BigBear 2.0 Evilginx2 Phishing Campaign Bypasses Microsoft 365 MFA With Session Cookie Theft
CloudSEK identified BigBear 2.0, an Evilginx2-based AiTM phishing operation stealing Microsoft 365 MFA session cookies, hitting 461 organizations across 40-plus countries.
The campaign proxies Microsoft sign-in pages to capture credentials and authenticated session cookies, enabling session replay into email, Teams, SharePoint, OneDrive, and connected SSO applications. CloudSEK's June 2026 discovery found 5,137 stolen records, 1,032 passwords, and 4,148 session cookies tied to 3,331 victim IPs, linked to operator 'General Boss' across 42 VPS nodes. The operation targeted IT services and managed service providers, used country-matched residential proxies, and involved at least five affiliates.
- 474 complete authenticated sessions stolen alongside 1,032 passwords
- Victims pushed away from security-key authentication toward phishable MFA
- Defenders urged to revoke sessions and tokens, not just reset passwords
- FIDO2/WebAuthn passkeys recommended as the phishing-resistant control
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| domain | annastudios-paros.com | shing domain Domain ccpipharma[.]com Phishing domain Domain annastudios-paros[.]com Phishing domain Domain dnsforward[.]com Phishing domain D |
| domain | arrmmy.com | omain daengrentacar[.]com Historical phishing domain Domain arrmmy[.]com Historical phishing domain Domain captelind[.]com Histori |
| domain | captelind.com | omain Domain arrmmy[.]com Historical phishing domain Domain captelind[.]com Historical phishing domain Domain planisteradmin[.]com Hi |
| domain | ccpipharma.com | node Domain konceptenterprises[.]com Phishing domain Domain ccpipharma[.]com Phishing domain Domain annastudios-paros[.]com Phishing d |
| domain | cifutura.com | ishing domain Domain dataclust[.]com Phishing domain Domain cifutura[.]com Phishing domain Domain hoaivt[.]com Phishing domain Domai |
| domain | daengrentacar.com | domain Domain soil-management[.]com Phishing domain Domain daengrentacar[.]com Historical phishing domain Domain arrmmy[.]com Historical |
| domain | dataclust.com | omain Domain hotelmidtownsurat[.]com Phishing domain Domain dataclust[.]com Phishing domain Domain cifutura[.]com Phishing domain Dom |
| domain | dnsforward.com | omain Domain annastudios-paros[.]com Phishing domain Domain dnsforward[.]com Phishing domain Domain hotelmidtownsurat[.]com Phishing d |
| domain | dronalms.com | Phishing domain Domain hoaivt[.]com Phishing domain Domain dronalms[.]com Phishing domain Domain virextec[.]com Phishing domain Dom |
| domain | haliotisbar.com | in hnospascualfadon[.]com Historical phishing domain Domain haliotisbar[.]com Historical phishing domain Domain knowncontractor[.]com H |
| domain | hnospascualfadon.com | main planisteradmin[.]com Historical phishing domain Domain hnospascualfadon[.]com Historical phishing domain Domain haliotisbar[.]com Histo |
| domain | hoaivt.com | hishing domain Domain cifutura[.]com Phishing domain Domain hoaivt[.]com Phishing domain Domain dronalms[.]com Phishing domain Dom |
| domain | hotelmidtownsurat.com | shing domain Domain dnsforward[.]com Phishing domain Domain hotelmidtownsurat[.]com Phishing domain Domain dataclust[.]com Phishing domain Do |
| domain | kgsscans.com | n management[.]michaelmarcotte[.]com Phishing domain Domain kgsscans[.]com Phishing domain Domain soil-management[.]com Phishing dom |
| domain | knowncontractor.com | Domain haliotisbar[.]com Historical phishing domain Domain knowncontractor[.]com Historical phishing domain Domain valtteri[.]net Historic |
| domain | konceptenterprises.com | s 45[.]32[.]64[.]165 Historical BigBear 2.0 VPS node Domain konceptenterprises[.]com Phishing domain Domain ccpipharma[.]com Phishing domain D |
| domain | management.daengrentacar.com | domain Domain valtteri[.]net Historical phishing domain URL management[.]daengrentacar[.]com/meetings Observed live Microsoft 365 phishing page File |
| domain | management.michaelmarcotte.com | ing domain Domain rootreseller[.]com Phishing domain Domain management[.]michaelmarcotte[.]com Phishing domain Domain kgsscans[.]com Phishing domain D |
| domain | offtic.com | hishing domain Domain virextec[.]com Phishing domain Domain offtic[.]com Phishing domain Domain rootreseller[.]com Phishing domain |
| domain | planisteradmin.com | in Domain captelind[.]com Historical phishing domain Domain planisteradmin[.]com Historical phishing domain Domain hnospascualfadon[.]com |
| domain | rootreseller.com | Phishing domain Domain offtic[.]com Phishing domain Domain rootreseller[.]com Phishing domain Domain management[.]michaelmarcotte[.]com |
| domain | soil-management.com | hishing domain Domain kgsscans[.]com Phishing domain Domain soil-management[.]com Phishing domain Domain daengrentacar[.]com Historical phi |
| domain | valtteri.net | ain knowncontractor[.]com Historical phishing domain Domain valtteri[.]net Historical phishing domain URL management[.]daengrentacar |
| domain | virextec.com | hishing domain Domain dronalms[.]com Phishing domain Domain virextec[.]com Phishing domain Domain offtic[.]com Phishing domain Domai |
Full article1,197 words · extracted from cybersecuritynews.com · click to collapse
BigBear 2.0 is a phishing operation designed to steal proof that a user has already passed multi-factor authentication.
It targets Microsoft 365 accounts through convincing sign-in links, then takes over the logged-in browser session rather than attempting to break the authentication factor.
The operation is a rebranded Evilginx2 phishing framework that targets Microsoft 365 accounts. Victims are drawn in through email links that open a proxy page resembling a Microsoft sign-in page.
It relays their traffic to the genuine service while quietly collecting credentials and the session data returned after sign-in.
CloudSEK analysts identified BigBear 2.0 in June 2026 after gaining access to its administrative panel. The researchers linked the activity to an operator using the alias General Boss and found a network of 42 virtual private server nodes.
CloudSEK said in a report shared with Cyber Security News (CSN) that the panel held 5,137 stolen records tied to 461 organizations and 3,331 unique victim IP addresses across more than 40 countries.
Of those records, 474 represented complete authenticated sessions, alongside 1,032 passwords and 4,148 session cookies. The records illustrate an operation that collects both immediate account access and material that may support persistent access later.
BigBear 2.0 Evilginx2 Phishing Campaign Bypasses Microsoft 365 MFA
BigBear 2.0 uses an adversary-in-the-middle setup, meaning it sits between the victim and the real Microsoft login service.
It captures the email address and password, lets Microsoft validate the request, and waits for the victim to complete their normal approval or code challenge.
.webp)
When sign-in succeeds, Microsoft sends an authenticated session cookie to the browser. Because the proxy handled the exchange, it can copy that cookie before forwarding the response.
The attacker can replay it in another browser and enter email, Teams, SharePoint, OneDrive, and connected single sign-on applications as the victim. Microsoft 365 session hijacking campaigns have reported the same account-takeover risk.
This is not a weakness in a one-time password, SMS code, or push notification by itself. These methods confirm the user during the live session, but the proxy steals the resulting proof. BigBear used country-matched residential proxies and scripts that pushed users away from security-key authentication.
The campaign particularly affected IT services and managed service providers, a concern because one compromised provider can offer attackers a route into customer environments.
At least five affiliates were linked to the panel. Phishing kits targeting organizations show this service-based model is spreading.
Containing identity compromise
Organizations should treat a suspected stolen cookie as an identity incident, not merely a password problem. Reset affected passwords, revoke active sessions and refresh tokens, and force a new sign-in for impacted accounts.
Teams should examine mailbox forwarding rules, OAuth consent grants, unfamiliar application access, and sign-in activity for evidence that a hijacked session was used after authentication. This review should begin as soon as suspicious activity is reported.
The most useful long-term control is phishing-resistant authentication, especially FIDO2 or WebAuthn security keys and passkeys where properly deployed.
These methods bind a login cryptographically to the genuine site, making a lookalike proxy far less useful. Passkey attack techniques nevertheless deserve ongoing attention.
.webp)
Administrators should require compliant devices through Conditional Access, shorten session lifetimes where appropriate, and watch for unusual residential IP ranges or new browser sessions.
Email filtering should inspect links that imitate sign-in pages even when they use valid certificates. Teams can monitor for the distinctive headers and cookies listed below, because infrastructure can be reassigned.
For users, a familiar Microsoft page and successful MFA prompt do not always prove that a browser is connected directly to Microsoft.
Verify unexpected sign-in requests through a trusted bookmark or known application, not an email link. This concern is reinforced by Evilginx session-cookie attacks, which also depend on real-time relaying rather than stolen passwords alone.
The campaign combined cookie theft, geographic proxy matching, and affiliate access. MFA must be paired with phishing-resistant methods, session controls, and rapid token revocation.
Indicators of compromise (IoCs):-
| Type | Indicator | Description |
|---|---|---|
| IP address | 38[.]60[.]250[.]157 | BigBear 2.0 VPS node |
| IP address | 95[.]179[.]233[.]79 | BigBear 2.0 VPS node |
| IP address | 80[.]240[.]27[.]55 | BigBear 2.0 VPS node |
| IP address | 65[.]20[.]103[.]58 | BigBear 2.0 VPS node |
| IP address | 38[.]54[.]124[.]88 | BigBear 2.0 VPS node |
| IP address | 208[.]85[.]20[.]79 | BigBear 2.0 VPS node |
| IP address | 95[.]179[.]169[.]154 | BigBear 2.0 VPS node |
| IP address | 107[.]191[.]46[.]14 | BigBear 2.0 VPS node |
| IP address | 130[.]94[.]82[.]180 | BigBear 2.0 VPS node |
| IP address | 38[.]54[.]124[.]58 | BigBear 2.0 VPS node |
| IP address | 208[.]85[.]18[.]18 | BigBear 2.0 VPS node |
| IP address | 45[.]32[.]147[.]239 | BigBear 2.0 VPS node |
| IP address | 208[.]76[.]222[.]214 | BigBear 2.0 VPS node |
| IP address | 130[.]94[.]82[.]230 | BigBear 2.0 VPS node |
| IP address | 65[.]20[.]102[.]80 | BigBear 2.0 VPS node |
| IP address | 70[.]34[.]208[.]46 | Historical BigBear 2.0 VPS node |
| IP address | 130[.]94[.]113[.]184 | Historical BigBear 2.0 VPS node |
| IP address | 78[.]141[.]193[.]59 | Historical BigBear 2.0 VPS node |
| IP address | 64[.]176[.]72[.]180 | Historical BigBear 2.0 VPS node |
| IP address | 136[.]244[.]114[.]85 | Historical BigBear 2.0 VPS node |
| IP address | 70[.]34[.]244[.]122 | Historical BigBear 2.0 VPS node |
| IP address | 199[.]247[.]10[.]14 | Historical BigBear 2.0 VPS node |
| IP address | 152[.]39[.]137[.]60 | Historical BigBear 2.0 VPS node |
| IP address | 91[.]245[.]235[.]208 | Historical BigBear 2.0 VPS node |
| IP address | 45[.]32[.]64[.]165 | Historical BigBear 2.0 VPS node |
| Domain | konceptenterprises[.]com | Phishing domain |
| Domain | ccpipharma[.]com | Phishing domain |
| Domain | annastudios-paros[.]com | Phishing domain |
| Domain | dnsforward[.]com | Phishing domain |
| Domain | hotelmidtownsurat[.]com | Phishing domain |
| Domain | dataclust[.]com | Phishing domain |
| Domain | cifutura[.]com | Phishing domain |
| Domain | hoaivt[.]com | Phishing domain |
| Domain | dronalms[.]com | Phishing domain |
| Domain | virextec[.]com | Phishing domain |
| Domain | offtic[.]com | Phishing domain |
| Domain | rootreseller[.]com | Phishing domain |
| Domain | management[.]michaelmarcotte[.]com | Phishing domain |
| Domain | kgsscans[.]com | Phishing domain |
| Domain | soil-management[.]com | Phishing domain |
| Domain | daengrentacar[.]com | Historical phishing domain |
| Domain | arrmmy[.]com | Historical phishing domain |
| Domain | captelind[.]com | Historical phishing domain |
| Domain | planisteradmin[.]com | Historical phishing domain |
| Domain | hnospascualfadon[.]com | Historical phishing domain |
| Domain | haliotisbar[.]com | Historical phishing domain |
| Domain | knowncontractor[.]com | Historical phishing domain |
| Domain | valtteri[.]net | Historical phishing domain |
| URL | management[.]daengrentacar[.]com/meetings | Observed live Microsoft 365 phishing page |
| Filename | cookie.js | File attachment used in the credential-processing workflow |
| Telegram bot | @comeandget_bot | Primary administrator command-and-control bot, revoked |
| Telegram bot token | 8629902848[:]AAGEFRukqwu9QaMSDNNuVRYF3juTcg4ehO4 | Defanged token for revoked primary administrator bot |
| Telegram bot | @botterxyz_bot | Affiliate credential-exfiltration bot |
| Telegram bot token | 8625043408[:]AAH6G8X0aW0QhoLEB1uJiYQ5-2aLSJzg8VE | Defanged affiliate bot token |
| Telegram bot | @PackingitonG_bot | Affiliate credential-exfiltration bot |
| Telegram bot token | 8783369414[:]AAGENRhb7By-0-cQFgrnOw1AW4NbOeUutVE | Defanged affiliate bot token |
| Telegram bot | @donplayer_bot | Affiliate credential-exfiltration bot |
| Telegram bot token | 8807072847[:]AAEYbUaFcbeAgxTZ2Zl8pFbpjRPM9jXvvzE | Defanged affiliate bot token |
| Telegram bot | @bolywan_bot | Affiliate credential-exfiltration bot |
| Telegram bot token | 8462028468[:]AAEQt7oq0c3nTHzApQtHk3RdZ7ifnkYd1XM | Defanged affiliate bot token |
| Telegram bot | @rdsxtdytguyg75d_bot | Affiliate credential-exfiltration bot |
| Telegram bot token | 8794520788[:]AAERSVBlWMpzHc21CCP_-9tL_pjqH9-WuFI | Defanged affiliate bot token |
| HTTP header | x-evg-token | Evilginx-related application header |
| HTTP header | x-evg-server | Evilginx-related application header |
| HTTP header | x-evg-session | Evilginx-related application header |
| Cookie | evginx_session | Evilginx-related session cookie |
| Cookie | evginx_token | Evilginx-related token cookie |
| Cookie | evginx_admin | Evilginx-related administrator cookie |
| Cookie | bigbear_session | BigBear 2.0 session cookie |
| Cookie | bigbear_token | BigBear 2.0 token cookie |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Keep your SOC up to date on active malware & phishing within 24h of their emergence. Try ANYRUN to prevent incidents with early detection.
Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.
Text extracted automatically; images, tables and formatting may be missing. Original: https://cybersecuritynews.com/bigbear-2-0-evilginx2/