BigBear 2.0 phishing campaign hijacks Microsoft 365 sessions after MFA
He recommended disabling or containing the affected account, revoking Entra sign-in sessions and refresh tokens, and forcing reauthentication.
BigBear 2.0 phishing campaign hijacks Microsoft 365 sessions after MFA
He recommended disabling or containing the affected account, revoking Entra sign-in sessions and refresh tokens, and forcing reauthentication. Incident responders should then examine Microsoft 365 logs for evidence of mailbox access, malicious inbox rules, unusual OAuth consent, newly registered MFA devices, privilege changes, and access to other cloud applications.
Tyagi cautioned that IP location may provide limited reassurance in such investigations because residential proxies can make attacker activity appear geographically consistent with the legitimate user. Responders should instead focus on reconstructing what occurred during the compromised session, he said.
Investigators should also determine whether the stolen session was used to reach other employees, customers, or external contacts, Prabhu added.
