BigBear phishing crew nets thousands of Microsoft 365 credentials
Researchers got inside the crooks' admin panel and found 5,137 stolen records tied to 461 organizations
A Microsoft 365 phishing operation targeting hundreds of organizations captured thousands of passwords and session cookies, including hundreds of authenticated sessions that could be hijacked to bypass MFA, according to researchers who accessed the crooks' own admin panel.
Security researchers at CloudSEK say they accessed the admin panel behind BigBear 2.0, an Evilginx2-based phishing-as-a-service operation targeting Microsoft 365 users, giving them an unusually detailed look at the campaign and its haul.
According to the researchers, the panel contained 5,137 records associated with 461 organizations, including 1,032 plaintext passwords and 4,148 session cookies. CloudSEK classified 474 records as complete MFA-bypassed authentications in which the attackers captured an authenticated Microsoft 365 session.
That potentially hands the crooks much more than an inbox. A hijacked Microsoft 365 account can expose email, calendars, Teams conversations, and files stored...
Copyright of this story solely belongs to www.theregister.com. To see the full text click HERE