BigBear 2.0 phishing campaign hijacks Microsoft 365 sessions after MFA

He recommended disabling or containing the affected account, revoking Entra sign-in sessions and refresh tokens, and forcing reauthentication.

[…Keep reading]

BigBear 2.0 phishing campaign hijacks Microsoft 365 sessions after MFA

BigBear 2.0 phishing campaign hijacks Microsoft 365 sessions after MFA

He recommended disabling or containing the affected account, revoking Entra sign-in sessions and refresh tokens, and forcing reauthentication. Incident responders should then examine Microsoft 365 logs for evidence of mailbox access, malicious inbox rules, unusual OAuth consent, newly registered MFA devices, privilege changes, and access to other cloud applications.

Tyagi cautioned that IP location may provide limited reassurance in such investigations because residential proxies can make attacker activity appear geographically consistent with the legitimate user. Responders should instead focus on reconstructing what occurred during the compromised session, he said.

Investigators should also determine whether the stolen session was used to reach other employees, customers, or external contacts, Prabhu added.

About Author

What do you feel about this?

Subscribe To InfoSec Today News

You have successfully subscribed to the newsletter

There was an error while trying to send your request. Please try again.

World Wide Crypto will use the information you provide on this form to be in touch with you and to provide updates and marketing.