BigBear 2.0: Evilginx2 Phishing Platform Bypasses Microsoft 365 MFA at Scale

BigBear 2.0 phishing platform bypassing Microsoft 365 MFA with Evilginx2 AiTM attack

A user may enter the correct password, complete MFA verification, and still lose their Microsoft 365 account. The phishing platform BigBear 2.0 intercepts the authenticated session after the second factor and delivers the attacker ready-made access to the victim’s email, Teams, SharePoint, OneDrive, and all connected services.

BigBear 2.0 is built on Evilginx2 and operates as an Adversary-in-the-Middle attack. The victim opens a phishing link, whereupon a reverse proxy positions itself between the browser and the genuine Microsoft login page. The username, password, and second-factor prompt all pass through Microsoft’s legitimate system, so the user sees a familiar interface and successfully completes authentication.

The Core Theft Happens After MFA

The principal theft occurs only after MFA is satisfied. Microsoft issues the browser a session cookie confirming successful authentication, but the response first passes through the Evilginx2 server. BigBear 2.0 retains that cookie and can automatically replay the session in an entirely different browser, with no need for the attacker to re-enter a password, SMS code, TOTP, or push notification.

The operators have augmented standard Evilginx2 with their own JavaScript modifications. One script disables PublicKeyCredential in the browser and obstructs FIDO2/WebAuthn, steering the user toward SMS, a one-time code, or a push confirmation instead. BigBear 2.0 does not crack FIDO2 itself; cryptographic verification is bound to the genuine domain, so the platform instead attempts to coerce the victim into abandoning a phishing-resistant login method.

Other modifications suppress portions of Microsoft’s telemetry and automatically enable “Stay signed in” so that stolen sessions remain valid longer. For concealment, the infrastructure employs residential proxies drawn from 69 countries, matched geographically to the victim, so a login from India passes through an Indian IP address and arouses far less suspicion in policies scanning for sudden country changes.

The Scale of the Operation

The platform’s panel accumulated a striking volume of data: 5,137 records in total, among them 1,032 plaintext passwords, 4,148 session cookies, and 474 fully hijacked sessions after MFA. The records spanned 461 organizations and 3,331 unique IP addresses across more than 40 countries. India, France, and Saudi Arabia accounted for the largest share of victims, with IT companies and managed-service providers representing the most prominent targets.

As CloudSEK’s TRIAD researchers detail in their report, the platform was uncovered in June 2026 after the team gained administrative access to the attackers’ panel. Over the observation period, 42 VPS nodes cycled through the panel, and at least five affiliates were receiving stolen data via their own dedicated Telegram bots. The operator, working under the alias “General Boss,” has effectively turned the toolkit into a Phishing-as-a-Service offering available for lease to other criminals.

Defensive Recommendations

Against attacks of this kind, the mere fact of having MFA enabled is no longer sufficient. Organizations are advised to prohibit weak fallback authentication methods and migrate to FIDO2/WebAuthn. Furthermore, they should enforce trusted-device requirements through Conditional Access and, upon any suspected compromise, revoke not only the password but also active sessions and refresh tokens. Resetting the password alone may leave the attacker in possession of access already stolen.

Support Our Threat Intelligence

If you find our technology report and cybersecurity news helpful, consider supporting our work.

Crypto QR Code
USDT (TRC20):
TN8BdV8cp4T1Cd28gK9qTAnZknzzuwyUtm
USDT (ERC20):
0x3725e1a7d3bc5765499fa6aaafe307fabcd75bce

Leave a Reply