Evilginx2 Phishing Steals Session Cookies, Bypasses Microsoft 365 MFA
Key Takeaways A sophisticated phishing campaign, dubbed BigBear 2.0, is actively targeting Microsoft 365 users. This operation leverages the Evilginx2 framework to bypass multi-factor authentication...
Key Takeaways
- A sophisticated phishing campaign, dubbed BigBear 2.0, is actively targeting Microsoft 365 users.
- This operation leverages the Evilginx2 framework to bypass multi-factor authentication (MFA) by stealing authenticated session cookies.
- The campaign has compromised over 5,000 records from 461 organizations across more than 40 countries, including complete authenticated sessions, passwords, and session cookies.
- IT services and managed service providers are primary targets, raising concerns about supply chain attacks.
- While MFA remains crucial, organizations must implement phishing-resistant authentication methods like FIDO2/WebAuthn and robust session management to counter these advanced attacks.
A new and aggressive phishing campaign, identified as BigBear 2.0, is successfully circumventing multi-factor authentication (MFA) to compromise Microsoft 365 accounts. This operation, utilizing the Evilginx2 phishing framework, focuses on stealing authenticated session cookies rather than directly breaking MFA mechanisms, enabling attackers to hijack active user sessions.
Table Of Content
The BigBear 2.0 campaign employs highly convincing phishing emails that direct victims to proxy websites. These sites meticulously mimic legitimate Microsoft sign-in pages. While users interact with what appears to be a genuine login process, the attacker’s proxy server silently intercepts credentials and, critically, captures the session data issued by Microsoft after successful authentication.
Security researchers at CloudSEK uncovered the BigBear 2.0 operation in June 2026 after gaining unauthorized access to its administrative panel. Their investigation revealed that the activity was linked to an operator known as “General Boss” and involved a network of 42 virtual private server (VPS) nodes. CloudSEK said in a report that the panel contained 5,137 stolen records affecting 461 organizations and 3,331 unique victim IP addresses spanning over 40 countries. These compromised records included 474 complete authenticated sessions, 1,032 passwords, and 4,148 session cookies, highlighting the attackers’ dual objective of immediate account access and establishing persistent footholds.
BigBear 2.0 Evilginx2 Phishing Campaign Bypasses Microsoft 365 MFA
The core of BigBear 2.0’s effectiveness lies in its adversary-in-the-middle (AiTM) architecture. This setup positions the attacker’s proxy between the victim and the legitimate Microsoft login service. The proxy captures the user’s email address and password, then forwards these details to Microsoft for validation. Crucially, it waits for the victim to complete their legitimate MFA challenge, whether it’s an approval notification or a code entry.
Once Microsoft successfully authenticates the user and issues an authenticated session cookie to the browser, the proxy intercepts this cookie before forwarding the response to the victim. This stolen cookie then allows the attacker to replay it in a separate browser, effectively gaining full access to the victim’s Microsoft 365 resources, including email, Teams, SharePoint, OneDrive, and any connected single sign-on (SSO) applications. This method bypasses MFA not by cracking it, but by stealing the proof of a successfully completed MFA session.
The campaign further enhanced its evasion capabilities by employing country-matched residential proxies and scripts designed to discourage users from employing more secure authentication methods like security keys. The primary targets of BigBear 2.0 included IT services and managed service providers, a concerning trend as compromising such entities can provide attackers with a gateway into multiple customer environments. At least five affiliates were associated with the observed control panel, indicating a growing service-based model for these advanced phishing kits.
What You Should Do
- Treat as an Identity Incident: Immediately respond to suspected cookie theft as a full identity compromise.
- Revoke and Reset: Reset affected user passwords, revoke all active sessions and refresh tokens, and mandate a new sign-in for compromised accounts.
- Conduct Thorough Audits: Examine mailbox forwarding rules, OAuth consent grants, unfamiliar application access, and sign-in activity logs for any post-hijack malicious actions.
- Implement Phishing-Resistant MFA: Prioritize and deploy FIDO2 or WebAuthn security keys and passkeys, as these methods cryptographically bind logins to legitimate sites, rendering proxy attacks less effective.
- Enforce Conditional Access: Utilize Conditional Access policies to require compliant devices and restrict access based on unusual residential IP ranges or new browser sessions. Shorten session lifetimes where appropriate.
- Enhance Email Filtering: Deploy advanced email filtering solutions capable of identifying and blocking links that mimic legitimate sign-in pages, even those with valid SSL certificates.
- Educate Users: Train users to verify unexpected sign-in requests by navigating directly to trusted bookmarks or known applications, rather than clicking on links in emails.
- Monitor for IoCs: Actively monitor network traffic and logs for the provided Indicators of Compromise (IoCs), including specific IP addresses, domains, Telegram bot tokens (defanged), and Evilginx-related HTTP headers and cookies.
| Type | Indicator | Description | |
|---|---|---|---|
| IP address | 38[.]60[.]250[.]157 |
BigBear 2.0 VPS node | |
| IP address | 95[.]179[.]233[.]79 |
BigBear 2.0 VPS node | |
| IP address | 80[.]240[.]27[.]55 |
BigBear 2.0 VPS node | |
| IP address | 65[.]20[.]103[.]58 |
BigBear 2.0 VPS node | |
| IP address | 38[.]54[.]124[.]88 |
BigBear 2.0 VPS node | |
| IP address | 208[.]85[.]20[.]79 |
BigBear 2.0 VPS node | |
| IP address | 95[.]179[.]169[.]154 |
BigBear 2.0 VPS node | |
| IP address | 107[.]191[.]46[.]14 |
BigBear 2.0 VPS node | |
| IP address | 130[.]94[.]82[.]180 |
BigBear 2.0 VPS node | |
| IP address | 38[.]54[.]124[.]58 |
BigBear 2.0 VPS node | |
| IP address | 208[.]85[.]18[.]18 |
BigBear 2.0 VPS node | |
| IP address | 45[.]32[.]147[.]239 |
BigBear 2.0 VPS node | |
| IP address | 208[.]76[.]222[.]214 |
BigBear 2.0 VPS node | |
| IP address | 130[.]94[.]82[.]230 |
BigBear 2.0 VPS node | |
| IP address | 65[.]20[.]102[.]80 |
BigBear 2.0 VPS node | |
| IP address | 70[.]34[.]208[.]46 |
Historical BigBear 2.0 VPS node | |
| IP address | 130[.]94[.]113[.]184 |
Historical BigBear 2.0 VPS node | |
| IP address | 78[.]141[.]193[.]59 |
Historical BigBear 2.0 VPS node | |
| IP address | 64[.]176[.]72[.]180 |
Historical BigBear 2.0 VPS node | |
| IP address | 136[.]244[.]114[.]85 |
Historical BigBear 2.0 VPS node | |
| IP address | 70[.]34[.]244[.]122 |
Historical BigBear 2.0 VPS node | |
| IP address | 199[.]247[.]10[.]14 |
Historical BigBear 2.0 VPS node | |
| IP address | 152[.]39[.]137[.]60 |
Historical BigBear 2.0 VPS node | |
| IP address | 91[.]245[.]235[.]208 |
Historical BigBear 2.0 VPS node | |
| IP address | 45[.]32[.]64[.]165 |
Historical BigBear 2.0 VPS node | |
| Domain | konceptenterprises[.]com |
Phishing domain | |
| Domain | ccpipharma[.]com |
Phishing domain | |
| Domain | annastudios-paros[.]com |
Phishing domain | |
| Domain | dnsforward[.]com |
Phishing domain | |
| Domain | hotelmidtownsurat[.]com |
Phishing domain | |
| Domain | dataclust[.]com |
Phishing domain | |
| Domain | cifutura[.]com |
Phishing domain | |
| Domain | hoaivt[.]com |
Phishing domain | |
| Domain | dronalms[.]com |
Phishing domain | |
| Domain | virextec[.]com |
Phishing domain | |
| Domain | offtic[.]com |
Phishing domain | |
| Domain | rootreseller[.]com |
Phishing domain | |
| Domain | management[.]michaelmarcotte[.]com |
Phishing domain | |
| Domain | kgsscans[.]com |
Phishing domain | |
| Domain | soil-management[.]com |
Phishing domain | |
| Domain | daengrentacar[.]com |
Historical phishing domain | |
| Domain | arrmmy[.]com |
Historical phishing domain | |
| Domain | captelind[.]com |
Historical phishing domain | |
| Domain | planisteradmin[.]com |
Historical phishing domain | |
| Domain | hnospascualfadon[.]com |
Historical phishing domain | |
| Domain | haliotisbar[.]com |
Historical phishing domain | |
| Domain | knowncontractor[.]com |
Historical phishing domain | |
| Domain | valtteri[.]net |
Historical phishing domain | |
| URL | management[.]daengrentacar[.]com/meetings |
Observed live Microsoft 365 phishing page | |
| Filename | cookie.js |
File attachment used in the credential-processing workflow | |
| Telegram bot | @comeandget_bot |
Primary administrator command-and-control bot, revoked | |
| Telegram bot token | 8629902848[:]AAGEFRukqwu9QaMSDNNuVRYF3juTcg4ehO4 |
Defanged token for revoked primary administrator bot | |
| Telegram bot | @botterxyz_bot |
Affiliate credential-exfiltration bot | |
| Telegram bot token | 8625043408[:]AAH6G8X0aW0QhoLEB1uJiYQ5-2aLSJzg8VE |
Defanged affiliate bot token | |
| Telegram bot | @PackingitonG_bot |
Affiliate credential-exfiltration bot | |
| Telegram bot token | 8783369414[:]AAGENRhb7By-0-cQFgrnOw1AW4NbOeUutVE |
Defanged affiliate bot token | |
| Telegram bot | @donplayer_bot |
Affiliate credential-exfiltration bot | |
| Telegram bot token | 8807072847[:]AAEYbUaFcbeAgxTZ2Zl8pFbpjRPM9jXvvzE |
Defanged affiliate bot token | |
| Telegram bot | @bolywan_bot |
Affiliate credential-exfiltration bot | |
| Telegram bot token | 8462028468[:]AAEQt7oq0c3nTHzApQtHk3RdZ7ifnkYd1XM |
Defanged affiliate bot token | |
| Telegram bot | @rdsxtdytguyg75d_bot |
Affiliate credential-exfiltration bot | |
| Telegram bot token | 8794520788[:]AAERSVBlWMpzHc21CCP_-9tL_pjqH9-WuFI |
Defanged affiliate bot token | |
| HTTP header | x-evg-token |
Evilginx-related application header | |
| HTTP header | x-evg-server |
Evilginx-related application header | |
| HTTP header | x-evg-session |
Evilginx-related application header | |
| Cookie | evginx_session |
Evilginx-related session cookie | |
| Cookie | evginx_token |
Evilginx-related token cookie | |
| Cookie | evginx_admin |
Evilginx-related administrator cookie | |
| Cookie | bigbear_session |
BigBear 2.0 session cookie | |
| Cookie | bigbear_token |
BigBear 2.0 token cookie |
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.