BigBear 2.0 Evilginx2 Phishing Campaign Bypasses Microsoft 365 MFA With Session Cookie Theft

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Spread the love

BigBear 2.0 is a phishing operation designed to steal proof that a user has already passed multi-factor authentication.

It targets Microsoft 365 accounts through convincing sign-in links, then takes over the logged-in browser session rather than attempting to break the authentication factor.

The operation is a rebranded Evilginx2 phishing framework that targets Microsoft 365 accounts. Victims are drawn in through email links that open a proxy page resembling a Microsoft sign-in page.

It relays their traffic to the genuine service while quietly collecting credentials and the session data returned after sign-in.

CloudSEK analysts identified BigBear 2.0 in June 2026 after gaining access to its administrative panel. The researchers linked the activity to an operator using the alias General Boss and found a network of 42 virtual private server nodes.

CloudSEK said in a report shared with Cyber Security News (CSN) that the panel held 5,137 stolen records tied to 461 organizations and 3,331 unique victim IP addresses across more than 40 countries.

Of those records, 474 represented complete authenticated sessions, alongside 1,032 passwords and 4,148 session cookies. The records illustrate an operation that collects both immediate account access and material that may support persistent access later.

BigBear 2.0 Evilginx2 Phishing Campaign Bypasses Microsoft 365 MFA

BigBear 2.0 uses an adversary-in-the-middle setup, meaning it sits between the victim and the real Microsoft login service.

It captures the email address and password, lets Microsoft validate the request, and waits for the victim to complete their normal approval or code challenge.

Campaign Timeline (Source - CloudSEK)
Campaign Timeline (Source – CloudSEK)

When sign-in succeeds, Microsoft sends an authenticated session cookie to the browser. Because the proxy handled the exchange, it can copy that cookie before forwarding the response.

The attacker can replay it in another browser and enter email, Teams, SharePoint, OneDrive, and connected single sign-on applications as the victim. Microsoft 365 session hijacking campaigns have reported the same account-takeover risk.

This is not a weakness in a one-time password, SMS code, or push notification by itself. These methods confirm the user during the live session, but the proxy steals the resulting proof. BigBear used country-matched residential proxies and scripts that pushed users away from security-key authentication.

The campaign particularly affected IT services and managed service providers, a concern because one compromised provider can offer attackers a route into customer environments.

At least five affiliates were linked to the panel. Phishing kits targeting organizations show this service-based model is spreading.

Containing identity compromise

Organizations should treat a suspected stolen cookie as an identity incident, not merely a password problem. Reset affected passwords, revoke active sessions and refresh tokens, and force a new sign-in for impacted accounts.

Teams should examine mailbox forwarding rules, OAuth consent grants, unfamiliar application access, and sign-in activity for evidence that a hijacked session was used after authentication. This review should begin as soon as suspicious activity is reported.

The most useful long-term control is phishing-resistant authentication, especially FIDO2 or WebAuthn security keys and passkeys where properly deployed.

These methods bind a login cryptographically to the genuine site, making a lookalike proxy far less useful. Passkey attack techniques nevertheless deserve ongoing attention.

Phishlet sample (Source - CloudSEK)
Phishlet sample (Source – CloudSEK)

Administrators should require compliant devices through Conditional Access, shorten session lifetimes where appropriate, and watch for unusual residential IP ranges or new browser sessions.

Email filtering should inspect links that imitate sign-in pages even when they use valid certificates. Teams can monitor for the distinctive headers and cookies listed below, because infrastructure can be reassigned.

For users, a familiar Microsoft page and successful MFA prompt do not always prove that a browser is connected directly to Microsoft.

Verify unexpected sign-in requests through a trusted bookmark or known application, not an email link. This concern is reinforced by Evilginx session-cookie attacks, which also depend on real-time relaying rather than stolen passwords alone.

The campaign combined cookie theft, geographic proxy matching, and affiliate access. MFA must be paired with phishing-resistant methods, session controls, and rapid token revocation.

Indicators of compromise (IoCs):-

Type Indicator Description
IP address 38[.]60[.]250[.]157 BigBear 2.0 VPS node
IP address 95[.]179[.]233[.]79 BigBear 2.0 VPS node
IP address 80[.]240[.]27[.]55 BigBear 2.0 VPS node
IP address 65[.]20[.]103[.]58 BigBear 2.0 VPS node
IP address 38[.]54[.]124[.]88 BigBear 2.0 VPS node
IP address 208[.]85[.]20[.]79 BigBear 2.0 VPS node
IP address 95[.]179[.]169[.]154 BigBear 2.0 VPS node
IP address 107[.]191[.]46[.]14 BigBear 2.0 VPS node
IP address 130[.]94[.]82[.]180 BigBear 2.0 VPS node
IP address 38[.]54[.]124[.]58 BigBear 2.0 VPS node
IP address 208[.]85[.]18[.]18 BigBear 2.0 VPS node
IP address 45[.]32[.]147[.]239 BigBear 2.0 VPS node
IP address 208[.]76[.]222[.]214 BigBear 2.0 VPS node
IP address 130[.]94[.]82[.]230 BigBear 2.0 VPS node
IP address 65[.]20[.]102[.]80 BigBear 2.0 VPS node
IP address 70[.]34[.]208[.]46 Historical BigBear 2.0 VPS node
IP address 130[.]94[.]113[.]184 Historical BigBear 2.0 VPS node
IP address 78[.]141[.]193[.]59 Historical BigBear 2.0 VPS node
IP address 64[.]176[.]72[.]180 Historical BigBear 2.0 VPS node
IP address 136[.]244[.]114[.]85 Historical BigBear 2.0 VPS node
IP address 70[.]34[.]244[.]122 Historical BigBear 2.0 VPS node
IP address 199[.]247[.]10[.]14 Historical BigBear 2.0 VPS node
IP address 152[.]39[.]137[.]60 Historical BigBear 2.0 VPS node
IP address 91[.]245[.]235[.]208 Historical BigBear 2.0 VPS node
IP address 45[.]32[.]64[.]165 Historical BigBear 2.0 VPS node
Domain konceptenterprises[.]com Phishing domain
Domain ccpipharma[.]com Phishing domain
Domain annastudios-paros[.]com Phishing domain
Domain dnsforward[.]com Phishing domain
Domain hotelmidtownsurat[.]com Phishing domain
Domain dataclust[.]com Phishing domain
Domain cifutura[.]com Phishing domain
Domain hoaivt[.]com Phishing domain
Domain dronalms[.]com Phishing domain
Domain virextec[.]com Phishing domain
Domain offtic[.]com Phishing domain
Domain rootreseller[.]com Phishing domain
Domain management[.]michaelmarcotte[.]com Phishing domain
Domain kgsscans[.]com Phishing domain
Domain soil-management[.]com Phishing domain
Domain daengrentacar[.]com Historical phishing domain
Domain arrmmy[.]com Historical phishing domain
Domain captelind[.]com Historical phishing domain
Domain planisteradmin[.]com Historical phishing domain
Domain hnospascualfadon[.]com Historical phishing domain
Domain haliotisbar[.]com Historical phishing domain
Domain knowncontractor[.]com Historical phishing domain
Domain valtteri[.]net Historical phishing domain
URL management[.]daengrentacar[.]com/meetings Observed live Microsoft 365 phishing page
Filename cookie.js File attachment used in the credential-processing workflow
Telegram bot @comeandget_bot Primary administrator command-and-control bot, revoked
Telegram bot token 8629902848[:]AAGEFRukqwu9QaMSDNNuVRYF3juTcg4ehO4 Defanged token for revoked primary administrator bot
Telegram bot @botterxyz_bot Affiliate credential-exfiltration bot
Telegram bot token 8625043408[:]AAH6G8X0aW0QhoLEB1uJiYQ5-2aLSJzg8VE Defanged affiliate bot token
Telegram bot @PackingitonG_bot Affiliate credential-exfiltration bot
Telegram bot token 8783369414[:]AAGENRhb7By-0-cQFgrnOw1AW4NbOeUutVE Defanged affiliate bot token
Telegram bot @donplayer_bot Affiliate credential-exfiltration bot
Telegram bot token 8807072847[:]AAEYbUaFcbeAgxTZ2Zl8pFbpjRPM9jXvvzE Defanged affiliate bot token
Telegram bot @bolywan_bot Affiliate credential-exfiltration bot
Telegram bot token 8462028468[:]AAEQt7oq0c3nTHzApQtHk3RdZ7ifnkYd1XM Defanged affiliate bot token
Telegram bot @rdsxtdytguyg75d_bot Affiliate credential-exfiltration bot
Telegram bot token 8794520788[:]AAERSVBlWMpzHc21CCP_-9tL_pjqH9-WuFI Defanged affiliate bot token
HTTP header x-evg-token Evilginx-related application header
HTTP header x-evg-server Evilginx-related application header
HTTP header x-evg-session Evilginx-related application header
Cookie evginx_session Evilginx-related session cookie
Cookie evginx_token Evilginx-related token cookie
Cookie evginx_admin Evilginx-related administrator cookie
Cookie bigbear_session BigBear 2.0 session cookie
Cookie bigbear_token BigBear 2.0 token cookie

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Keep your SOC up to date on active malware & phishing within 24h of their emergence. Try ANYRUN to prevent incidents with early detection.

The post BigBear 2.0 Evilginx2 Phishing Campaign Bypasses Microsoft 365 MFA With Session Cookie Theft appeared first on Cyber Security News.