A phishing-as-a-service (PhaaS) platform known as BigBear 2.0 has compromised 258 organizations worldwide, bypassing multi-factor authentication (MFA) to steal over 5,000 Microsoft 365 credentials. The attack demonstrates how standardized phishing kits now routinely defeat common MFA protections, posing a severe risk for enterprises in Hong Kong’s Microsoft 365-heavy business environment.
Researchers documented the campaign, detailed in a report on September 12, showing how the BigBear 2.0 service lowers the skill barrier for cybercriminals to execute advanced adversary-in-the-middle (AitM) phishing attacks. This model moves beyond password theft, instead targeting the authenticated session itself.
The attack works by presenting victims with a realistic, proxy-enabled login page. When a user enters their credentials and completes a second authentication step—such as an authenticator app code—the fraudulent site doesn't just steal the password. It intercepts the resulting session token. Attackers then use this hijacked cookie to gain direct access to the account, rendering the original MFA step ineffective.
The emergence of such scalable PhaaS tools represents a critical evolution in cyber threats. As security analysts note, capabilities once exclusive to sophisticated threat groups are now available to a broader range of attackers, making widespread MFA bypass a commodity service.
The campaign's scale, hitting 258 distinct organizations, underscores the operational threat to sectors like finance and professional services that depend on Microsoft 365. A single compromised account can lead to business email fraud, data exfiltration, and further network infiltration.
In response, security experts argue that defense strategies must evolve beyond relying on MFA as a finish line. Effective protection now requires securing the entire authentication session. Recommended priorities include migrating high-risk users to phishing-resistant standards like FIDO2, which use cryptographic challenges that cannot be intercepted by proxies.
Furthermore, organizations are urged to implement conditional access policies that assess risk signals—like device compliance and impossible travel logins—to flag hijacked sessions. Continuous monitoring for anomalous post-authentication activity, such as a token used from an unexpected location, is now considered a vital detective control.
The BigBear 2.0 campaign makes clear that combating modern phishing requires layered defenses. Protecting credentials is no longer sufficient; organizations must actively defend the integrity of the authenticated session from start to finish.
名為BigBear 2.0的釣魚即服務(PhaaS)平台已入侵全球258個機構,繞過多重驗證(MFA)並竊取逾5,000組Microsoft 365登入憑證。此次攻擊顯示,標準化釣魚工具組現已能常規化突破常見的MFA防護,對香港普遍採用Microsoft 365的商業環境構成嚴重威脅。
研究人員於9月12日發表報告詳述此次攻擊行動,指出BigBear 2.0服務如何降低網絡罪犯執行高級中間人(AitM)釣魚攻擊的技術門檻。此模式已超越傳統密碼竊取,轉而針對已通過驗證的會話本身。
攻擊手法透過向受害者展示具備代理功能的仿造登入頁面運作。當用戶輸入憑證並完成第二步驗證(如驗證器應用程式的驗證碼)時,惡意網站不僅竊取密碼,更會攔截產生的會話代幣。攻擊者隨後利用此劫持的Cookie直接存取帳戶,使原始MFA機制形同虛設。
這類可規模化PhaaS工具的出現,代表網絡威脅的重大演進。如安全分析師所指出,過去僅限高級威脅組織使用的技術,現已普及至更廣泛的攻擊者群體,使大規模繞過MFA成為常見的攻擊服務。
此次攻擊波及258個不同機構,突顯對依賴Microsoft 365的金融及專業服務等行業構成的營運威脅。單一帳戶被入侵可能導致商業電郵詐騙、數據外洩及進一步的網絡滲透。
對此,安全專家認為防禦策略必須進化,不能僅依賴MFA作為安全防線。現時有效保護需確保整個驗證會話的安全。建議優先事項包括將高風險用戶遷移至具備防釣魚功能的FIDO2標準,其採用無法被代理截獲的加密挑戰機制。
此外,強烈建議機構實施條件式存取政策,評估設備合規性與不可能旅行紀錄等風險信號,以標記遭劫持的會話。持續監控驗證後的異常活動(如代幣從意外位置使用)現被視為關鍵的偵測性控制措施。
BigBear 2.0行動明確顯示,對抗現代化釣魚攻擊需採用多層防禦。單純保護憑證已不足夠;機構必須主動捍衛從開始到結束整個驗證會話的完整性。
