Threat reportPhishingTL-2026-2374
BigBear 2.0 Evilginx2 Phishing-as-a-Service Campaign Targeting Microsoft 365 with MFA Bypass
BigBear 2.0 Evilginx2 Phishing-as-a-Service Campaign (TL-2026-2374), also tracked as BigBear, is a critical-severity phishing campaign, first published 2026-09-07 and last reviewed 2026-09-08. It is attributed to General Boss with medium confidence, affects Microsoft Microsoft 365 (Exchange Online, Teams, SharePoint, OneDrive, maps to 22 MITRE ATT&CK techniques (T1056.003, T1059.007, T1071.001), and is covered by 9 detection rules and 44 indicators of compromise.
- Severity
- CRITICALAssessed severity
- CVEs
- 0None referenced
- Techniques
- 22MITRE ATT&CK
- Actors
- 1General Boss
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 44Indicators of compromise
Key facts for TL-2026-2374
- Threat ID
- TL-2026-2374
- Also known as
- BigBear, BigBear 2.0, BigBear 2.0 PhaaS
- Severity
- CRITICAL
- Status
- ACTIVE
- Category
- PHISHING
- First published
- Last reviewed
- Attribution
- General Boss
- Attribution confidence
- MEDIUM
- Motivation
- FINANCIAL
- Target sectors
- it services msp, saas technology, oil gas, pharmaceuticals, consulting
- Target regions
- india, france, saudi arabia, new zealand, germany, North America, Europe, Middle East
- Detection rules
- 9
- Indicators of compromise
- 44
- Updates
- 2026-09-08 · 2 updates · revalidated 2× · latest source
Malware and tooling in BigBear 2.0 Evilginx2 Phishing-as-a-Service Campaign
Malware and tooling: telegram, evilginx2 - S9003, ipapi.is
How BigBear 2.0 Evilginx2 Phishing-as-a-Service Campaign works
CloudSEK's TRIAD discovered BigBear 2.0, a rebranded Evilginx2-based phishing-as-a-service (PhaaS) framework operated by threat actor 'General Boss' with at least five affiliates. The campaign managed 42 VPS nodes on Vultr, used geo-matched residential proxy pools from 69 countries to bypass ipapi.is anti-bot detection, employed custom JavaScript injections to disable FIDO2/WebAuthn and block Microsoft anti-phishing telemetry, and exfiltrated 5,137 credential records — including 474 complete MFA-bypassed authentications — across 461 organizations in 40+ countries. The operation was still active at publication.
In June 2026, CloudSEK's TRIAD threat intelligence platform uncovered a large-scale phishing-as-a-service operation dubbed BigBear 2.0 — a rebranded and heavily modified deployment of the open-source Evilginx2 adversary-in-the-middle (AiTM) framework. The campaign was operated by a threat actor using the alias 'General Boss' and leased to at least five affiliate operators who received stolen credentials in real time via Telegram bots. CloudSEK researchers gained administrative access to the actor's control panel, enabling comprehensive infrastructure and TTP analysis.
The core attack mechanism is an AiTM reverse proxy implemented in Evilginx2 using a phishlet configuration named 'offy' targeting Microsoft 365 and its OAuth 2.0 authorization flow. Victims receive spearphishing links pointing to phishing domains with Let's Encrypt TLS certificates; the DNS uses wildcard records so subdomains like <custom>.<phishing-domain> resolve to the VPS. When a victim navigates to the phishing page, Evilginx2 proxies all traffic bidirectionally between the victim and the legitimate login.microsoftonline.com, capturing credentials in plaintext (1,032 passwords captured) and intercepting the ESTSAUTH session cookie issued after MFA completion. The attacker then replays these cookies via a REST API at /api/jobs to hijack authenticated sessions. The ESTSAUTH cookie is bound to the browser session but not to a specific device or location, making it replayable from any machine.
BigBear 2.0 extended base Evilginx2 with three proprietary JavaScript injections patched into every proxied login page. The first disables FIDO2/WebAuthn by setting `Object.defineProperty(window, 'PublicKeyCredential', { value: undefined })`, forcing hardware security key users to fall back to phishable MFA (SMS, TOTP, or push). The second monkey-patches `window.fetch` and `XMLHttpRequest` to silently drop requests matching a blocklist of `['canarytokens', 'events.data.microsoft.com', 'OneCollector']`, preventing Microsoft's anti-phishing telemetry and any canary tokens from reaching their collection endpoints. The third auto-checks `#KmsiCheckboxField` and clicks `idSIButton9` after a delay to enable 'Keep Me Signed In' (KMSI), maximizing session cookie lifetime. These modifications are not present in standard Evilginx2 and represent a significant operational investment by the operator.
The campaign's infrastructure is notable for its scale and sophistication. All 42 VPS nodes were hosted by The Constant Company LLC (Vultr) and managed through a multi-tenant control panel with role-based access (admin and user tiers). The panel integrated a residential proxy pool spanning 69 countries with automated geo-matching: upstream traffic to Microsoft was routed through a residential IP matching the victim's country, defeating geo-anomaly detection and datacenter/VPN IP blacklists. An ipapi.is integration blocked non-residential IPs from accessing the phishing pages themselves, creating a significant anti-analysis barrier — researchers could only access the panel via residential IPs. Persistent cookie access was maintained via a keepalive mechanism that periodically refreshed captured session cookies by reusing Microsoft's 90-day refresh tokens.
Campaign statistics demonstrate both the scale and the effectiveness of the MFA bypass: 5,137 total credential records exfiltrated, comprising 474 complete MFA-bypassed sessions (9.2%), 1,032 plaintext passwords, and 4,148 session cookies. These records came from 3,331 unique victim IPs across 461 organizations in 40+ countries, with 258 organizations having at least one completed MFA bypass. The most targeted sector was IT Services/MSP (151 organizations), followed by SaaS/Technology (38), Oil & Gas (22), Pharmaceuticals (20), and Consulting (16). Top countries by victim count were India (658 records, 12.8%), France (463, 9.0%), Saudi Arabia (353, ~6%), New Zealand, and Germany.
Affiliate attribution was established through Telegram bot API probing. The primary admin C2 bot (@comeandget_bot) was revoked, and five affiliate bots were identified actively receiving stolen credentials. The most prolific reseller affiliates were @Sunagashison (Mrit Sunagashison, managing 4 nodes) and @app_ham (Syed Hasham, managing 3 nodes), both operating at a reseller tier (User ID 5). Other affiliates (@donplayer00, @workin_161, @Mazal100) each managed single nodes. The Diamond Model applied by CloudSEK profiled the adversary as cybercriminal rather than state-sponsored, with monetization likely via initial access brokerage rather than direct ransomware deployment.
In late July 2026, the threat actor engaged counter-forensic operations, deleting 26 of 42 VPS nodes from the panel. At the time of CloudSEK's September 7, 2026 publication, the phishing infrastructure had been offline for approximately three weeks, but the administration panel remained online and one VPS node was still active. BeaconBeagle correlation checks on the VPS infrastructure (IP 130.94.82.180, domain dnsforward.com) returned no C2 beacon matches, confirming the infrastructure was purpose-built for AiTM phishing rather than beacon-based C2. The campaign's custom SQL injection plot, cookie replay API, cookie names (evginx_session, bigbear_session), and HTTP headers (x-evg- prefix) provide strong detection signals for defenders.
MITRE ATT&CK techniques used in TL-2026-2374
Collection
T1056.003 Input Capture: Web Portal Capture; T1185 Browser Session Hijacking; T1557 Adversary-in-the-Middle
Execution
T1059.007 Command and Scripting Interpreter: JavaScript; T1204.001 User Execution: Malicious Link
Command and Control
T1071.001 Application Layer Protocol: Web Protocols; T1090.002 Proxy: External Proxy
Persistence
T1078 Valid Accounts; T1098 Account Manipulation
Exfiltration
T1102 Web Service; T1567 Exfiltration Over Web Service
Credential Access
T1111 Multi-Factor Authentication Interception; T1556.006 Modify Authentication Process: Multi-Factor Authentication
Defense Evasion
T1480.001 Execution Guardrails: Environmental Keying
credential-access
T1539 Steal Web Session Cookie
Lateral Movement
T1550.004 Use Alternate Authentication Material: Web Session Cookie
Initial Access
T1566.002 Phishing: Spearphishing Link
Resource Development
T1583.001 Acquire Infrastructure: Domains; T1583.003 Acquire Infrastructure: Virtual Private Server; T1588.002 Obtain Capabilities: Tool
Reconnaissance
T1598.003 Phishing for Information: Spearphishing Link
defense-impairment
Affected products and versions in BigBear 2.0 Evilginx2 Phishing-as-a-Service Campaign
- Microsoft — Microsoft 365 (Exchange Online, Teams, SharePoint, OneDrive, Entra ID)
Vulnerable versions: All tenants relying on non-phishing-resistant MFA (SMS, TOTP, push notifications)
Fixed in: N/A — deploy FIDO2/WebAuthn phishing-resistant MFA via Conditional Access
Remediation for BigBear 2.0 Evilginx2 Phishing-as-a-Service Campaign
Immediate actions
- Reset passwords for all accounts with sign-in activity from identified VPS IP ranges
- Revoke active sessions and refresh tokens via Entra ID admin portal
- Force re-authentication for all high-privilege and MFA-bypassed accounts
- Block identified VPS IP addresses (38.60.250.157, 95.179.233.79, 80.240.27.55, 65.20.103.58, 38.54.124.88, 208.85.20.79, 95.179.169.154, 107.191.46.14, 130.94.82.180, 38.54.124.58, 208.85.18.18, 45.32.147.239, 208.76.222.214, 130.94.82.230, 65.20.102.80) at perimeter
- Block identified phishing domains at email gateway and proxy level
- Hunt for evginx_session, evginx_token, evginx_admin, bigbear_session, and bigbear_token cookies in captured traffic
- Search Entra ID sign-in logs for sessions originating from Vultr AS-AS36351 residential IPs matching user geography
- Review Unified Audit Log for SessionId anomalies (consistent SessionId across diverse IPs/User-Agents)
Workarounds
- Temporarily restrict access to Exchange Online, Teams, SharePoint, and OneDrive to compliant/managed devices only
- Reduce session cookie lifetime and enforce sign-in frequency policies in Conditional Access
- Disable KMSI (Keep Me Signed In) for high-risk user populations
Longer-term hardening
- Enforce phishing-resistant FIDO2/WebAuthn hardware keys for all users via Conditional Access
- Deploy Conditional Access policies requiring managed/compliant devices rather than geo-location signals
- Enable Entra ID Identity Protection with risk-based policies — AiTM and Anomalous Token detections
- Implement Continuous Access Evaluation (CAE) for token revocation on suspicious activity
- Monitor Certificate Transparency logs for suspicious lookalike domains with Let's Encrypt certs
- Deploy network-level TLS fingerprinting (JA3/JA4) to detect reverse proxy anomalies
- Enable device compliance and device ID checks in Conditional Access policies
- Implement canary token infrastructure with alerting on token activation
Timeline of BigBear 2.0 Evilginx2 Phishing-as-a-Service Campaign
- CloudSEK TRIAD discovers BigBear 2.0 campaign, a rebranded Evilginx2-based PhaaS framework targeting Microsoft 365
- CloudSEK researchers gain administrator-level access to the threat actor control panel, enabling comprehensive infrastructure and TTP analysis
- Initial panel export captures 1,442 credential records, primarily from Indian and European victims
- Campaign reaches peak operational scale: 42 VPS nodes across 5+ affiliates, 5,137 credential records (474 MFA-bypassed, 1,032 passwords, 4,148 session cookies), 461 organizations in 40+ countries
- Threat actor begins deleting VPS nodes from panel in response to detection; removes 26 of 42 nodes in counter-forensic operation
- Phishing infrastructure goes offline (approximately 3 weeks before publication); administration panel remains online
- CloudSEK publishes report detailing the BigBear 2.0 campaign; BleepingComputer and other outlets publish concurrent coverage
Update history for TL-2026-2374
- 2026-09-08 — BigBear 2.0 Evilginx2 Phishing-as-a-Service Compromised 258 Microsoft 365 Organizations via AiTM Proxy Bypassing MFA: New indicators (4) 2 new phishing domains (ccpipharma.com, haliotisbar.com) and 2 VPS IPs (80.240.27.55, 38.54.124.88) that were already implicated via the existing record's remediation block-list but not previously carried as IOC rows. New
- 2026-09-08 — BigBear 2.0 Evilginx2-based Phishing-as-a-Service Bypassed MFA at 258 Microsoft 365 Organizations: What changed No field escalation applied. The newer pass actually rates severity HIGH vs. the published CRITICAL and gives slightly different milestone dates (discovery 06-01 vs. 06-10, counter-forensics 07-28 vs. 07-25, offline 08-20 vs. 0
Sources cited for BigBear 2.0 Evilginx2 Phishing-as-a-Service Campaign
- Tracking BigBear 2.0 Evilginx2 Phishing Campaign
- BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations
- evilginx2 — MITRE ATT&CK Software S9003
- Bypassing MFA: A Forensic Look at Evilginx2 Phishing Kit
- Evilginx 3: AiTM Phishing and MFA Bypass for Red Teams
- PH-AITM-EVILGINX — AttackPaths
- Misconfigured Server Exposes Evilginx Phishing Campaigns Bypassing MFA to Target Microsoft 365
- Microsoft 365 Phishing Alert: How Attackers Bypass MFA with Evilginx & Device Code Flow
Detection coverage for TL-2026-2374
As of 2026-09-08, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2374 across Splunk SPL, Microsoft KQL and Sigma, covering 44 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.