How the Scam Works Mechanically
The BigBear 2.0 platform operates as a sophisticated phishing-as-a-service (PhaaS), providing cybercriminals with the tools to conduct highly effective attacks against Microsoft 365 users. At its core, BigBear utilizes a technique known as an adversary-in-the-middle (AiTM) attack, often powered by frameworks like Evilginx2. This method involves setting up a reverse proxy that sits between the victim and Microsoft's legitimate authentication servers. When a user attempts to log in, their credentials and session cookies are intercepted by the attacker's proxy. Crucially, this AiTM setup can capture the multi-factor authentication (MFA) codes or tokens as well, effectively bypassing these crucial security layers. The stolen credentials and session cookies are then replayed by the attacker through an API, allowing them to hijack the victim's authenticated session. To further evade detection, BigBear employs custom JavaScript to disable advanced authentication methods like FIDO2/WebAuthn, forcing users towards less secure authentication processes. Additionally, the service leverages geo-matched residential proxies, making the malicious traffic appear to originate from the victim's actual geographic location, thus avoiding suspicion from security systems.
Warning Signs & Red Flags
- Unexpected login prompts for Microsoft 365 services, especially if they appear outside of your normal workflow.
- Requests for credentials or MFA codes that seem unusual or are not prompted by a direct action you initiated.
- Websites that look legitimate but have slightly altered URLs or are not using HTTPS correctly (though sophisticated phishing can mimic these perfectly).
- Emails or messages urging immediate action to verify an account or prevent service interruption, often with a sense of urgency.
- Any attempt to disable or circumvent multi-factor authentication, even if it's presented as a convenience or a troubleshooting step.
- Unusual browser behavior or prompts related to authentication methods like FIDO2/WebAuthn being disabled.
How to Protect Yourself & Report
Protecting yourself from advanced phishing threats like those orchestrated by BigBear requires vigilance and robust security practices. Always be skeptical of unsolicited login requests and verify the legitimacy of any communication before entering credentials. Ensure your Microsoft 365 accounts are protected with phishing-resistant MFA methods, such as FIDO2 security keys or authenticator apps, and avoid SMS-based MFA where possible. Organizations should enforce the use of managed devices and implement Conditional Access policies that add extra layers of security. If you suspect you have encountered a phishing attempt or have fallen victim, immediately reset your Microsoft 365 password, revoke any active sessions, and report the incident to your IT security team or Microsoft. For reporting phishing attempts, you can often use the 'Report Phishing' feature within your email client or report it directly to Microsoft and relevant cybersecurity authorities.