BigBear 2.0 Evilginx2 Phishing Campaign Bypasses Microsoft 365 MFA With Session Cookie Theft

BigBear 2.0 is a phishing operation designed to steal proof that a user has already passed multi-factor authentication. It targets Microsoft 365 accounts through convincing sign-in links, then takes over the logged-in browser session rather than attempting to break the authentication factor. The operation is a rebranded Evilginx2 phishing framework that targets Microsoft 365 accounts. […]

This article has been indexed from Cyber Security News

Read the original article: