# BigBear 2.0 Evilginx2 Phishing-as-a-Service Campaign Targeting Microsoft 365 with MFA Bypass

> CloudSEK's TRIAD discovered BigBear 2.0, a rebranded Evilginx2-based phishing-as-a-service (PhaaS) framework operated by threat actor 'General Boss' with at least five affiliates. The campaign managed 42 VPS nodes on Vultr, used geo-matched residential proxy pools from 69 countries to bypass ipapi.is anti-bot detection, employed custom JavaScript injections to disable FIDO2/WebAuthn and block Microsoft anti-phishing telemetry, and exfiltrated 5,137 credential records — including 474 complete MFA-bypassed authentications — across 461 organizations in 40+ countries. The operation was still active at publication.

- **Published:** 2026-09-07T00:00:00Z
- **Last reviewed:** 2026-09-08T12:30:16.265Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-2374
- **ID:** TL-2026-2374
- **Severity:** CRITICAL
- **Category:** PHISHING
- **Status:** ACTIVE
- **Actor:** General Boss
- **Detections:** 9 · **IOCs:** 44 (full data via the Threadlinqs MCP server — Purple tier)

## Description

In June 2026, CloudSEK's TRIAD threat intelligence platform uncovered a large-scale phishing-as-a-service operation dubbed BigBear 2.0 — a rebranded and heavily modified deployment of the open-source Evilginx2 adversary-in-the-middle (AiTM) framework. The campaign was operated by a threat actor using the alias 'General Boss' and leased to at least five affiliate operators who received stolen credentials in real time via Telegram bots. CloudSEK researchers gained administrative access to the actor's control panel, enabling comprehensive infrastructure and TTP analysis.

The core attack mechanism is an AiTM reverse proxy implemented in Evilginx2 using a phishlet configuration named 'offy' targeting Microsoft 365 and its OAuth 2.0 authorization flow. Victims receive spearphishing links pointing to phishing domains with Let's Encrypt TLS certificates; the DNS uses wildcard records so subdomains like <custom>.<phishing-domain> resolve to the VPS. When a victim navigates to the phishing page, Evilginx2 proxies all traffic bidirectionally between the victim and the legitimate login.microsoftonline.com, capturing credentials in plaintext (1,032 passwords captured) and intercepting the ESTSAUTH session cookie issued after MFA completion. The attacker then replays these cookies via a REST API at /api/jobs to hijack authenticated sessions. The ESTSAUTH cookie is bound to the browser session but not to a specific device or location, making it replayable from any machine.

BigBear 2.0 extended base Evilginx2 with three proprietary JavaScript injections patched into every proxied login page. The first disables FIDO2/WebAuthn by setting `Object.defineProperty(window, 'PublicKeyCredential', { value: undefined })`, forcing hardware security key users to fall back to phishable MFA (SMS, TOTP, or push). The second monkey-patches `window.fetch` and `XMLHttpRequest` to silently drop requests matching a blocklist of `['canarytokens', 'events.data.microsoft.com', 'OneCollector']`, preventing Microsoft's anti-phishing telemetry and any canary tokens from reaching their collection endpoints. The third auto-checks `#KmsiCheckboxField` and clicks `idSIButton9` after a delay to enable 'Keep Me Signed In' (KMSI), maximizing session cookie lifetime. These modifications are not present in standard Evilginx2 and represent a significant operational investment by the operator.

The campaign's infrastructure is notable for its scale and sophistication. All 42 VPS nodes were hosted by The Constant Company LLC (Vultr) and managed through a multi-tenant control panel with role-based access (admin and user tiers). The panel integrated a residential proxy pool spanning 69 countries with automated geo-matching: upstream traffic to Microsoft was routed through a residential IP matching the victim's country, defeating geo-anomaly detection and datacenter/VPN IP blacklists. An ipapi.is integration blocked non-residential IPs from accessing the phishing pages themselves, creating a significant anti-analysis barrier — researchers could only access the panel via residential IPs. Persistent cookie access was maintained via a keepalive mechanism that periodically refreshed captured session cookies by reusing Microsoft's 90-day refresh tokens.

Campaign statistics demonstrate both the scale and the effectiveness of the MFA bypass: 5,137 total credential records exfiltrated, comprising 474 complete MFA-bypassed sessions (9.2%), 1,032 plaintext passwords, and 4,148 session cookies. These records came from 3,331 unique victim IPs across 461 organizations in 40+ countries, with 258 organizations having at least one completed MFA bypass. The most targeted sector was IT Services/MSP (151 organizations), followed by SaaS/Technology (38), Oil & Gas (22), Pharmaceuticals (20), and Consulting (16). Top countries by victim count were India (658 records, 12.8%), France (463, 9.0%), Saudi Arabia (353, ~6%), New Zealand, and Germany.

Affiliate attribution was established through Telegram bot API probing. The primary admin C2 bot (@comeandget_bot) was revoked, and five affiliate bots were identified actively receiving stolen credentials. The most prolific reseller affiliates were @Sunagashison (Mrit Sunagashison, managing 4 nodes) and @app_ham (Syed Hasham, managing 3 nodes), both operating at a reseller tier (User ID 5). Other affiliates (@donplayer00, @workin_161, @Mazal100) each managed single nodes. The Diamond Model applied by CloudSEK profiled the adversary as cybercriminal rather than state-sponsored, with monetization likely via initial access brokerage rather than direct ransomware deployment.

In late July 2026, the threat actor engaged counter-forensic operations, deleting 26 of 42 VPS nodes from the panel. At the time of CloudSEK's September 7, 2026 publication, the phishing infrastructure had been offline for approximately three weeks, but the administration panel remained online and one VPS node was still active. BeaconBeagle correlation checks on the VPS infrastructure (IP 130.94.82.180, domain dnsforward.com) returned no C2 beacon matches, confirming the infrastructure was purpose-built for AiTM phishing rather than beacon-based C2. The campaign's custom SQL injection plot, cookie replay API, cookie names (evginx_session, bigbear_session), and HTTP headers (x-evg- prefix) provide strong detection signals for defenders.

## MITRE ATT&CK

- T1583.001 Acquire Infrastructure: Domains
- T1583.003 Acquire Infrastructure: Virtual Private Server
- T1588.002 Obtain Capabilities: Tool
- T1566.002 Phishing: Spearphishing Link
- T1204.001 User Execution: Malicious Link
- T1059.007 Command and Scripting Interpreter: JavaScript
- T1685 Disable or Modify Tools
- T1111 Multi-Factor Authentication Interception
- T1556.006 Modify Authentication Process: Multi-Factor Authentication
- T1557 Adversary-in-the-Middle
- T1539 Steal Web Session Cookie
- T1056.003 Input Capture: Web Portal Capture
- T1185 Browser Session Hijacking
- T1071.001 Application Layer Protocol: Web Protocols
- T1090.002 Proxy: External Proxy
- T1550.004 Use Alternate Authentication Material: Web Session Cookie
- T1078 Valid Accounts
- T1598.003 Phishing for Information: Spearphishing Link
- T1098 Account Manipulation
- T1480.001 Execution Guardrails: Environmental Keying
- T1102 Web Service
- T1567 Exfiltration Over Web Service

## Sources

- [Tracking BigBear 2.0 Evilginx2 Phishing Campaign](https://www.cloudsek.com/blog/tracking-bigbear-2-0-evilginx2-phishing-campaign)
- [BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations](https://www.bleepingcomputer.com/news/security/bigbear-microsoft-365-phishing-service-bypassed-mfa-at-258-organizations/)
- [evilginx2 — MITRE ATT&CK Software S9003](https://attack.mitre.org/software/S9003/)
- [Bypassing MFA: A Forensic Look at Evilginx2 Phishing Kit](https://www.levelblue.com/blogs/spiderlabs-blog/bypassing-mfa-a-forensic-look-at-evilginx2-phishing-kit)
- [Evilginx 3: AiTM Phishing and MFA Bypass for Red Teams](https://hackita.it/articoli/evilginx3-aitm-mfa-bypass/)
- [PH-AITM-EVILGINX — AttackPaths](https://www.attackpaths.org/en/techniques/PH-AITM-EVILGINX)
- [Misconfigured Server Exposes Evilginx Phishing Campaigns Bypassing MFA to Target Microsoft 365](https://www.rescana.com/post/misconfigured-server-exposes-evilginx-phishing-campaigns-bypassing-mfa-to-target-microsoft-365-accounts)
- [Microsoft 365 Phishing Alert: How Attackers Bypass MFA with Evilginx & Device Code Flow](https://teamtsuga.com/article/microsoft-365-phishing-alert-how-attackers-bypass-mfa-with-evilginx-device-code-flow)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-2374
