BigBear 2.0 phishing campaign hijacks Microsoft 365 sessions after MFA

Summary

A phishing-as-a-service operation dubbed BigBear 2.0 has been discovered targeting Microsoft 365 users, successfully hijacking authenticated sessions even after multi-factor authentication (MFA) has been completed. The operation utilizes a framework that intercepts session cookies, allowing attackers to reuse legitimate sessions without re-authentication and bypass location-based security checks.

IFF Assessment

FOE

This campaign demonstrates a sophisticated method for attackers to bypass MFA and hijack user sessions, posing a significant threat to organizations.

Defender Context

Defenders need to be aware of sophisticated phishing campaigns that can bypass MFA by stealing session cookies. This technique, particularly when combined with residential proxies, can weaken location-based security controls. Organizations should consider implementing additional security measures and user training to mitigate the risk of session hijacking.

Read Full Story →