HomeRisk ManagementsBigBear 2 PhaaS Campaign Compromises Over 5,000 Microsoft Credentials

BigBear 2 PhaaS Campaign Compromises Over 5,000 Microsoft Credentials

Published on

spot_img

Phishing-as-a-Service Operation Exposes Thousands of Microsoft 365 Credentials

In a significant cybersecurity development, researchers have identified a new phishing-as-a-service (PhaaS) operation known as Bigbear 2.0, which has reportedly exfiltrated over 5,100 records of Microsoft 365 credentials from unsuspecting victims. This alarming operation is based on the adversary-in-the-middle framework called Evilginx2, as indicated by the research organization CloudSEK.

CloudSEK’s analysts managed to gain administrative access to the Bigbear 2.0 threat actor panel. This access allowed them to monitor traffic from 3,331 unique victim IP addresses spanning more than 40 countries. In their investigation, the team discovered that the panel ran 42 Virtual Private Server (VPS) nodes throughout the lifetime of the campaign. These nodes were primarily hosted by The Constant Company LLC (known as Vultr) and were specifically configured with an "offy" phishlet aimed solely at Microsoft 365 users.

According to Gagan Aggarwal, a researcher at CloudSEK, the operator behind this operation goes by the alias "General Boss." The operator employed various sophisticated techniques, including geo-matched residential proxy pools, real-time exfiltration of information via Telegram, and automated cookie replay mechanisms. These tactics were designed to circumvent Multi-Factor Authentication (MFA) procedures and establish ongoing access to compromised accounts.

CloudSEK’s findings found 5,137 credential records exposed, encompassing 4,148 session cookies, 1,032 plaintext passwords, and 474 authentications where MFA defenses were successfully bypassed. Countries most affected by this phishing operation included India, France, Saudi Arabia, New Zealand, and Germany.

The report further indicates that at least five affiliates are using the Bigbear 2.0 service. These affiliates receive stolen credentials through dedicated bots on Telegram, illustrating a streamlined approach to disseminating acquired sensitive information. The platform employs automation for enhanced user experience; stolen data from phishing pages flows directly into Telegram and into a cookie-replay system, enabling attackers to execute session hijacking quickly.

The Implications of Wider Compromise

Of particular concern is the targeting of IT service providers and managed service firms, which constitute the most affected sector. Aggarwal raises an important point: "IT service providers are high-value targets because they manage client infrastructure; a single compromise can open the door for supply chain attacks affecting numerous downstream clients." Furthermore, IT staff often possess privileged access to Azure Active Directory (AD), on-premises Active Directory, Remote Monitoring and Management (RMM) tools, and password management systems.

Having acquired session cookies, threat actors could theoretically gain access to a range of applications including email, Teams, SharePoint, OneDrive, Entra ID, and other connected Software as a Service (SaaS) offerings. With this level of access, attackers could launch various nefarious activities such as business email compromise (BEC), financial fraud, phishing, data theft, and even the exploitation of additional enterprise systems.

CloudSEK makes several strong recommendations for organizations that may be impacted by this significant security breach. These recommendations include:

  1. Revoking Suspicious Session and Refresh Tokens: Organizations should take immediate action to revoke any tokens that may have been compromised.
  2. Forcing Re-authentication: Users should be prompted to re-authenticate to secure their accounts.
  3. Resetting Compromised Passwords: All passwords suspected to be compromised should be reset without delay.
  4. Adopting Phishing-Resistant Authentication: The organization suggests that businesses implement authentication options like FIDO2 or WebAuthn, which are designed to withstand phishing attempts.
  5. Strengthening Conditional Access Policies: Companies should reevaluate and enhance their conditional access policies and requirements for compliant devices.

The discovery of the Bigbear 2.0 operation highlights the evolving tactics employed by cybercriminals and emphasizes the pressing need for organizations to bolster their cybersecurity frameworks. As threats continue to grow in complexity and scale, awareness and proactive measures become paramount in safeguarding sensitive information against potential breaches.

Source link

Latest articles

What Your Maps Might Be Missing

An OnDemand Webinar from Elastic ...

50% of CISOs View Mythos as a Reason to Leave the Profession

In the rapidly evolving landscape of cybersecurity, the integration of artificial intelligence (AI) into...

Improving AI Returns Through Stronger Foundations

Data Quality and Governance Essential for Scaling AI in Organizations In a landscape increasingly dominated...

Grindr Agrees to £26 Million Settlement in UK Privacy Class Action

Grindr Settles UK Class Action for £26 Million Over Data Privacy Violations In a significant...

More like this

What Your Maps Might Be Missing

An OnDemand Webinar from Elastic ...

50% of CISOs View Mythos as a Reason to Leave the Profession

In the rapidly evolving landscape of cybersecurity, the integration of artificial intelligence (AI) into...

Improving AI Returns Through Stronger Foundations

Data Quality and Governance Essential for Scaling AI in Organizations In a landscape increasingly dominated...