BigBear 2 PhaaS Campaign Steals 5000+ Microsoft Credentials
CloudSEK researchers found the BigBear 2.0 PhaaS kit, built on Evilginx2, has stolen over 5,100 Microsoft 365 credentials across 461 organizations in 40+ countries.
CloudSEK gained admin access to the BigBear 2.0 phishing-as-a-service panel, an Evilginx2-based adversary-in-the-middle platform operated by someone using the alias 'General Boss'. The team observed 3,331 unique victim IPs across more than 40 countries, 42 VPS nodes mostly on Vultr, and 5,137 credential records across 461 organizations, including 4,148 session cookies, 1,032 plaintext passwords, and 474 completed MFA-bypassed authentications. IT and managed service providers were the most targeted sector, raising supply-chain risk since their compromise can expose client infrastructure and privileged Azure AD access.
BigBear 2.0 Evilginx2 Phishing Campaign Bypasses Microsoft 365 MFA With Session Cookie Theft
CloudSEK identified BigBear 2.0, an Evilginx2-based AiTM phishing operation stealing Microsoft 365 MFA session cookies, hitting 461 organizations across 40-plus countries.
The campaign proxies Microsoft sign-in pages to capture credentials and authenticated session cookies, enabling session replay into email, Teams, SharePoint, OneDrive, and connected SSO applications. CloudSEK's June 2026 discovery found 5,137 stolen records, 1,032 passwords, and 4,148 session cookies tied to 3,331 victim IPs, linked to operator 'General Boss' across 42 VPS nodes. The operation targeted IT services and managed service providers, used country-matched residential proxies, and involved at least five affiliates.