BigBear 2 PhaaS Campaign Steals 5000+ Microsoft Credentials
BigBear 2.0 is a phishing-as-a-service kit that tricks Microsoft 365 users into entering their login details on fake Microsoft pages. Attackers use this to steal credentials and gain access to accounts.
- Report priority
- Medium
- Targets
- Microsoft
How it works
- Attackers set up fake Microsoft 365 login pages that look real.
- When users enter their email and password, the site sends those details to the attackers instead of Microsoft.
- This happens when someone clicks a link in a phishing email or message that leads to the fake page.
What to do
If you clicked a Microsoft 365 login link in an email or message and entered your password, check your Microsoft 365 account for any unusual activity, like unknown sign-ins or changed settings. If you suspect you entered your password on a fake page, reset your password immediately via the official Microsoft login page.
If you entered your password on a fake page, and reset your password right away. Enable multi-factor authentication in your Microsoft 365 account to add extra security. Report phishing emails to Microsoft via their Phishing Reporting Center.
Technical details
Attackers send phishing emails pretending to be from Microsoft Support. The email includes a link to a fake Microsoft 365 login page. When a victim clicks the link and enters their credentials, the attackers capture those details.
CloudSEK has uncovered BigBear 2.0, a new phishing-as-a-service operation targeting Microsoft 365