Threat reportPhishingTL-2026-2374

BigBear 2.0 Evilginx2 Phishing-as-a-Service Campaign Targeting Microsoft 365 with MFA Bypass

criticalACTIVE

BigBear 2.0 Evilginx2 Phishing-as-a-Service Campaign (TL-2026-2374), also tracked as BigBear, is a critical-severity phishing campaign, first published 2026-09-07 and last reviewed 2026-09-08. It is attributed to General Boss with medium confidence, affects Microsoft Microsoft 365 (Exchange Online, Teams, SharePoint, OneDrive, maps to 22 MITRE ATT&CK techniques (T1056.003, T1059.007, T1071.001), and is covered by 9 detection rules and 44 indicators of compromise.

Severity
CRITICALAssessed severity
CVEs
0None referenced
Techniques
22MITRE ATT&CK
Actors
1General Boss
Detection rules
9SPL · KQL · Sigma
IOCs
44Indicators of compromise

Key facts for TL-2026-2374

Threat ID
TL-2026-2374
Also known as
BigBear, BigBear 2.0, BigBear 2.0 PhaaS
Severity
CRITICAL
Status
ACTIVE
Category
PHISHING
First published
Last reviewed
Attribution
General Boss
Attribution confidence
MEDIUM
Motivation
FINANCIAL
Target sectors
it services msp, saas technology, oil gas, pharmaceuticals, consulting
Target regions
india, france, saudi arabia, new zealand, germany, North America, Europe, Middle East
Detection rules
9
Indicators of compromise
44
Updates
2026-09-08 · 2 updates · revalidated 2× · latest source

Malware and tooling in BigBear 2.0 Evilginx2 Phishing-as-a-Service Campaign

Malware and tooling: telegram, evilginx2 - S9003, ipapi.is

How BigBear 2.0 Evilginx2 Phishing-as-a-Service Campaign works

CloudSEK's TRIAD discovered BigBear 2.0, a rebranded Evilginx2-based phishing-as-a-service (PhaaS) framework operated by threat actor 'General Boss' with at least five affiliates. The campaign managed 42 VPS nodes on Vultr, used geo-matched residential proxy pools from 69 countries to bypass ipapi.is anti-bot detection, employed custom JavaScript injections to disable FIDO2/WebAuthn and block Microsoft anti-phishing telemetry, and exfiltrated 5,137 credential records — including 474 complete MFA-bypassed authentications — across 461 organizations in 40+ countries. The operation was still active at publication.

In June 2026, CloudSEK's TRIAD threat intelligence platform uncovered a large-scale phishing-as-a-service operation dubbed BigBear 2.0 — a rebranded and heavily modified deployment of the open-source Evilginx2 adversary-in-the-middle (AiTM) framework. The campaign was operated by a threat actor using the alias 'General Boss' and leased to at least five affiliate operators who received stolen credentials in real time via Telegram bots. CloudSEK researchers gained administrative access to the actor's control panel, enabling comprehensive infrastructure and TTP analysis.

The core attack mechanism is an AiTM reverse proxy implemented in Evilginx2 using a phishlet configuration named 'offy' targeting Microsoft 365 and its OAuth 2.0 authorization flow. Victims receive spearphishing links pointing to phishing domains with Let's Encrypt TLS certificates; the DNS uses wildcard records so subdomains like <custom>.<phishing-domain> resolve to the VPS. When a victim navigates to the phishing page, Evilginx2 proxies all traffic bidirectionally between the victim and the legitimate login.microsoftonline.com, capturing credentials in plaintext (1,032 passwords captured) and intercepting the ESTSAUTH session cookie issued after MFA completion. The attacker then replays these cookies via a REST API at /api/jobs to hijack authenticated sessions. The ESTSAUTH cookie is bound to the browser session but not to a specific device or location, making it replayable from any machine.

BigBear 2.0 extended base Evilginx2 with three proprietary JavaScript injections patched into every proxied login page. The first disables FIDO2/WebAuthn by setting `Object.defineProperty(window, 'PublicKeyCredential', { value: undefined })`, forcing hardware security key users to fall back to phishable MFA (SMS, TOTP, or push). The second monkey-patches `window.fetch` and `XMLHttpRequest` to silently drop requests matching a blocklist of `['canarytokens', 'events.data.microsoft.com', 'OneCollector']`, preventing Microsoft's anti-phishing telemetry and any canary tokens from reaching their collection endpoints. The third auto-checks `#KmsiCheckboxField` and clicks `idSIButton9` after a delay to enable 'Keep Me Signed In' (KMSI), maximizing session cookie lifetime. These modifications are not present in standard Evilginx2 and represent a significant operational investment by the operator.

The campaign's infrastructure is notable for its scale and sophistication. All 42 VPS nodes were hosted by The Constant Company LLC (Vultr) and managed through a multi-tenant control panel with role-based access (admin and user tiers). The panel integrated a residential proxy pool spanning 69 countries with automated geo-matching: upstream traffic to Microsoft was routed through a residential IP matching the victim's country, defeating geo-anomaly detection and datacenter/VPN IP blacklists. An ipapi.is integration blocked non-residential IPs from accessing the phishing pages themselves, creating a significant anti-analysis barrier — researchers could only access the panel via residential IPs. Persistent cookie access was maintained via a keepalive mechanism that periodically refreshed captured session cookies by reusing Microsoft's 90-day refresh tokens.

Campaign statistics demonstrate both the scale and the effectiveness of the MFA bypass: 5,137 total credential records exfiltrated, comprising 474 complete MFA-bypassed sessions (9.2%), 1,032 plaintext passwords, and 4,148 session cookies. These records came from 3,331 unique victim IPs across 461 organizations in 40+ countries, with 258 organizations having at least one completed MFA bypass. The most targeted sector was IT Services/MSP (151 organizations), followed by SaaS/Technology (38), Oil & Gas (22), Pharmaceuticals (20), and Consulting (16). Top countries by victim count were India (658 records, 12.8%), France (463, 9.0%), Saudi Arabia (353, ~6%), New Zealand, and Germany.

Affiliate attribution was established through Telegram bot API probing. The primary admin C2 bot (@comeandget_bot) was revoked, and five affiliate bots were identified actively receiving stolen credentials. The most prolific reseller affiliates were @Sunagashison (Mrit Sunagashison, managing 4 nodes) and @app_ham (Syed Hasham, managing 3 nodes), both operating at a reseller tier (User ID 5). Other affiliates (@donplayer00, @workin_161, @Mazal100) each managed single nodes. The Diamond Model applied by CloudSEK profiled the adversary as cybercriminal rather than state-sponsored, with monetization likely via initial access brokerage rather than direct ransomware deployment.

In late July 2026, the threat actor engaged counter-forensic operations, deleting 26 of 42 VPS nodes from the panel. At the time of CloudSEK's September 7, 2026 publication, the phishing infrastructure had been offline for approximately three weeks, but the administration panel remained online and one VPS node was still active. BeaconBeagle correlation checks on the VPS infrastructure (IP 130.94.82.180, domain dnsforward.com) returned no C2 beacon matches, confirming the infrastructure was purpose-built for AiTM phishing rather than beacon-based C2. The campaign's custom SQL injection plot, cookie replay API, cookie names (evginx_session, bigbear_session), and HTTP headers (x-evg- prefix) provide strong detection signals for defenders.

MITRE ATT&CK techniques used in TL-2026-2374

Collection

T1056.003 Input Capture: Web Portal Capture; T1185 Browser Session Hijacking; T1557 Adversary-in-the-Middle

Execution

T1059.007 Command and Scripting Interpreter: JavaScript; T1204.001 User Execution: Malicious Link

Command and Control

T1071.001 Application Layer Protocol: Web Protocols; T1090.002 Proxy: External Proxy

Persistence

T1078 Valid Accounts; T1098 Account Manipulation

Exfiltration

T1102 Web Service; T1567 Exfiltration Over Web Service

Credential Access

T1111 Multi-Factor Authentication Interception; T1556.006 Modify Authentication Process: Multi-Factor Authentication

Defense Evasion

T1480.001 Execution Guardrails: Environmental Keying

credential-access

T1539 Steal Web Session Cookie

Lateral Movement

T1550.004 Use Alternate Authentication Material: Web Session Cookie

Initial Access

T1566.002 Phishing: Spearphishing Link

Resource Development

T1583.001 Acquire Infrastructure: Domains; T1583.003 Acquire Infrastructure: Virtual Private Server; T1588.002 Obtain Capabilities: Tool

Reconnaissance

T1598.003 Phishing for Information: Spearphishing Link

defense-impairment

T1685 Disable or Modify Tools

Affected products and versions in BigBear 2.0 Evilginx2 Phishing-as-a-Service Campaign

  • Microsoft — Microsoft 365 (Exchange Online, Teams, SharePoint, OneDrive, Entra ID)
    Vulnerable versions: All tenants relying on non-phishing-resistant MFA (SMS, TOTP, push notifications)
    Fixed in: N/A — deploy FIDO2/WebAuthn phishing-resistant MFA via Conditional Access

Remediation for BigBear 2.0 Evilginx2 Phishing-as-a-Service Campaign

Immediate actions

  • Reset passwords for all accounts with sign-in activity from identified VPS IP ranges
  • Revoke active sessions and refresh tokens via Entra ID admin portal
  • Force re-authentication for all high-privilege and MFA-bypassed accounts
  • Block identified VPS IP addresses (38.60.250.157, 95.179.233.79, 80.240.27.55, 65.20.103.58, 38.54.124.88, 208.85.20.79, 95.179.169.154, 107.191.46.14, 130.94.82.180, 38.54.124.58, 208.85.18.18, 45.32.147.239, 208.76.222.214, 130.94.82.230, 65.20.102.80) at perimeter
  • Block identified phishing domains at email gateway and proxy level
  • Hunt for evginx_session, evginx_token, evginx_admin, bigbear_session, and bigbear_token cookies in captured traffic
  • Search Entra ID sign-in logs for sessions originating from Vultr AS-AS36351 residential IPs matching user geography
  • Review Unified Audit Log for SessionId anomalies (consistent SessionId across diverse IPs/User-Agents)

Workarounds

  • Temporarily restrict access to Exchange Online, Teams, SharePoint, and OneDrive to compliant/managed devices only
  • Reduce session cookie lifetime and enforce sign-in frequency policies in Conditional Access
  • Disable KMSI (Keep Me Signed In) for high-risk user populations

Longer-term hardening

  • Enforce phishing-resistant FIDO2/WebAuthn hardware keys for all users via Conditional Access
  • Deploy Conditional Access policies requiring managed/compliant devices rather than geo-location signals
  • Enable Entra ID Identity Protection with risk-based policies — AiTM and Anomalous Token detections
  • Implement Continuous Access Evaluation (CAE) for token revocation on suspicious activity
  • Monitor Certificate Transparency logs for suspicious lookalike domains with Let's Encrypt certs
  • Deploy network-level TLS fingerprinting (JA3/JA4) to detect reverse proxy anomalies
  • Enable device compliance and device ID checks in Conditional Access policies
  • Implement canary token infrastructure with alerting on token activation

Timeline of BigBear 2.0 Evilginx2 Phishing-as-a-Service Campaign

  • CloudSEK TRIAD discovers BigBear 2.0 campaign, a rebranded Evilginx2-based PhaaS framework targeting Microsoft 365
  • CloudSEK researchers gain administrator-level access to the threat actor control panel, enabling comprehensive infrastructure and TTP analysis
  • Initial panel export captures 1,442 credential records, primarily from Indian and European victims
  • Campaign reaches peak operational scale: 42 VPS nodes across 5+ affiliates, 5,137 credential records (474 MFA-bypassed, 1,032 passwords, 4,148 session cookies), 461 organizations in 40+ countries
  • Threat actor begins deleting VPS nodes from panel in response to detection; removes 26 of 42 nodes in counter-forensic operation
  • Phishing infrastructure goes offline (approximately 3 weeks before publication); administration panel remains online
  • CloudSEK publishes report detailing the BigBear 2.0 campaign; BleepingComputer and other outlets publish concurrent coverage

Update history for TL-2026-2374

Sources cited for BigBear 2.0 Evilginx2 Phishing-as-a-Service Campaign

Detection coverage for TL-2026-2374

As of 2026-09-08, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2374 across Splunk SPL, Microsoft KQL and Sigma, covering 44 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
44 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats