A phishing-as-a-service operation dubbed BigBear 2.0 is hijacking authenticated Microsoft 365 sessions at hundreds of organizations by stealing cookies generated after users complete multifactor authentication.[2][3][15] Security firm CloudSEK reports that its TRIAD team gained administrator access to the BigBear 2.0 control panel, exposing a live adversary-in-the-middle infrastructure built on the Evilginx2 framework and tuned specifically to intercept Microsoft 365 logins.[2][6][12]
The exposed panel showed BigBear 2.0 had amassed 5,137 records tied to Microsoft 365 accounts, including 1,032 plaintext passwords, 4,148 session cookies and 474 fully MFA-bypassed authentications in which attackers captured an already authenticated session.[2][3][7][15][13] CloudSEK’s analysis links those records to 461 targeted organizations and more than 3,331 unique victim IPs across 40-plus countries, with separate reporting noting that at least 258 organizations had at least one completed MFA-bypass compromise.[2][4][7][13] Because those sessions grant full access to Microsoft 365 tenants, a hijacked account can expose mailboxes, calendars, Teams conversations, SharePoint and OneDrive files, and—where privileges allow—Entra ID and connected cloud or SaaS applications, creating a direct path to business email compromise, internal phishing, data theft and lateral movement.[2][6][7]
BigBear 2.0’s effectiveness rests on Evilginx2’s adversary-in-the-middle design, which proxies the legitimate Microsoft 365 sign-in page through attacker-controlled infrastructure while relaying credentials and MFA challenges to the real service.[2][6][8][11] Victims see what appears to be a normal Microsoft login flow, enter their username, password and second factor, and receive successful access from Microsoft—while the proxy silently captures the resulting session cookie and other authentication artifacts.[8][9][11] Attackers can then import those cookies into their own browsers or tooling to replay the authenticated session and access Microsoft 365 resources without re-prompting the victim, until the token expires or is revoked.[9][11]
CloudSEK’s report describes BigBear 2.0 as a customized, multi-tenant evolution of Evilginx2, with a default phishlet dubbed offy that is engineered for Microsoft 365, Azure AD and Entra ID logins.[2][6][12] Researchers say the framework includes JavaScript designed to suppress FIDO2/WebAuthn prompts on phishing pages, nudging users toward weaker MFA methods such as SMS codes, push notifications and TOTP that remain vulnerable to adversary-in-the-middle interception.[2][9][15] The operation also relies on a large pool of residential proxies to route traffic through IP addresses that match victims’ regions, making successful logins from attacker infrastructure look less suspicious and filtering out connections from datacenters, VPNs and known proxy ranges to frustrate scanners and investigators.[2][6][12] CloudSEK identified 42 virtual private server nodes linked to the campaign, observed that the infrastructure is managed through a multi-user panel and leased to at least five affiliate operators, and noted that stolen credentials were delivered in real time via Telegram bots.[2][5][7][15] The actor behind BigBear 2.0, tracked as “General Boss,” has not been linked to any state-backed group and appears primarily financially motivated, with stolen Microsoft 365 access used for business email compromise, data theft or resale to other criminals.[2][5][12]
The campaign underscores how widely deployed MFA controls can be undermined when attackers shift from stealing passwords to stealing authenticated sessions, particularly in cloud productivity suites that underpin daily business operations.[2][9][11][12] CloudSEK and other researchers emphasize that phishing-resistant FIDO2/WebAuthn authentication—using hardware security keys bound to specific domains—remains resilient against Evilginx-style adversary-in-the-middle attacks because it does not rely on re-usable session cookies alone.[9][11][12] To limit exposure, organizations are urged to pair strong authentication with conditional access policies that evaluate device health, location and risk signals; enforce compliant or managed devices for administrative access; closely monitor sign-in telemetry for unusual cookie re-use or geo-improbable logins; and rapidly revoke suspected-compromised session and refresh tokens in Microsoft 365 and Entra ID.[2][12][15]
With BigBear 2.0 still assessed as active as of early September 2026, the operation highlights how turnkey phishing-as-a-service platforms are industrializing advanced adversary-in-the-middle techniques for a broad criminal customer base.[2][3][7][12] Security teams that have treated MFA as a near-complete safeguard against account takeover now face a rising class of session-hijacking attacks that exploit gaps in token management and device trust, making rigorous hardening of Microsoft 365 and identity infrastructure an urgent priority rather than a long-term roadmap item.
References
- Tracking BigBear 2.0 Evilginx2 Phishing Campaign
- BigBear обошёл MFA и похитил тысячи данных Microsoft 365
- BigBear PhaaS Exposes the MFA Bypass Reality: Session …
- BigBear 2.0 Evilginx2 Phishing-as-a-Service Campaign
- BigBear 2.0 – Mallory.ai
- BigBear 2.0 обошёл MFA в Microsoft 365 у 258 организаций
- Evilginx2: Bypass 2FA con Phishing Proxy Man-in-the-Middle
- Runbook: AiTM phishing with Evilginx2
- Bypassing MFA: A Forensic Look at Evilginx2 Phishing Kit
- CloudSEK Blog – Cybersecurity Insights
- Domain Spoofing Protection: BigBear MFA Phishing …
- BigBear 2.0: phishing burla MFA no Microsoft 365 | SempreUpdate