Tracking BigBear 2.0 Evilginx2 Phishing Campaign | CloudSEK

Tracking BigBear 2.0 Evilginx2 Phishing Campaign | CloudSEK
CloudSEK’s TRIAD uncovered BigBear 2.0, a rebranded Evilginx2-based phishing-as-a-service platform that targeted Microsoft 365 and enabled MFA bypass through AiTM session theft. The operation exfiltrated 5,137 credential records across 3,331 victim IPs in 40+ countries, used Telegram-driven credential delivery and geo-matched residential proxies, and remained active while evidence of counter-forensic cleanup was observed. #BigBear20 #Evilginx2 #GeneralBoss #Microsoft365 #Telegram

Keypoints

  • CloudSEK discovered BigBear 2.0 in June 2026 and gained admin access to the threat actor panel.
  • The framework was built on Evilginx2 and configured with the “offy” phishlet to target Microsoft 365 authentication.
  • The panel managed 42 VPS nodes, mostly hosted by The Constant Company LLC (Vultr), and used a multi-user PhaaS model.
  • Attackers captured 5,137 records, including 1,032 plaintext passwords, 4,148 session cookies, and 474 full MFA-bypassed authentications.
  • The campaign impacted 3,331 unique victim IPs across 40+ countries, with India, France, Saudi Arabia, New Zealand, and Germany leading.
  • Custom JavaScript disabled FIDO2/WebAuthn, blocked Microsoft telemetry, and auto-enabled “Keep Me Signed In” to prolong access.
  • Since late July 2026, 26 of the 42 VPS nodes were deleted from the panel, indicating active counter-forensic activity.

MITRE Techniques

  • [T1566.002 ] Spearphishing Link – Initial access was delivered through phishing URLs sent to victims (‘Victim clicks the phishing link’).
  • [T1557.001 ] Adversary-in-the-Middle – Evilginx2 relayed traffic between the victim and Microsoft login to intercept authentication (‘the proxy captures the session token’).
  • [T1550.004 ] Web Session Cookie – Stolen session cookies were replayed to hijack authenticated sessions (‘attacker replays the captured session cookie’).
  • [T1539 ] Steal Web Session Cookie – The proxy exfiltrated cookies from the login flow (‘session token is captured by the proxy’).
  • [T1056.003 ] Web Portal Capture – Credentials were harvested through a proxied Microsoft 365 login page (‘captures plaintext AND forwards to Microsoft’).
  • [T1078 ] Valid Accounts – Stolen credentials and cookies were used to access victim mailboxes and SaaS accounts (‘access the victim’s mailbox, Teams, SharePoint’).
  • [T1098 ] Account Manipulation – Post-compromise mailbox abuse such as rule creation was noted as a likely follow-on (‘mail rule creation post-theft’).
  • [T1573.001 ] Encrypted C2 – HTTPS was used between the proxy and Microsoft and for infrastructure communication (‘HTTPS-based C2 communication’).
  • [T1102 ] Web Service – Telegram APIs were used for real-time exfiltration and operator notification (‘stolen credentials in real time’).
  • [T1583.003 ] Virtual Private Server – The campaign relied on leased VPS infrastructure for hosting phishing nodes (’42 VPS nodes’).
  • [T1583.001 ] Domains – Multiple phishing domains were registered and used to host the lure pages (‘phishing domain registration’).
  • [T1588.002 ] Tool: Evilginx2 – The adversary used Evilginx2 as the core AiTM phishing framework (‘rebranded Evilginx2-based phishing-as-a-service’).

Indicators of Compromise

  • [IP Address ] Attacker VPS and historical infrastructure used for hosting phishing nodes – 130[.]94[.]82[.]180, 38[.]54[.]124[.]58, and other 20+ VPS IPs
  • [Domain ] Active phishing domains used in the campaign – konceptenterprises[.]com, annastudios-paros[.]com, dnsforward[.]com, and other domains
  • [Telegram Bot ] Credential exfiltration and operator coordination bots – @comeandget_bot, @botterxyz_bot, and other affiliate bots
  • [HTTP Header ] Evilginx/BigBear-specific headers observed in traffic – x-evg-token, x-evg-server, and x-evg-session
  • [Cookie Name ] Session cookies and admin cookies tied to the phishing framework – evginx_session, bigbear_session, and evginx_admin
  • [File/Artifact Name ] BigBear and Evilginx-related artifacts referenced in the panel – cookie.js, /api/jobs, and cookie replay outputs


Read more: https://www.cloudsek.com/blog/tracking-bigbear-2-0-evilginx2-phishing-campaign