A new cyberattack tool called BigBear 2.0 has been found to compromise Microsoft 365 accounts even when two-factor authentication (MFA) is in place. The tool does not directly break MFA, but instead waits for the user to approve the authentication step, then steals the session cookie from Microsoft’s servers. This cookie allows the attacker to access the account without needing to re-authenticate. Security researchers at CloudSEK discovered a vast network of cybercriminals using this tool, with activity spanning 40 countries and over 250 organizations affected.
BigBear 2.0 uses a technique known as "Adversary-in-the-Middle" (AiTM) phishing, which involves tricking users into entering their credentials on a fake website that mimics the real Microsoft login page. Once the user inputs their email and password, the tool forwards the request to Microsoft’s servers, allowing the user to complete the MFA step. At this point, the attacker captures session cookies—digital tokens that prove the user has already authenticated—and uses them to access the account without needing the user’s credentials again.
CloudSEK’s analysis revealed that 5,137 Microsoft 365 accounts were compromised using this method, including 463 in France. The data collected included 1,032 passwords, 4,148 session cookies, and 474 successful logins that bypassed MFA. These findings highlight the effectiveness of the tool in bypassing modern security measures, even when users have enabled MFA.
While BigBear 2.0 can bypass some MFA methods, it does not mean that MFA should be abandoned. However, not all MFA methods are equally secure. Methods like TOTP (time-based one-time passwords), SMS, and push notifications verify that the user has the second factor but do not confirm the website’s legitimacy. More secure options like FIDO2 and WebAuthn, which rely on physical security keys or passkeys, are less vulnerable to AiTM attacks because they are tied to the actual service domain.
CloudSEK also found that BigBear 2.0 includes JavaScript designed to disable WebAuthn in the browser, forcing users to fall back to less secure authentication methods. This underscores the importance for businesses to disable easily bypassed backup authentication methods. If an account is compromised, simply changing the password may not be enough, as attackers may still have active session cookies or refresh tokens. Companies should also revoke these tokens and force re-authentication, especially for high-value accounts.
Cybersecurity Firm Reveals Extent of Microsoft 365 Account Compromises via BigBear 2.0 Phishing Tool
AI-rewritten from original reportingHow it works
mfaphishingbigbearcloudsekmicrosoft365cybersecurity



