BigBear 2.0 Microsoft 365 phishing campaign
Campaign
Summary
Hide ▲
Show ▼
The BigBear 2.0 phishing campaign is bypassing MFA to steal Microsoft 365 credentials from 258 organizations, putting account sessions and cloud data at risk. The operation uses an Evilginx2-based AiTM flow to intercept passwords and authenticated session cookies after victims complete login. It has already produced more than 5,000 credential records and affected 3,331 unique victim IPs across 40+ countries.
Related Happenings
UNC7005 (Storm-2945) targeted OAuth and WhatsApp phishing campaign
Campaign
H score16
First: 20.08.2026 22:59
Last: 20.08.2026 22:59
Sources 1
About this happening:
A UNC7005 (Storm-2945) campaign is hijacking accounts with OAuth, WhatsApp linking, and device-code phishing across academia, diplomatic, nonprofit, and Euro...
UNC7005 (Storm-2945) targeted OAuth and WhatsApp phishing campaign
CampaignAbout this happening: A UNC7005 (Storm-2945) campaign is hijacking accounts with OAuth, WhatsApp linking, and device-code phishing across academia, diplomatic, nonprofit, and Euro...
Greatness PhaaS expands into device code phishing and integrated token-theft operations
Threat Actor Meta
H score40
First: 04.08.2026 20:27
Last: 04.08.2026 20:27
Sources 1
About this happening:
Greatness PhaaS has added device code phishing, expanding its crimeware panel into a broader token-theft ecosystem that makes MFA bypass easier for customers targe...
Greatness PhaaS expands into device code phishing and integrated token-theft operations
Threat Actor MetaAbout this happening: Greatness PhaaS has added device code phishing, expanding its crimeware panel into a broader token-theft ecosystem that makes MFA bypass easier for customers targe...
LogoKit real-time per-victim phishing campaign
Campaign
H score35
First: 29.07.2026 19:00
Last: 29.07.2026 19:00
Sources 1
About this happening:
The LogoKit phishing-as-a-service campaign now builds a unique login page per victim in real time, making credential theft harder to detect and block. It uses live scree...
LogoKit real-time per-victim phishing campaign
CampaignAbout this happening: The LogoKit phishing-as-a-service campaign now builds a unique login page per victim in real time, making credential theft harder to detect and block. It uses live scree...
Kratos ecosystem shift changes threat-actor operations
Threat Actor Meta
H score39
First: 22.07.2026 02:07
Last: 22.07.2026 02:07
Sources 1
About this happening:
The Kratos phishing-as-a-service ecosystem was dismantled after it scaled to more than 1,800 criminal customers, exposing a subscription model that drove roughly 15,000...
Kratos ecosystem shift changes threat-actor operations
Threat Actor MetaAbout this happening: The Kratos phishing-as-a-service ecosystem was dismantled after it scaled to more than 1,800 criminal customers, exposing a subscription model that drove roughly 15,000...
Forg365 PhaaS industrializes Microsoft 365 credential theft and session hijacking
Threat Actor Meta
H score36
First: 13.07.2026 16:03
Last: 13.07.2026 16:03
Sources 1
About this happening:
Forg365 has emerged as a subscription-based phishing platform that lowers the barrier to Microsoft 365 account theft while scaling session hijacking and mailbox ab...
Forg365 PhaaS industrializes Microsoft 365 credential theft and session hijacking
Threat Actor MetaAbout this happening: Forg365 has emerged as a subscription-based phishing platform that lowers the barrier to Microsoft 365 account theft while scaling session hijacking and mailbox ab...
Timeline
-
07.09.2026 18:39 2 articles · 1h ago
BigBear 2.0 bypasses MFA at 258 organizations
Initial DisclosureResearchers at CloudSEK identified BigBear 2.0 as a phishing-as-a-service operation using an Evilginx2-based adversary-in-the-middle flow to intercept passwords and authenticated session cookies after victims completed multi-factor authentication. The service was configured around 42 VPS nodes targeting Microsoft 365, used custom JavaScript to interfere with FIDO2/WebAuthn, and relied on geo-matched residential proxies to reduce authentication alerts. CloudSEK assessed that the panel had exfiltrated 5,137 credential records, including 474 complete MFA-bypassed authentications, 1,032 plaintext passwords, and 4,148 session cookies, affecting 258 distinct organizations and 3,331 unique victim IPs across 40+ countries while the operation remained active.
Show sources
- BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations — www.bleepingcomputer.com — 07.09.2026 18:39
- BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations — www.bleepingcomputer.com — 07.09.2026 18:39