BigBear 2.0 is a phishing operation designed to steal proof that a user has already passed multi-factor authentication.
It targets Microsoft 365 accounts through convincing sign-in links, then takes over the logged-in browser session rather than attempting to break the authentication factor.
The operation is a rebranded Evilginx2 phishing framework that targets Microsoft 365 accounts. Victims are drawn in through email links that open a proxy page resembling a Microsoft sign-in page.
It relays their traffic to the genuine service while quietly collecting credentials and the session data returned after sign-in.
CloudSEK analysts identified BigBear 2.0 in June 2026 after gaining access to its administrative panel. The researchers linked the activity to an operator using the alias General Boss and found a network of 42 virtual private server nodes.
CloudSEK said in a report shared with Cyber Security News (CSN) that the panel held 5,137 stolen records tied to 461 organizations and 3,331 unique victim IP addresses across more than 40 countries.
Of those records, 474 represented complete authenticated sessions, alongside 1,032 passwords and 4,148 session cookies. The records illustrate an operation that collects both immediate account access and material that may support persistent access later.
BigBear 2.0 Evilginx2 Phishing Campaign Bypasses Microsoft 365 MFA
BigBear 2.0 uses an adversary-in-the-middle setup, meaning it sits between the victim and the real Microsoft login service.
It captures the email address and password, lets Microsoft validate the request, and waits for the victim to complete their normal approval or code challenge.
When sign-in succeeds, Microsoft sends an authenticated session cookie to the browser. Because the proxy handled the exchange, it can copy that cookie before forwarding the response.
The attacker can replay it in another browser and enter email, Teams, SharePoint, OneDrive, and connected single sign-on applications as the victim. Microsoft 365 session hijacking campaigns have reported the same account-takeover risk.
This is not a weakness in a one-time password, SMS code, or push notification by itself. These methods confirm the user during the live session, but the proxy steals the resulting proof. BigBear used country-matched residential proxies and scripts that pushed users away from security-key authentication.
The campaign particularly affected IT services and managed service providers, a concern because one compromised provider can offer attackers a route into customer environments.
At least five affiliates were linked to the panel. Phishing kits targeting organizations show this service-based model is spreading.
Containing identity compromise
Organizations should treat a suspected stolen cookie as an identity incident, not merely a password problem. Reset affected passwords, revoke active sessions and refresh tokens, and force a new sign-in for impacted accounts.
Teams should examine mailbox forwarding rules, OAuth consent grants, unfamiliar application access, and sign-in activity for evidence that a hijacked session was used after authentication. This review should begin as soon as suspicious activity is reported.
The most useful long-term control is phishing-resistant authentication, especially FIDO2 or WebAuthn security keys and passkeys where properly deployed.
These methods bind a login cryptographically to the genuine site, making a lookalike proxy far less useful. Passkey attack techniques nevertheless deserve ongoing attention.
.webp)
Administrators should require compliant devices through Conditional Access, shorten session lifetimes where appropriate, and watch for unusual residential IP ranges or new browser sessions.
Email filtering should inspect links that imitate sign-in pages even when they use valid certificates. Teams can monitor for the distinctive headers and cookies listed below, because infrastructure can be reassigned.
For users, a familiar Microsoft page and successful MFA prompt do not always prove that a browser is connected directly to Microsoft.
Verify unexpected sign-in requests through a trusted bookmark or known application, not an email link. This concern is reinforced by Evilginx session-cookie attacks, which also depend on real-time relaying rather than stolen passwords alone.
The campaign combined cookie theft, geographic proxy matching, and affiliate access. MFA must be paired with phishing-resistant methods, session controls, and rapid token revocation.
Indicators of compromise (IoCs):-
| Type | Indicator | Description |
|---|---|---|
| IP address | 38[.]60[.]250[.]157 |
BigBear 2.0 VPS node |
| IP address | 95[.]179[.]233[.]79 |
BigBear 2.0 VPS node |
| IP address | 80[.]240[.]27[.]55 |
BigBear 2.0 VPS node |
| IP address | 65[.]20[.]103[.]58 |
BigBear 2.0 VPS node |
| IP address | 38[.]54[.]124[.]88 |
BigBear 2.0 VPS node |
| IP address | 208[.]85[.]20[.]79 |
BigBear 2.0 VPS node |
| IP address | 95[.]179[.]169[.]154 |
BigBear 2.0 VPS node |
| IP address | 107[.]191[.]46[.]14 |
BigBear 2.0 VPS node |
| IP address | 130[.]94[.]82[.]180 |
BigBear 2.0 VPS node |
| IP address | 38[.]54[.]124[.]58 |
BigBear 2.0 VPS node |
| IP address | 208[.]85[.]18[.]18 |
BigBear 2.0 VPS node |
| IP address | 45[.]32[.]147[.]239 |
BigBear 2.0 VPS node |
| IP address | 208[.]76[.]222[.]214 |
BigBear 2.0 VPS node |
| IP address | 130[.]94[.]82[.]230 |
BigBear 2.0 VPS node |
| IP address | 65[.]20[.]102[.]80 |
BigBear 2.0 VPS node |
| IP address | 70[.]34[.]208[.]46 |
Historical BigBear 2.0 VPS node |
| IP address | 130[.]94[.]113[.]184 |
Historical BigBear 2.0 VPS node |
| IP address | 78[.]141[.]193[.]59 |
Historical BigBear 2.0 VPS node |
| IP address | 64[.]176[.]72[.]180 |
Historical BigBear 2.0 VPS node |
| IP address | 136[.]244[.]114[.]85 |
Historical BigBear 2.0 VPS node |
| IP address | 70[.]34[.]244[.]122 |
Historical BigBear 2.0 VPS node |
| IP address | 199[.]247[.]10[.]14 |
Historical BigBear 2.0 VPS node |
| IP address | 152[.]39[.]137[.]60 |
Historical BigBear 2.0 VPS node |
| IP address | 91[.]245[.]235[.]208 |
Historical BigBear 2.0 VPS node |
| IP address | 45[.]32[.]64[.]165 |
Historical BigBear 2.0 VPS node |
| Domain | konceptenterprises[.]com |
Phishing domain |
| Domain | ccpipharma[.]com |
Phishing domain |
| Domain | annastudios-paros[.]com |
Phishing domain |
| Domain | dnsforward[.]com |
Phishing domain |
| Domain | hotelmidtownsurat[.]com |
Phishing domain |
| Domain | dataclust[.]com |
Phishing domain |
| Domain | cifutura[.]com |
Phishing domain |
| Domain | hoaivt[.]com |
Phishing domain |
| Domain | dronalms[.]com |
Phishing domain |
| Domain | virextec[.]com |
Phishing domain |
| Domain | offtic[.]com |
Phishing domain |
| Domain | rootreseller[.]com |
Phishing domain |
| Domain | management[.]michaelmarcotte[.]com |
Phishing domain |
| Domain | kgsscans[.]com |
Phishing domain |
| Domain | soil-management[.]com |
Phishing domain |
| Domain | daengrentacar[.]com |
Historical phishing domain |
| Domain | arrmmy[.]com |
Historical phishing domain |
| Domain | captelind[.]com |
Historical phishing domain |
| Domain | planisteradmin[.]com |
Historical phishing domain |
| Domain | hnospascualfadon[.]com |
Historical phishing domain |
| Domain | haliotisbar[.]com |
Historical phishing domain |
| Domain | knowncontractor[.]com |
Historical phishing domain |
| Domain | valtteri[.]net |
Historical phishing domain |
| URL | management[.]daengrentacar[.]com/meetings |
Observed live Microsoft 365 phishing page |
| Filename | cookie.js |
File attachment used in the credential-processing workflow |
| Telegram bot | @comeandget_bot |
Primary administrator command-and-control bot, revoked |
| Telegram bot token | 8629902848[:]AAGEFRukqwu9QaMSDNNuVRYF3juTcg4ehO4 |
Defanged token for revoked primary administrator bot |
| Telegram bot | @botterxyz_bot |
Affiliate credential-exfiltration bot |
| Telegram bot token | 8625043408[:]AAH6G8X0aW0QhoLEB1uJiYQ5-2aLSJzg8VE |
Defanged affiliate bot token |
| Telegram bot | @PackingitonG_bot |
Affiliate credential-exfiltration bot |
| Telegram bot token | 8783369414[:]AAGENRhb7By-0-cQFgrnOw1AW4NbOeUutVE |
Defanged affiliate bot token |
| Telegram bot | @donplayer_bot |
Affiliate credential-exfiltration bot |
| Telegram bot token | 8807072847[:]AAEYbUaFcbeAgxTZ2Zl8pFbpjRPM9jXvvzE |
Defanged affiliate bot token |
| Telegram bot | @bolywan_bot |
Affiliate credential-exfiltration bot |
| Telegram bot token | 8462028468[:]AAEQt7oq0c3nTHzApQtHk3RdZ7ifnkYd1XM |
Defanged affiliate bot token |
| Telegram bot | @rdsxtdytguyg75d_bot |
Affiliate credential-exfiltration bot |
| Telegram bot token | 8794520788[:]AAERSVBlWMpzHc21CCP_-9tL_pjqH9-WuFI |
Defanged affiliate bot token |
| HTTP header | x-evg-token |
Evilginx-related application header |
| HTTP header | x-evg-server |
Evilginx-related application header |
| HTTP header | x-evg-session |
Evilginx-related application header |
| Cookie | evginx_session |
Evilginx-related session cookie |
| Cookie | evginx_token |
Evilginx-related token cookie |
| Cookie | evginx_admin |
Evilginx-related administrator cookie |
| Cookie | bigbear_session |
BigBear 2.0 session cookie |
| Cookie | bigbear_token |
BigBear 2.0 token cookie |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.