Skip to content

Leadership1 publisher3 min readPublished

Session cookies outnumber plaintext passwords four to one in BigBear 2.0's panel

CloudSEK got inside the BigBear 2.0 administrative panel and found more captured Microsoft 365 session cookies than plaintext passwords, along with code written to switch FIDO2 off on the phishing pages.

The Board Room · Leadership desk

Illustration accompanying Session cookies outnumber plaintext passwords four to one in BigBear 2.0's panel

What happened

  • CloudSEK said it uncovered the BigBear 2.0 phishing service in June after getting into its administrative panel, which held 5,137 credential records tied to 461 organizations in more than 40 countries.
  • Of those records, 474 showed a completed login in which the attacker captured the authenticated session Microsoft created after the victim finished multifactor authentication.
  • IT services and managed service providers accounted for 151 of the organizations in the data, the most heavily represented sector CloudSEK identified.

Compiled by The Board RoomSomething wrong?How this is made

Why it matters

  • exposure One replayed session belonging to a managed service provider's staff reaches the customer environments and administrative systems that provider holds privileged access to, and the data set is weighted toward those firms.
  • decision Identity owners have to settle whether phishing-resistant methods are enforced or merely offered beside OTP and push, since the operation strips the strong option out of the page when it can.
  • constraint Token protection cannot be procured as a finished answer, because Grover's caution about coverage across platforms, clients and workloads means part of the estate stays reachable after the purchase.
  • precedent With at least five affiliates sharing one panel, post-MFA session theft is now something an unskilled buyer rents, so defenders should expect the technique in commodity campaigns, not targeted ones.

The panel's confirmed post-MFA captures are a fraction of its records: 474 against 5,137 credential records [4][2], about one in eleven [2]. That is a fraction of victims, but the number is enough to retire the assumption that a completed prompt certifies the session behind it. Keith Prabhu, founder and CEO of Confidis, said successful MFA should no longer be treated as proof that an account or session remains secure [14]. Akshat Tyagi, associate practice leader at HFS Research, said OTP, SMS and push-based MFA should not be relied on as standalone defenses against this type of attack, because the attacker can let the legitimate user complete authentication before stealing the resulting session [20].

CloudSEK's numbers are weighted toward session material anyway. The firm counted 4,148 captured session cookies against 1,032 plaintext passwords [3], four cookies for every password [1]. Evilginx2 is what makes that possible: an attacker-controlled reverse proxy sits between the victim and Microsoft's legitimate authentication service, and once Microsoft issues the authenticated session cookie the phishing infrastructure can intercept it and reuse the session without completing authentication again [5]. Sakshi Grover, senior research manager for cybersecurity products and services at IDC Asia Pacific, said session cookies and access and refresh tokens should be treated as high-value authentication material rather than technical artifacts behind the password [18].

Custom code in the same panel complicates the reading that only token controls matter. Researchers found code on the phishing pages designed to disable FIDO2/WebAuthn, potentially steering users toward weaker, phishable authentication methods [7]. The code was written on purpose. The straightforward read is that the strong factor was an obstacle worth engineering around. Tyagi said enterprises should enforce phishing-resistant authentication such as FIDO2/WebAuthn passkeys and not simply make it available alongside weaker alternatives [15]. Prabhu pointed to Windows Hello for Business and certificate-based authentication as further options, with stronger methods enforced through Conditional Access authentication strengths [16].

Packaging is the change Tyagi identifies. "What BigBear 2.0 changes is accessibility and scale," Tyagi said [12]. "It packages AiTM phishing, residential proxies and automated cookie replay into a service that lowers the expertise needed to run these attacks" [13]. CloudSEK observed 42 virtual private server nodes over the campaign, with 26 deleted from the panel since late July [9], leaving 16 [3].

Token protection alone does not close this gap. Grover said organizations should use Continuous Access Evaluation and token protection where Microsoft 365 supports them, but cautioned against treating token protection as a complete solution because coverage varies across platforms, clients and workloads [17]. The location signal is degraded as well: the operation selects residential proxies according to the victim's country, which CloudSEK said can weaken location-based checks used in Conditional Access policies [6]. Grover said many enterprise controls are geared toward detecting credential theft. They are not built to catch the hijacking of an already authenticated session [19].

IT services and managed service providers were 151 of the 461 organizations CloudSEK identified [10][2], about a third of them [4], and CloudSEK said employees at such organizations may hold privileged access to customer environments and administrative systems [11]. The Conditional Access configuration is the immediate decision. The clients and workloads where token protection does not reach are the consequence, because a replayed session still works there [17].

What to watch

  • Whether Microsoft extends token protection coverage to the clients and workloads Grover said it does not reach.
  • Whether follow-up research finds more than five affiliate operators, or new VPS nodes replacing the 26 deleted since late July.
  • Whether FIDO2-disabling code shows up as a standard feature in other phishing-as-a-service panels.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories