BigBear 2.0 Evilginx2 Phishing Campaign Bypasses Microsoft 365 MFA With Session Cookie Theft
Brief
BigBear 2.0 is a phishing operation designed to steal proof that a user has already passed multi-factor authentication.
It targets Microsoft 365 accounts through convincing sign-in links, then takes over the logged-in browser session rather than attempting to break the authentication factor.
The operation is a rebranded Evilginx2 phishing framework that targets Microsoft 365 accounts. Victims are drawn in through email links that open a proxy page resembling a Microsoft sign-in page.
It relays their traffic to the genuine service while quietly collecting credentials and the session data returned after sign-in.
CloudSEK analysts identified BigBear 2. 0 in June 2026 after gaining access to its administrative panel. The researchers linked the activity to an operator using the alias General Boss and found a network of 42 virtual private server nodes.
