Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Panzer Ransomware Targets Italian Firms with ESXi-Ready RaaS
September 8, 2026
US Offers $10M Reward for Iran IRGC Cyber Chief Linked to Critical Infrastructure Attacks
September 8, 2026
Best Managed XDR Services for 2026
September 8, 2026
Home/CyberSecurity News/Evilginx2 Phishing Steals Session Cookies, Bypasses Microsoft 365 MFA
CyberSecurity News

Evilginx2 Phishing Steals Session Cookies, Bypasses Microsoft 365 MFA

Key Takeaways A sophisticated phishing campaign, dubbed BigBear 2.0, is actively targeting Microsoft 365 users. This operation leverages the Evilginx2 framework to bypass multi-factor authentication...

Marcus Rodriguez
Marcus Rodriguez
September 8, 2026 4 Min Read
2 0

Key Takeaways

  • A sophisticated phishing campaign, dubbed BigBear 2.0, is actively targeting Microsoft 365 users.
  • This operation leverages the Evilginx2 framework to bypass multi-factor authentication (MFA) by stealing authenticated session cookies.
  • The campaign has compromised over 5,000 records from 461 organizations across more than 40 countries, including complete authenticated sessions, passwords, and session cookies.
  • IT services and managed service providers are primary targets, raising concerns about supply chain attacks.
  • While MFA remains crucial, organizations must implement phishing-resistant authentication methods like FIDO2/WebAuthn and robust session management to counter these advanced attacks.

A new and aggressive phishing campaign, identified as BigBear 2.0, is successfully circumventing multi-factor authentication (MFA) to compromise Microsoft 365 accounts. This operation, utilizing the Evilginx2 phishing framework, focuses on stealing authenticated session cookies rather than directly breaking MFA mechanisms, enabling attackers to hijack active user sessions.

Table Of Content

  • Key Takeaways
  • BigBear 2.0 Evilginx2 Phishing Campaign Bypasses Microsoft 365 MFA
  • What You Should Do

The BigBear 2.0 campaign employs highly convincing phishing emails that direct victims to proxy websites. These sites meticulously mimic legitimate Microsoft sign-in pages. While users interact with what appears to be a genuine login process, the attacker’s proxy server silently intercepts credentials and, critically, captures the session data issued by Microsoft after successful authentication.

Security researchers at CloudSEK uncovered the BigBear 2.0 operation in June 2026 after gaining unauthorized access to its administrative panel. Their investigation revealed that the activity was linked to an operator known as “General Boss” and involved a network of 42 virtual private server (VPS) nodes. CloudSEK said in a report that the panel contained 5,137 stolen records affecting 461 organizations and 3,331 unique victim IP addresses spanning over 40 countries. These compromised records included 474 complete authenticated sessions, 1,032 passwords, and 4,148 session cookies, highlighting the attackers’ dual objective of immediate account access and establishing persistent footholds.

BigBear 2.0 Evilginx2 Phishing Campaign Bypasses Microsoft 365 MFA

The core of BigBear 2.0’s effectiveness lies in its adversary-in-the-middle (AiTM) architecture. This setup positions the attacker’s proxy between the victim and the legitimate Microsoft login service. The proxy captures the user’s email address and password, then forwards these details to Microsoft for validation. Crucially, it waits for the victim to complete their legitimate MFA challenge, whether it’s an approval notification or a code entry.

Once Microsoft successfully authenticates the user and issues an authenticated session cookie to the browser, the proxy intercepts this cookie before forwarding the response to the victim. This stolen cookie then allows the attacker to replay it in a separate browser, effectively gaining full access to the victim’s Microsoft 365 resources, including email, Teams, SharePoint, OneDrive, and any connected single sign-on (SSO) applications. This method bypasses MFA not by cracking it, but by stealing the proof of a successfully completed MFA session.

The campaign further enhanced its evasion capabilities by employing country-matched residential proxies and scripts designed to discourage users from employing more secure authentication methods like security keys. The primary targets of BigBear 2.0 included IT services and managed service providers, a concerning trend as compromising such entities can provide attackers with a gateway into multiple customer environments. At least five affiliates were associated with the observed control panel, indicating a growing service-based model for these advanced phishing kits.

What You Should Do

  • Treat as an Identity Incident: Immediately respond to suspected cookie theft as a full identity compromise.
  • Revoke and Reset: Reset affected user passwords, revoke all active sessions and refresh tokens, and mandate a new sign-in for compromised accounts.
  • Conduct Thorough Audits: Examine mailbox forwarding rules, OAuth consent grants, unfamiliar application access, and sign-in activity logs for any post-hijack malicious actions.
  • Implement Phishing-Resistant MFA: Prioritize and deploy FIDO2 or WebAuthn security keys and passkeys, as these methods cryptographically bind logins to legitimate sites, rendering proxy attacks less effective.
  • Enforce Conditional Access: Utilize Conditional Access policies to require compliant devices and restrict access based on unusual residential IP ranges or new browser sessions. Shorten session lifetimes where appropriate.
  • Enhance Email Filtering: Deploy advanced email filtering solutions capable of identifying and blocking links that mimic legitimate sign-in pages, even those with valid SSL certificates.
  • Educate Users: Train users to verify unexpected sign-in requests by navigating directly to trusted bookmarks or known applications, rather than clicking on links in emails.
  • Monitor for IoCs: Actively monitor network traffic and logs for the provided Indicators of Compromise (IoCs), including specific IP addresses, domains, Telegram bot tokens (defanged), and Evilginx-related HTTP headers and cookies.
Type Indicator Description
IP address 38[.]60[.]250[.]157 BigBear 2.0 VPS node
IP address 95[.]179[.]233[.]79 BigBear 2.0 VPS node
IP address 80[.]240[.]27[.]55 BigBear 2.0 VPS node
IP address 65[.]20[.]103[.]58 BigBear 2.0 VPS node
IP address 38[.]54[.]124[.]88 BigBear 2.0 VPS node
IP address 208[.]85[.]20[.]79 BigBear 2.0 VPS node
IP address 95[.]179[.]169[.]154 BigBear 2.0 VPS node
IP address 107[.]191[.]46[.]14 BigBear 2.0 VPS node
IP address 130[.]94[.]82[.]180 BigBear 2.0 VPS node
IP address 38[.]54[.]124[.]58 BigBear 2.0 VPS node
IP address 208[.]85[.]18[.]18 BigBear 2.0 VPS node
IP address 45[.]32[.]147[.]239 BigBear 2.0 VPS node
IP address 208[.]76[.]222[.]214 BigBear 2.0 VPS node
IP address 130[.]94[.]82[.]230 BigBear 2.0 VPS node
IP address 65[.]20[.]102[.]80 BigBear 2.0 VPS node
IP address 70[.]34[.]208[.]46 Historical BigBear 2.0 VPS node
IP address 130[.]94[.]113[.]184 Historical BigBear 2.0 VPS node
IP address 78[.]141[.]193[.]59 Historical BigBear 2.0 VPS node
IP address 64[.]176[.]72[.]180 Historical BigBear 2.0 VPS node
IP address 136[.]244[.]114[.]85 Historical BigBear 2.0 VPS node
IP address 70[.]34[.]244[.]122 Historical BigBear 2.0 VPS node
IP address 199[.]247[.]10[.]14 Historical BigBear 2.0 VPS node
IP address 152[.]39[.]137[.]60 Historical BigBear 2.0 VPS node
IP address 91[.]245[.]235[.]208 Historical BigBear 2.0 VPS node
IP address 45[.]32[.]64[.]165 Historical BigBear 2.0 VPS node
Domain konceptenterprises[.]com Phishing domain
Domain ccpipharma[.]com Phishing domain
Domain annastudios-paros[.]com Phishing domain
Domain dnsforward[.]com Phishing domain
Domain hotelmidtownsurat[.]com Phishing domain
Domain dataclust[.]com Phishing domain
Domain cifutura[.]com Phishing domain
Domain hoaivt[.]com Phishing domain
Domain dronalms[.]com Phishing domain
Domain virextec[.]com Phishing domain
Domain offtic[.]com Phishing domain
Domain rootreseller[.]com Phishing domain
Domain management[.]michaelmarcotte[.]com Phishing domain
Domain kgsscans[.]com Phishing domain
Domain soil-management[.]com Phishing domain
Domain daengrentacar[.]com Historical phishing domain
Domain arrmmy[.]com Historical phishing domain
Domain captelind[.]com Historical phishing domain
Domain planisteradmin[.]com Historical phishing domain
Domain hnospascualfadon[.]com Historical phishing domain
Domain haliotisbar[.]com Historical phishing domain
Domain knowncontractor[.]com Historical phishing domain
Domain valtteri[.]net Historical phishing domain
URL management[.]daengrentacar[.]com/meetings Observed live Microsoft 365 phishing page
Filename cookie.js File attachment used in the credential-processing workflow
Telegram bot @comeandget_bot Primary administrator command-and-control bot, revoked
Telegram bot token 8629902848[:]AAGEFRukqwu9QaMSDNNuVRYF3juTcg4ehO4 Defanged token for revoked primary administrator bot
Telegram bot @botterxyz_bot Affiliate credential-exfiltration bot
Telegram bot token 8625043408[:]AAH6G8X0aW0QhoLEB1uJiYQ5-2aLSJzg8VE Defanged affiliate bot token
Telegram bot @PackingitonG_bot Affiliate credential-exfiltration bot
Telegram bot token 8783369414[:]AAGENRhb7By-0-cQFgrnOw1AW4NbOeUutVE Defanged affiliate bot token
Telegram bot @donplayer_bot Affiliate credential-exfiltration bot
Telegram bot token 8807072847[:]AAEYbUaFcbeAgxTZ2Zl8pFbpjRPM9jXvvzE Defanged affiliate bot token
Telegram bot @bolywan_bot Affiliate credential-exfiltration bot
Telegram bot token 8462028468[:]AAEQt7oq0c3nTHzApQtHk3RdZ7ifnkYd1XM Defanged affiliate bot token
Telegram bot @rdsxtdytguyg75d_bot Affiliate credential-exfiltration bot
Telegram bot token 8794520788[:]AAERSVBlWMpzHc21CCP_-9tL_pjqH9-WuFI Defanged affiliate bot token
HTTP header x-evg-token Evilginx-related application header
HTTP header x-evg-server Evilginx-related application header
HTTP header x-evg-session Evilginx-related application header
Cookie evginx_session Evilginx-related session cookie
Cookie evginx_token Evilginx-related token cookie
Cookie evginx_admin Evilginx-related administrator cookie
Cookie bigbear_session BigBear 2.0 session cookie
Cookie bigbear_token BigBear 2.0 token cookie

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackphishingSecurityThreat

Share Article

Marcus Rodriguez

Marcus Rodriguez

Marcus is a security researcher and investigative journalist with expertise in vulnerability research, bug bounties, and cloud security. Since 2017, Marcus has been breaking stories on critical vulnerabilities affecting major platforms. His investigative work has led to the disclosure of numerous security flaws and improved defenses across the industry. Marcus is an active participant in bug bounty programs and has been recognized for responsible disclosure practices. He holds multiple security certifications and regularly speaks at industry events.

Previous Post

AI Customer Service Bots Vulnerable to Security Code Theft

Next Post

Best Managed XDR Services for 2026

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Critical Flaw in HashiCorp Terraform Registry Lets Attackers Steal Cloud Credentials
September 8, 2026
Top 10 Web Application Firewall Solutions for 2026
September 8, 2026
Top Firewall-as-a-Service (FWaaS) Providers in 2026
September 8, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us