Microsoft 365 Under Siege: Fake IT Support Calls and Phishing Campaigns Bypass MFA to Steal Credentials
Microsoft 365 users are currently in the crosshairs of a sophisticated, multi-pronged cyberattack wave. Threat actors are combining old-school social engineering—like fake IT help desk phone calls—with cutting-edge phishing-as-a-service (PhaaS) frameworks to bypass multi-factor authentication (MFA) and hijack enterprise accounts. The ultimate goal of this hacking spree is credential theft and data exfiltration, targeting businesses across the globe with a specific focus on US-based sectors.
Security researchers at CloudSEK and Arctic Wolf have independently tracked these campaigns, revealing a complex web of affiliates and overlapping infrastructure. The attacks are not just about stealing passwords; they are about intercepting authenticated session cookies to completely bypass MFA protections, granting cybercriminals unfettered access to sensitive corporate data stored in Outlook, Teams, SharePoint, and OneDrive. This represents a significant escalation in the ongoing battle for enterprise cybersecurity.
The Anatomy of the Attack: Social Engineering Meets Phishing-as-a-Service
The attack methodology observed in these campaigns is a chilling blend of human manipulation and technical sophistication. The initial vector often involves a phone call, a Microsoft Teams message, or an email. The attacker poses as a member of the organization's IT help desk, claiming there is a critical issue with the user's account or device that requires immediate attention. This social engineering tactic is designed to create a sense of urgency and lower the victim's defenses.
Once the conversation is underway, the "IT support" agent guides the user down one of two paths. The first involves convincing the victim to grant remote access to their machine, ostensibly to fix the problem. The second, and more prevalent, method directs the user to a spoofed Microsoft 365 login page. Here, the victim is prompted to enter their username, password, and the all-important 2FA code. Unbeknownst to the user, this fake page is a sophisticated trap built to harvest every piece of information they type.
BigBear 2.0: The AiTM Proxy Framework Fueling the Fire
At the heart of this credential-harvesting operation is a powerful PhaaS framework known as BigBear 2.0. This tool is a game-changer in the world of hacking, as it utilizes an attacker-in-the-middle (AiTM) proxy. This proxy sits between the victim and the legitimate Microsoft infrastructure, capturing not only the username and password but also the MFA code and the authenticated session cookie. By replaying these stolen credentials and cookies through an API, the attacker can essentially hijack a legitimate authentication session without needing to break the MFA mechanism itself.
CloudSEK’s analysis of the BigBear 2.0 campaign reveals a staggering scale of operation. The researchers noted that the PhaaS panel is leased to at least five affiliate operators, who use live Telegram bots to exfiltrate stolen credentials in real-time. The campaign has been remarkably successful, with CloudSEK reporting that BigBear 2.0 was used to exfiltrate more than 5,000 credential records. This includes 474 complete MFA-bypassed authentications, 1,032 plaintext passwords, and 4,148 session cookies, affecting 3,331 unique victim IPs across more than 40 countries. The operation was still active at the time of the report, highlighting the persistent nature of this threat.
PREY-0058: A Blurred Line Between Threat Actors
While CloudSEK focused on the infrastructure, Arctic Wolf’s researchers tracked a specific threat actor they have dubbed PREY-0058. This group is responsible for a significant portion of the attacks, but the investigation reveals a complex landscape. Despite significant overlaps in techniques, technologies, and procedures (TTPs) with other collectives, PREY-0058 is not simply a rebrand of an older organization. Instead, the researchers believe the lines between these groups are heavily blurred. There appears to be a large pool of affiliates, splinter crews, and other cohorts all using the same phishing infrastructure, which often confuses defenders and security analysts trying to attribute attacks.
This shared infrastructure makes it difficult to track individual groups but also presents a unique opportunity for defenders. By identifying and disrupting the common tools—like the BigBear 2.0 framework—security teams can potentially dismantle the operations of multiple threat actors at once. The focus of these attacks is primarily on data theft rather than ransomware deployment, with attackers showing a clear preference for quietly exfiltrating sensitive information from corporate cloud services.
Targeted Industries and the Data Breach Impact
The campaigns have targeted a wide array of organizations, with a specific focus on US-based businesses. According to Arctic Wolf, the primary sectors under attack include construction and engineering, healthcare and pharmaceuticals, real estate and property management, finance, and professional services. These industries often hold valuable intellectual property, financial data, and personal health information, making them prime targets for data breach attempts.
CloudSEK’s data further underscores the severity of the threat, revealing that the campaign targeted 461 organizations, of which 258 had at least one set of credentials compromised. The attackers are not just collecting data; they are actively harvesting it from Outlook emails, SharePoint document libraries, and OneDrive folders. This level of access allows for extensive corporate espionage and can lead to significant financial and reputational damage for the affected companies.
Defending Against MFA Bypass and Phishing Attacks
In light of these sophisticated attacks, the researchers stress that traditional MFA is no longer a silver bullet. The AiTM proxy technique effectively neutralizes standard 2FA codes, as they are captured and replayed in real-time. To combat this, organizations must implement more robust security measures. The primary recommendation is the deployment of phishing-resistant MFA. Unlike standard codes, phishing-resistant methods like passkeys, YubiKeys, and other FIDO2/WebAuthn-based authentication cryptographically tie the authentication request to the legitimate website. This means the authentication cannot be simply forwarded to an attacker, effectively neutralizing the AiTM proxy.
Beyond hardware keys, organizations are advised to implement Conditional Access policies to restrict access based on user location, device compliance, and risk signals. Restricting the scope of data that users can access via SharePoint and other services can also limit the blast radius of a compromised account. Furthermore, employee education remains a critical defense. Users must be trained to recognize the signs of social engineering, such as unsolicited IT support calls, and to verify any request for credentials through a separate, trusted channel.
Arctic Wolf also suggests that defenders can disrupt this activity by detecting anomalous residential-proxy token replay, unusual SharePoint discovery and bulk access patterns, and mailbox harvesting activities. Monitoring for newly registered authentication-themed lure infrastructure can also provide early warning signs of an impending campaign.
Conclusion: The Evolution of Credential Theft
The recent campaigns against Microsoft 365 users represent a significant evolution in the cybersecurity threat landscape. The combination of social engineering, PhaaS frameworks like BigBear 2.0, and AiTM proxies has made it easier than ever for cybercriminals to bypass MFA and infiltrate corporate networks. The focus on data exfiltration rather than ransomware suggests a shift toward stealthy, long-term espionage. For security researchers and IT professionals, the key takeaway is clear: relying on standard MFA is no longer sufficient. Adopting phishing-resistant authentication methods, implementing robust conditional access policies, and fostering a culture of security awareness are essential steps to defend against these sophisticated hacking campaigns. The battle for your credentials is ongoing, and the attackers are more organized and equipped than ever before.