top of page

This Phishing Kit Waits for You to Finish MFA. Then It Walks In.

Writer: cAIberOps (SY-ber-ops) | MSSP
cAIberOps (SY-ber-ops) | MSSP
4 days ago
5 min read

Most of what your team was taught about phishing assumes the fake login page steals a password. The current generation does something worse: it lets you log in to the real Microsoft page, waits politely while you approve the MFA prompt, and steals the signed-in session itself. Researchers are tracking a live operation doing exactly this to Microsoft 365 users right now, and the most-targeted victims are the IT providers small and medium businesses rely on.

The campaign, in numbers

In June 2026, researchers at CloudSEK identified a phishing-as-a-service operation tracked as BigBear 2.0, built on the Evilginx2 framework and aimed exclusively at Microsoft 365 accounts. By the time of their September report, the operation had targeted 461 organizations, with victims across more than 40 countries, and the single most-targeted sector was IT services and managed service providers, at 151 of those organizations. Attackers go after the providers because one compromised provider opens doors into the clients it manages.

The capture rate is the alarming part: by CloudSEK's count, 80 percent of password entries on the phishing pages resulted in a captured session cookie, and the operation logged more than 5,000 stolen records, including 474 sessions where MFA had been fully completed and bypassed.

How an attack works after MFA

The technique is called adversary in the middle, and it is worth two minutes to understand, because it breaks the mental model most staff have.

The email carries a link to a lookalike domain with a valid security certificate. Clicking it does not open a fake login page. It opens the real Microsoft login, relayed through the attacker's server, which sits invisibly between the user and Microsoft. The user types a real password into what is functionally the real page, approves the real MFA prompt on their phone, and lands in their real inbox. Nothing looks wrong, because nothing visible went wrong. But because every byte passed through the attacker's relay, the attacker now holds the session cookie Microsoft issued after MFA, and replaying that cookie opens the victim's mailbox and files without a password or a prompt.

Every common MFA method falls to this: push approvals, codes from an app, codes over text. The researchers note one exception, hardware-backed passkeys (FIDO2), and this operation's answer to that is blunt: it injects code that disables the passkey option on the page, nudging users back to methods it can capture.

Why the usual defenses have a hard time

The operation is engineered around the defenses, and the CloudSEK report is specific about how. The phishing pages block Microsoft's own telemetry endpoints so the activity is harder to spot from Redmond's side. The sign-in Microsoft eventually records comes from a proxy matched to the victim's own region, so location-based rules see nothing unusual. Scanners and security crawlers get filtered out by an anti-bot check before they ever see the page. And the delivery links use lookalike or compromised domains with valid certificates, which leads to the report's most quotable finding: "Without URL reputation analysis, most email gateways permit these links."

None of this means the built-in protections in Microsoft 365 failed some test. It means this class of attack is purpose-built to route around a single layer of defense, whichever layer that is.

What actually helps

Three things, layered, and honesty requires saying up front that nothing on this list makes adversary-in-the-middle impossible.

First, stop the email earlier. The delivery link is the weakest point of the whole chain, and it is exactly where URL reputation analysis matters, the control the researchers name as the gap in most gateways. Emulation goes a step further and tests how the link actually behaves, not just whether a domain sits on a blocklist.

Second, upgrade the MFA that can be upgraded. Hardware-backed passkeys resist this technique by design, because the credential is bound to the real domain and will not fire on a relay. Not every account and workflow supports them yet, but the owner's account and the bookkeeper's account should be first in line.

Third, watch what happens after the click. A stolen session gets used: strange sign-ins, new mailbox rules, unusual sends. Catching that quickly is the difference between one compromised mailbox and a wire-fraud incident, and it requires something watching, in the account layer and on the machines.

Where we fit

Email security is what we sell, so weigh this section accordingly, but every item below maps to the attack above. Our Managed Email Security is built on Check Point Harmony Email and Collaboration, and it deploys through an API behind Microsoft's own filtering, as a second and different layer that attackers cannot see from the outside, since mail routing never changes. Its anti-phishing engines inspect the link, the language, the metadata, and the history between sender and recipient, which is aimed at exactly the pattern lookalike-domain mail presents. Unknown links go through URL emulation, which addresses exactly the gateway gap the researchers describe, and unknown attachments are detonated in a sandbox while a cleaned copy is delivered. Check Point's platform also offers account takeover detection that flags suspicious sign-in activity, which matters precisely because this attack begins after a successful login, and confirming what a given deployment includes is part of our onboarding. And on day one it runs a retroactive scan of existing mailboxes, so a new client learns quickly whether something like this campaign already arrived.

Around that platform is the part a tool cannot do: a named engineer watches the dashboard and acts on what it flags, rather than a ticket queue hoping someone reads it. When something does get through, our Managed Endpoint Protection (powered by SentinelOne) is the layer on the machines. For teams that want to go further, we offer security awareness training built on the attack patterns actually seen in your own organization, and dark web monitoring that alerts when staff credentials show up exposed, the safety net for exactly the aftermath this campaign produces.

Check Point reports its email layer cuts phishing reaching the inbox by 99.2 percent for organizations using it. That is the vendor's number, and we will not promise perfection on top of it. What we promise is the layer, and a person watching it.

The honest part

If your business runs on Microsoft 365, this campaign is aimed at businesses shaped like yours, and no single product ends the risk. The defense is unglamorous: filter the delivery, harden the MFA that can be hardened, watch the aftermath, and have someone accountable for responding. In our experience, many small and medium businesses are missing most of the four. Two of them cost a conversation, not money.

The question worth asking this week

Not "would our people click." Some day, someone will. Ask the after question: if a session were stolen from one of your mailboxes today, what would notice, and who would act?

We work with small and medium businesses nationwide from our home base in McLean, Virginia. If you are in Washington DC, Northern Virginia, Maryland, or anywhere in the country and the honest answer is "nothing, and nobody," book a free 15-minute call. We will show you what our email layer flags in a typical week, and what it found on day one for mailboxes like yours.

Comments


bottom of page