Threat Advisory

Evilginx2 Phishing Campaign Hijacks Authenticated Sessions with MFA Bypass

Threat: Phishing Campaign
Threat Actor Name: General Boss
Threat Actor Type: cybercriminal
Targeted Region: India, France, Germany
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

BigBear 2.0 is a global Microsoft 365 phishing-as-a-service operation targeting hundreds of organizations across 100+ countries. The investigation exposed the attacker’s admin panel, affiliate network, phishing infrastructure, and thousands of stolen credentials and session cookies. The BigBear panel uses Evilginx2 as its core technique, employing Adversary-in-the-Middle (AiTM) phishing to hijack authenticated sessions even after MFA. The "offy" phishlet specifically targets the OAuth 2.0 authorization flow used by Microsoft 365, making it effective against any organization using Azure AD / Entra ID for authentication. The panel has exfiltrated 5,137 credential records, including 474 complete MFA-bypassed authentications, 1,032 plaintext passwords, and 4,148 session cookies. The campaign uses geo-matched residential proxy pools to bypass Microsoft's geo-anomaly detection and IP blacklists.

The attacker manipulates the authentication flow so the victim ends up using an alternative authentication method that is weaker or not phishing-resistant. Each Evilginx2 instance terminates the victim's TLS connection at the phishing domain, making forensic attribution difficult. The campaign has been active for several months, with 42 VPS nodes observed across various regions. The panel supports role-based access and multi-tenant design consistent with a Phishing-as-a-Service (PhaaS) business model. The attacker uses Telegram bots to exfiltrate stolen credentials in real-time, with at least five affiliate operators identified through live probing.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

BigBear 2.0 is a global Microsoft 365 phishing-as-a-service operation targeting hundreds of organizations across 100+ countries. The investigation exposed the attacker’s admin panel, affiliate network, phishing infrastructure, and thousands of stolen credentials and session cookies. The BigBear panel uses Evilginx2 as its core technique, employing Adversary-in-the-Middle (AiTM) phishing to hijack authenticated sessions even after MFA. The "offy" phishlet specifically targets the OAuth 2.0 authorization flow used by Microsoft 365, making it effective against any organization using Azure AD / Entra ID for authentication. The panel has exfiltrated 5,137 credential records, including 474 complete MFA-bypassed authentications, 1,032 plaintext passwords, and 4,148 session cookies. The campaign uses geo-matched residential proxy pools to bypass Microsoft's geo-anomaly detection and IP blacklists.

The attacker manipulates the authentication flow so the victim ends up using an alternative authentication method that is weaker or not phishing-resistant. Each Evilginx2 instance terminates the victim's TLS connection at the phishing domain, making forensic attribution difficult. The campaign has been active for several months, with 42 VPS nodes observed across various regions. The panel supports role-based access and multi-tenant design consistent with a Phishing-as-a-Service (PhaaS) business model. The attacker uses Telegram bots to exfiltrate stolen credentials in real-time, with at least five affiliate operators identified through live probing.[emaillocker id="1283"]

The campaign has affected 3,331 unique victim IPs across 40+ countries, with India being the most-targeted country. The targeted sectors include IT Services/MSP, SaaS/Technology, Oil & Gas, Pharmaceuticals, and Consulting. The campaign is characterized by a hybrid targeting model using both broad email list spraying and sector-specific lists. The panel includes custom JavaScript injections that disable FIDO2/WebAuthn MFA and residential proxy pools bypass ipapi.is anti-bot detection. The keepalive feature periodically refreshes captured session cookies to extend the window of access beyond the initial cookie expiry. BigBear 2.0 exposes a REST API endpoint for programmatic, bulk session hijacking without manual browser intervention.

THREAT PROFILE:

Tactic Technique Id Technique Sub-technique
Initial access T1566.002 Phishing Spearphishing Link
Persistence T1547.001 Boot or Logon Autostart Execution Registry Run Keys / Startup Folder
Defence Evasion T1036.005 Masquerading Match Legitimate Resource Name or Location
Credential access T1555.003 Credentials from Password Stores Credentials from Web Browsers
Command and control T1071.001 Application Layer Protocol Web Protocols
Command and control T1105 Ingress Tool Transfer -
Exfiltration T1041 Exfiltration Over C2 Channel -
Exfiltration T1567.002 Exfiltration Over Web Service Exfiltration to Cloud Storage

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu