BigBear 2.0 is a global Microsoft 365 phishing-as-a-service operation targeting hundreds of organizations across 100+ countries. The investigation exposed the attacker’s admin panel, affiliate network, phishing infrastructure, and thousands of stolen credentials and session cookies. The BigBear panel uses Evilginx2 as its core technique, employing Adversary-in-the-Middle (AiTM) phishing to hijack authenticated sessions even after MFA. The "offy" phishlet specifically targets the OAuth 2.0 authorization flow used by Microsoft 365, making it effective against any organization using Azure AD / Entra ID for authentication. The panel has exfiltrated 5,137 credential records, including 474 complete MFA-bypassed authentications, 1,032 plaintext passwords, and 4,148 session cookies. The campaign uses geo-matched residential proxy pools to bypass Microsoft's geo-anomaly detection and IP blacklists.
The attacker manipulates the authentication flow so the victim ends up using an alternative authentication method that is weaker or not phishing-resistant. Each Evilginx2 instance terminates the victim's TLS connection at the phishing domain, making forensic attribution difficult. The campaign has been active for several months, with 42 VPS nodes observed across various regions. The panel supports role-based access and multi-tenant design consistent with a Phishing-as-a-Service (PhaaS) business model. The attacker uses Telegram bots to exfiltrate stolen credentials in real-time, with at least five affiliate operators identified through live probing.[/subscribe_to_unlock_form]
BigBear 2.0 is a global Microsoft 365 phishing-as-a-service operation targeting hundreds of organizations across 100+ countries. The investigation exposed the attacker’s admin panel, affiliate network, phishing infrastructure, and thousands of stolen credentials and session cookies. The BigBear panel uses Evilginx2 as its core technique, employing Adversary-in-the-Middle (AiTM) phishing to hijack authenticated sessions even after MFA. The "offy" phishlet specifically targets the OAuth 2.0 authorization flow used by Microsoft 365, making it effective against any organization using Azure AD / Entra ID for authentication. The panel has exfiltrated 5,137 credential records, including 474 complete MFA-bypassed authentications, 1,032 plaintext passwords, and 4,148 session cookies. The campaign uses geo-matched residential proxy pools to bypass Microsoft's geo-anomaly detection and IP blacklists.
The attacker manipulates the authentication flow so the victim ends up using an alternative authentication method that is weaker or not phishing-resistant. Each Evilginx2 instance terminates the victim's TLS connection at the phishing domain, making forensic attribution difficult. The campaign has been active for several months, with 42 VPS nodes observed across various regions. The panel supports role-based access and multi-tenant design consistent with a Phishing-as-a-Service (PhaaS) business model. The attacker uses Telegram bots to exfiltrate stolen credentials in real-time, with at least five affiliate operators identified through live probing.[emaillocker id="1283"]
The campaign has affected 3,331 unique victim IPs across 40+ countries, with India being the most-targeted country. The targeted sectors include IT Services/MSP, SaaS/Technology, Oil & Gas, Pharmaceuticals, and Consulting. The campaign is characterized by a hybrid targeting model using both broad email list spraying and sector-specific lists. The panel includes custom JavaScript injections that disable FIDO2/WebAuthn MFA and residential proxy pools bypass ipapi.is anti-bot detection. The keepalive feature periodically refreshes captured session cookies to extend the window of access beyond the initial cookie expiry. BigBear 2.0 exposes a REST API endpoint for programmatic, bulk session hijacking without manual browser intervention.
| Tactic | Technique Id | Technique | Sub-technique |
|---|---|---|---|
| Initial access | T1566.002 | Phishing | Spearphishing Link |
| Persistence | T1547.001 | Boot or Logon Autostart Execution | Registry Run Keys / Startup Folder |
| Defence Evasion | T1036.005 | Masquerading | Match Legitimate Resource Name or Location |
| Credential access | T1555.003 | Credentials from Password Stores | Credentials from Web Browsers |
| Command and control | T1071.001 | Application Layer Protocol | Web Protocols |
| Command and control | T1105 | Ingress Tool Transfer | - |
| Exfiltration | T1041 | Exfiltration Over C2 Channel | - |
| Exfiltration | T1567.002 | Exfiltration Over Web Service | Exfiltration to Cloud Storage |
The following reports contain further technical details:
[/emaillocker]