BigBear 2.0 AiTM Phishing: How Microsoft 365 Sessions Are Hijacked After MFA

September 25, 2026

By: Gunupuru Siva Prasad

Security Analyst

What organizations need to know about BigBear 2.0, session cookie theft, warning signs, business risk, and recommended Microsoft 365 security controls.

What Is the BigBear 2.0 Microsoft 365 Phishing Campaign?

BigBear 2.0 is a sophisticated phishing-as-a-service (PhaaS) platform, targeting Microsoft 365 users through Adversary-in-the-Middle (AiTM) attacks.

Unlike traditional credential theft campaigns, BigBear captures authenticated session cookies after users successfully complete Multi-Factor Authentication (MFA). This allows threat actors to take over Microsoft 365 sessions without requiring additional authentication.

The campaign has reportedly impacted 258 organizations globally, highlighting the growing threat posed by session hijacking attacks against cloud environments.

It is also not an isolated event. BigBear 2.0 is the latest entry in a run of Microsoft 365 phishing kits built around the same session-theft mechanic, following Forg365 phishing-as-a-service and the Axios and Salty 2FA MFA bypass kits our team tracked earlier this year.

How Does BigBear 2.0 Hijack Microsoft 365 Sessions?

BigBear 2.0 is a Microsoft 365-focused phishing framework built on the Evilginx2 AiTM infrastructure. Attackers place a malicious proxy between the user and Microsoft’s sign-in service to capture login data in real time.

Key Findings from the BigBear 2.0 Campaign
  • Successful compromise of 258 organizations across more than 40 countries.
  • Theft of 5,137 credential records, including:
    • 4,148 authenticated Microsoft 365 session cookies.
    • 1,032 plain text passwords.
    • 474 confirmed MFA-authenticated sessions.
  • Use of 42 VPS nodes dedicated to Microsoft 365 phishing operations.
  • Use of geo-matched residential proxies to make attacker sign-ins appear consistent with the victim’s location, reducing the likelihood of triggering location-based security controls.
  • Custom JavaScript is designed to interfere with phishing-resistant authentication methods such as FIDO2 and WebAuthn.

What Is the BigBear 2.0 Attack Lifecycle?

  1. Victim receives a phishing email impersonating a Microsoft 365 login request.
  2. The user is redirected to an AiTM phishing page controlled by the attacker.
  3. Credentials and MFA responses are relayed to Microsoft’s legitimate authentication service.
  4. Upon successful authentication, the attacker captures the authenticated session cookie.
  5. The stolen cookie is replayed to access the victim’s Microsoft 365 account without requiring MFA again.
  6. The hijacked session can then be used to access email, files, Teams chats, and connected cloud applications.

BigBear 2.0 MITRE ATT&CK Techniques

  • T1566 – Phishing
  • T1557 – Adversary-in-the-Middle
  • T1056 – Input Capture
  • T1539 – Steal Web Session Cookie
  • T1090 – Proxy
  • 004 – Valid Cloud Accounts
  • T1114 – Email Collection
  • T1530 – Data from Cloud Storage

What BigBear 2.0 Indicators and Tactics Should Organizations Monitor?

The researchers did not publicly release specific domains, IP addresses, or file hashes associated with the campaign. However, organizations should monitor the following behavioral indicators:

  • Suspicious Microsoft 365 sign-ins following successful MFA events.
  • Session activity originating from residential proxy services.
  • Unusual mailbox forwarding rules or inbox rule creation.
  • OAuth application consent grants that were not previously authorized.
  • Unexpected downloads from SharePoint Online or OneDrive.
  • Sign-ins flagged as impossible travel, atypical travel, or unfamiliar sign-in properties.

Why Is BigBear 2.0 a Risk to Microsoft 365 Security?

This campaign demonstrates that MFA alone may not fully protect cloud accounts against modern AiTM phishing attacks. By targeting authenticated session cookies instead of bypassing MFA directly, attackers can gain access to Microsoft 365 environments while appearing as legitimate users. Successful compromises may lead to email account takeover, data theft, business email compromise (BEC), unauthorized access to cloud applications, and broader organizational exposure.

Identity is now the primary attack surface for cloud-first organizations and it needs the same layered treatment the network perimeter once got. That is the operating principle behind our cybersecurity services.

How Can Organizations Defend Against BigBear 2.0 AiTM Phishing?

  • Deploy phishing-resistant authentication methods such as FIDO2 security keys or passkeys.
  • Review Microsoft Entra ID sign-in logs for token replay and suspicious authenticated sessions.
  • Revoke active sessions and reset credentials if suspicious account activity is identified.
  • Enforce Conditional Access policies requiring compliant devices and risk-based authentication controls.
  • Monitor for unusual mailbox rules, OAuth application grants, and large cloud storage downloads.
  • Conduct user awareness training focused on AiTM phishing techniques and fake Microsoft login pages.
  • Block known phishing infrastructure and review indicators shared by trusted threat intelligence providers.

A structured Microsoft 365 security assessment will surface which of these gaps are live in your tenant today, and a Microsoft Zero Trust assessment maps the Conditional Access architecture needed to make token theft far less useful to an attacker.


Cyber threats never sleep neither do we. ProArch SOC protects you 24/7.

Explore ProArch SOC Services