件會將驗證請求直接轉送至 Microsoft 的合法伺服器。用戶隨後照常完成標準 MFA 挑戰,例如批准推送通知,對遭入侵一事渾然不覺。

然而,關鍵漏洞在此暴露。由於驗證過程經過攻擊者的代理伺服器,該套件得以攔截 Microsoft 在驗證成功後發出的有效工作階段 Cookie。此 Cookie 可在無需用戶再次驗證的情況下提供帳戶存取權限,實質上令初始 MFA 步驟在此特定攻擊向量下失效。

這起事件凸顯了商業化攻擊工具日益嚴峻的威脅。BigBear 2.0 等平台將高階 AiTM 釣魚技術包裝為訂閱制服務,為威脅行為者提供現成方案。此模式大幅擴展攻擊規模,使攻擊者能以最少技術專業知識,同時針對數百家企業發動大規模攻擊。

此事件標誌安全策略必須轉變。僅強化登入時刻的傳統模式已不敷所需,組織必須採行分層、持續的防禦方法。

首要建議是部署能抵禦釣魚的驗證機制。FIDO2 與 WebAuthn 等標準透過安全金鑰或平台驗證器實施,在登入憑證與合法網站網域之間建立加密連結。此加密綁定能防止 AiTM 代理伺服器成功劫持驗證過程。

輔助控制措施同樣重要。安全團隊應實施嚴格的條件式存取政策——要求符合規範的裝置、特定應用程式或核准位置才能存取資源——並加強登入後監控。偵測異常活動(如不可能的移動路徑或不尋常的存取模式),即使工作階段 Token 已被竊取,亦能實現攻擊中斷。

隨著威脅行為者將高階技術產品化,安全必要性已超越初始登入環節。保護數碼身份現在要求的是在整個用戶工作階段的存續期間,持續驗證其合法性與情境。


精密釣魚攻擊的商業化正催生新一輪憑證竊取浪潮,BigBear 2.0 釣魚即服務(PhaaS)平台便是明證。在近期一場攻擊行動中,此框架成功繞過 258 間機構的多因素認證(MFA),竊取超過 5,000 個 Microsoft 365 帳戶憑證。

此次攻擊的核心在於即時中間人(Man-in-the-Middle)技術。BigBear 2.0 套件並非單純擷取登入資料,而是充當對抗性代理伺服器。當用戶被誘導至偽造入口網站並輸入憑證時,套件會將驗證請求直接轉送至 Microsoft 的合法伺服器。用戶隨後照常完成標準 MFA 挑戰,例如批准推送通知,對遭入侵一事渾然不覺。

關鍵漏洞在此暴露。由於驗證過程須透過攻擊者的代理伺服器進行,套件得以攔截 Microsoft 在登入成功後發出的有效工作階段 Cookie。此 Cookie 可無需用戶再次驗證便能存取帳戶,實質上令初始 MFA 步驟在此特定攻擊向量下失效。

此事件凸顯商業化攻擊工具日益嚴峻的威脅。BigBear 2.0 等平台將高階 AiTM 釣魚技術包裝為訂閱制服務,為威脅行為者提供現成方案。此模式大幅擴展攻擊規模,使攻擊者能以最少技術專業知識,同時針對數百間企業發動大規模攻擊。

對防禦者而言,此事件標誌安全策略必須轉變。僅強化登入環節的傳統模式已不敷所需,機構必須採行分層、持續的防禦方法。

首要建議是部署能抵禦釣魚的認證機制。FIDO2 與 WebAuthn 等標準透過安全金鑰或平台驗證器實施,在登入憑證與合法網站網域之間建立加密綁定。此綁定能防止 AiTM 代理伺服器成功劫持驗證流程。

輔助控制措施同樣至關重要。安全團隊應實施嚴格的 Conditional Access 政策——要求符合規範的裝置、特定應用程式或核准位置才能存取資源——並加強登入後監控。偵測異常活動(如不可能的移動軌跡或異常存取模式),即使工作階段 Token 已遭竊取,亦能及時中斷攻擊。

隨着威脅行為者將高階技術產品化,安全要務已超越初始登入階段。保護數碼身份現需着重於在整個用戶工作階段生命週期中,持續驗證其合法性與情境。

新聞來源 / Original News Source