ZeroHour
Cyber Security Newspublished ()ingested Tushar Subhra Dutta1

BigBear 2.0 Evilginx2 Phishing Campaign Bypasses Microsoft 365 MFA With Session Cookie Theft

highPhishing & fraud exploited in the wildimportance 74
AI summary · glm-5.3-flash

CloudSEK identified BigBear 2.0, an Evilginx2-based AiTM phishing operation stealing Microsoft 365 MFA session cookies, hitting 461 organizations across 40-plus countries.

The campaign proxies Microsoft sign-in pages to capture credentials and authenticated session cookies, enabling session replay into email, Teams, SharePoint, OneDrive, and connected SSO applications. CloudSEK's June 2026 discovery found 5,137 stolen records, 1,032 passwords, and 4,148 session cookies tied to 3,331 victim IPs, linked to operator 'General Boss' across 42 VPS nodes. The operation targeted IT services and managed service providers, used country-matched residential proxies, and involved at least five affiliates.

  • 474 complete authenticated sessions stolen alongside 1,032 passwords
  • Victims pushed away from security-key authentication toward phishable MFA
  • Defenders urged to revoke sessions and tokens, not just reset passwords
  • FIDO2/WebAuthn passkeys recommended as the phishing-resistant control

Indicators of compromiseAll →

TypeIndicatorContext
domainannastudios-paros.comshing domain Domain ccpipharma[.]com Phishing domain Domain annastudios-paros[.]com Phishing domain Domain dnsforward[.]com Phishing domain D
domainarrmmy.comomain daengrentacar[.]com Historical phishing domain Domain arrmmy[.]com Historical phishing domain Domain captelind[.]com Histori
domaincaptelind.comomain Domain arrmmy[.]com Historical phishing domain Domain captelind[.]com Historical phishing domain Domain planisteradmin[.]com Hi
domainccpipharma.comnode Domain konceptenterprises[.]com Phishing domain Domain ccpipharma[.]com Phishing domain Domain annastudios-paros[.]com Phishing d
domaincifutura.comishing domain Domain dataclust[.]com Phishing domain Domain cifutura[.]com Phishing domain Domain hoaivt[.]com Phishing domain Domai
domaindaengrentacar.comdomain Domain soil-management[.]com Phishing domain Domain daengrentacar[.]com Historical phishing domain Domain arrmmy[.]com Historical
domaindataclust.comomain Domain hotelmidtownsurat[.]com Phishing domain Domain dataclust[.]com Phishing domain Domain cifutura[.]com Phishing domain Dom
domaindnsforward.comomain Domain annastudios-paros[.]com Phishing domain Domain dnsforward[.]com Phishing domain Domain hotelmidtownsurat[.]com Phishing d
domaindronalms.comPhishing domain Domain hoaivt[.]com Phishing domain Domain dronalms[.]com Phishing domain Domain virextec[.]com Phishing domain Dom
domainhaliotisbar.comin hnospascualfadon[.]com Historical phishing domain Domain haliotisbar[.]com Historical phishing domain Domain knowncontractor[.]com H
domainhnospascualfadon.commain planisteradmin[.]com Historical phishing domain Domain hnospascualfadon[.]com Historical phishing domain Domain haliotisbar[.]com Histo
domainhoaivt.comhishing domain Domain cifutura[.]com Phishing domain Domain hoaivt[.]com Phishing domain Domain dronalms[.]com Phishing domain Dom
domainhotelmidtownsurat.comshing domain Domain dnsforward[.]com Phishing domain Domain hotelmidtownsurat[.]com Phishing domain Domain dataclust[.]com Phishing domain Do
domainkgsscans.comn management[.]michaelmarcotte[.]com Phishing domain Domain kgsscans[.]com Phishing domain Domain soil-management[.]com Phishing dom
domainknowncontractor.comDomain haliotisbar[.]com Historical phishing domain Domain knowncontractor[.]com Historical phishing domain Domain valtteri[.]net Historic
domainkonceptenterprises.coms 45[.]32[.]64[.]165 Historical BigBear 2.0 VPS node Domain konceptenterprises[.]com Phishing domain Domain ccpipharma[.]com Phishing domain D
domainmanagement.daengrentacar.comdomain Domain valtteri[.]net Historical phishing domain URL management[.]daengrentacar[.]com/meetings Observed live Microsoft 365 phishing page File
domainmanagement.michaelmarcotte.coming domain Domain rootreseller[.]com Phishing domain Domain management[.]michaelmarcotte[.]com Phishing domain Domain kgsscans[.]com Phishing domain D
domainofftic.comhishing domain Domain virextec[.]com Phishing domain Domain offtic[.]com Phishing domain Domain rootreseller[.]com Phishing domain
domainplanisteradmin.comin Domain captelind[.]com Historical phishing domain Domain planisteradmin[.]com Historical phishing domain Domain hnospascualfadon[.]com
domainrootreseller.comPhishing domain Domain offtic[.]com Phishing domain Domain rootreseller[.]com Phishing domain Domain management[.]michaelmarcotte[.]com
domainsoil-management.comhishing domain Domain kgsscans[.]com Phishing domain Domain soil-management[.]com Phishing domain Domain daengrentacar[.]com Historical phi
domainvaltteri.netain knowncontractor[.]com Historical phishing domain Domain valtteri[.]net Historical phishing domain URL management[.]daengrentacar
domainvirextec.comhishing domain Domain dronalms[.]com Phishing domain Domain virextec[.]com Phishing domain Domain offtic[.]com Phishing domain Domai
Full article1,197 words · extracted from cybersecuritynews.com · click to collapse

BigBear 2.0 is a phishing operation designed to steal proof that a user has already passed multi-factor authentication.

It targets Microsoft 365 accounts through convincing sign-in links, then takes over the logged-in browser session rather than attempting to break the authentication factor.

The operation is a rebranded Evilginx2 phishing framework that targets Microsoft 365 accounts. Victims are drawn in through email links that open a proxy page resembling a Microsoft sign-in page.

It relays their traffic to the genuine service while quietly collecting credentials and the session data returned after sign-in.

CloudSEK analysts identified BigBear 2.0 in June 2026 after gaining access to its administrative panel. The researchers linked the activity to an operator using the alias General Boss and found a network of 42 virtual private server nodes.

CloudSEK said in a report shared with Cyber Security News (CSN) that the panel held 5,137 stolen records tied to 461 organizations and 3,331 unique victim IP addresses across more than 40 countries.

Of those records, 474 represented complete authenticated sessions, alongside 1,032 passwords and 4,148 session cookies. The records illustrate an operation that collects both immediate account access and material that may support persistent access later.

BigBear 2.0 Evilginx2 Phishing Campaign Bypasses Microsoft 365 MFA

BigBear 2.0 uses an adversary-in-the-middle setup, meaning it sits between the victim and the real Microsoft login service.

It captures the email address and password, lets Microsoft validate the request, and waits for the victim to complete their normal approval or code challenge.

Campaign Timeline (Source - CloudSEK)
Campaign Timeline (Source – CloudSEK)

When sign-in succeeds, Microsoft sends an authenticated session cookie to the browser. Because the proxy handled the exchange, it can copy that cookie before forwarding the response.

The attacker can replay it in another browser and enter email, Teams, SharePoint, OneDrive, and connected single sign-on applications as the victim. Microsoft 365 session hijacking campaigns have reported the same account-takeover risk.

This is not a weakness in a one-time password, SMS code, or push notification by itself. These methods confirm the user during the live session, but the proxy steals the resulting proof. BigBear used country-matched residential proxies and scripts that pushed users away from security-key authentication.

The campaign particularly affected IT services and managed service providers, a concern because one compromised provider can offer attackers a route into customer environments.

At least five affiliates were linked to the panel. Phishing kits targeting organizations show this service-based model is spreading.

Containing identity compromise

Organizations should treat a suspected stolen cookie as an identity incident, not merely a password problem. Reset affected passwords, revoke active sessions and refresh tokens, and force a new sign-in for impacted accounts.

Teams should examine mailbox forwarding rules, OAuth consent grants, unfamiliar application access, and sign-in activity for evidence that a hijacked session was used after authentication. This review should begin as soon as suspicious activity is reported.

The most useful long-term control is phishing-resistant authentication, especially FIDO2 or WebAuthn security keys and passkeys where properly deployed.

These methods bind a login cryptographically to the genuine site, making a lookalike proxy far less useful. Passkey attack techniques nevertheless deserve ongoing attention.

Phishlet sample (Source - CloudSEK)
Phishlet sample (Source – CloudSEK)

Administrators should require compliant devices through Conditional Access, shorten session lifetimes where appropriate, and watch for unusual residential IP ranges or new browser sessions.

Email filtering should inspect links that imitate sign-in pages even when they use valid certificates. Teams can monitor for the distinctive headers and cookies listed below, because infrastructure can be reassigned.

For users, a familiar Microsoft page and successful MFA prompt do not always prove that a browser is connected directly to Microsoft.

Verify unexpected sign-in requests through a trusted bookmark or known application, not an email link. This concern is reinforced by Evilginx session-cookie attacks, which also depend on real-time relaying rather than stolen passwords alone.

The campaign combined cookie theft, geographic proxy matching, and affiliate access. MFA must be paired with phishing-resistant methods, session controls, and rapid token revocation.

Indicators of compromise (IoCs):-

TypeIndicatorDescription
IP address38[.]60[.]250[.]157BigBear 2.0 VPS node
IP address95[.]179[.]233[.]79BigBear 2.0 VPS node
IP address80[.]240[.]27[.]55BigBear 2.0 VPS node
IP address65[.]20[.]103[.]58BigBear 2.0 VPS node
IP address38[.]54[.]124[.]88BigBear 2.0 VPS node
IP address208[.]85[.]20[.]79BigBear 2.0 VPS node
IP address95[.]179[.]169[.]154BigBear 2.0 VPS node
IP address107[.]191[.]46[.]14BigBear 2.0 VPS node
IP address130[.]94[.]82[.]180BigBear 2.0 VPS node
IP address38[.]54[.]124[.]58BigBear 2.0 VPS node
IP address208[.]85[.]18[.]18BigBear 2.0 VPS node
IP address45[.]32[.]147[.]239BigBear 2.0 VPS node
IP address208[.]76[.]222[.]214BigBear 2.0 VPS node
IP address130[.]94[.]82[.]230BigBear 2.0 VPS node
IP address65[.]20[.]102[.]80BigBear 2.0 VPS node
IP address70[.]34[.]208[.]46Historical BigBear 2.0 VPS node
IP address130[.]94[.]113[.]184Historical BigBear 2.0 VPS node
IP address78[.]141[.]193[.]59Historical BigBear 2.0 VPS node
IP address64[.]176[.]72[.]180Historical BigBear 2.0 VPS node
IP address136[.]244[.]114[.]85Historical BigBear 2.0 VPS node
IP address70[.]34[.]244[.]122Historical BigBear 2.0 VPS node
IP address199[.]247[.]10[.]14Historical BigBear 2.0 VPS node
IP address152[.]39[.]137[.]60Historical BigBear 2.0 VPS node
IP address91[.]245[.]235[.]208Historical BigBear 2.0 VPS node
IP address45[.]32[.]64[.]165Historical BigBear 2.0 VPS node
Domainkonceptenterprises[.]comPhishing domain
Domainccpipharma[.]comPhishing domain
Domainannastudios-paros[.]comPhishing domain
Domaindnsforward[.]comPhishing domain
Domainhotelmidtownsurat[.]comPhishing domain
Domaindataclust[.]comPhishing domain
Domaincifutura[.]comPhishing domain
Domainhoaivt[.]comPhishing domain
Domaindronalms[.]comPhishing domain
Domainvirextec[.]comPhishing domain
Domainofftic[.]comPhishing domain
Domainrootreseller[.]comPhishing domain
Domainmanagement[.]michaelmarcotte[.]comPhishing domain
Domainkgsscans[.]comPhishing domain
Domainsoil-management[.]comPhishing domain
Domaindaengrentacar[.]comHistorical phishing domain
Domainarrmmy[.]comHistorical phishing domain
Domaincaptelind[.]comHistorical phishing domain
Domainplanisteradmin[.]comHistorical phishing domain
Domainhnospascualfadon[.]comHistorical phishing domain
Domainhaliotisbar[.]comHistorical phishing domain
Domainknowncontractor[.]comHistorical phishing domain
Domainvaltteri[.]netHistorical phishing domain
URLmanagement[.]daengrentacar[.]com/meetingsObserved live Microsoft 365 phishing page
Filenamecookie.jsFile attachment used in the credential-processing workflow
Telegram bot@comeandget_botPrimary administrator command-and-control bot, revoked
Telegram bot token8629902848[:]AAGEFRukqwu9QaMSDNNuVRYF3juTcg4ehO4Defanged token for revoked primary administrator bot
Telegram bot@botterxyz_botAffiliate credential-exfiltration bot
Telegram bot token8625043408[:]AAH6G8X0aW0QhoLEB1uJiYQ5-2aLSJzg8VEDefanged affiliate bot token
Telegram bot@PackingitonG_botAffiliate credential-exfiltration bot
Telegram bot token8783369414[:]AAGENRhb7By-0-cQFgrnOw1AW4NbOeUutVEDefanged affiliate bot token
Telegram bot@donplayer_botAffiliate credential-exfiltration bot
Telegram bot token8807072847[:]AAEYbUaFcbeAgxTZ2Zl8pFbpjRPM9jXvvzEDefanged affiliate bot token
Telegram bot@bolywan_botAffiliate credential-exfiltration bot
Telegram bot token8462028468[:]AAEQt7oq0c3nTHzApQtHk3RdZ7ifnkYd1XMDefanged affiliate bot token
Telegram bot@rdsxtdytguyg75d_botAffiliate credential-exfiltration bot
Telegram bot token8794520788[:]AAERSVBlWMpzHc21CCP_-9tL_pjqH9-WuFIDefanged affiliate bot token
HTTP headerx-evg-tokenEvilginx-related application header
HTTP headerx-evg-serverEvilginx-related application header
HTTP headerx-evg-sessionEvilginx-related application header
Cookieevginx_sessionEvilginx-related session cookie
Cookieevginx_tokenEvilginx-related token cookie
Cookieevginx_adminEvilginx-related administrator cookie
Cookiebigbear_sessionBigBear 2.0 session cookie
Cookiebigbear_tokenBigBear 2.0 token cookie

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Keep your SOC up to date on active malware & phishing within 24h of their emergence. Try ANYRUN to prevent incidents with early detection.

Tushar Subhra Dutta

Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.

Text extracted automatically; images, tables and formatting may be missing. Original: https://cybersecuritynews.com/bigbear-2-0-evilginx2/