BigBear 2.0 AiTM Service Bypasses Microsoft 365 MFA by Stealing Session Cookies
CloudSEK researchers published findings on September 7, 2026, detailing BigBear 2.0, a high-severity Adversary-in-the-Middle phishing service targeting Microsoft 365 users. The service uses Evilginx2 to clone Microsoft login pages and injects JavaScript to disable WebAuthn and FIDO2 authentication, nudging victims toward weaker MFA methods like TOTP, SMS, or push notifications. Acting as a real-time proxy, it relays stolen credentials and MFA responses to legitimate Microsoft servers, then captures session cookies to maintain persistent unauthorized access. Attackers reuse these cookies via residential proxies to access emails, files, and accounts, and may follow up with inbox rule creation, OAuth consent abuse, or internal phishing. Organizations can defend against this threat by enforcing phishing-resistant MFA policies, applying device-based Conditional Access controls, and immediately revoking sessions and tokens upon detecting a compromise.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in