Tracking BigBear 2.0 Evilginx2 Phishing Campaign
In June 2026, researchers uncovered BigBear 2.0, a rebranded Evilginx2-based phishing-as-a-service framework targeting Microsoft 365 credentials globally. The operation, managed by operator 'General Boss', deployed 42 VPS nodes primarily hosted on Vultr infrastructure, utilizing the 'offy' phishlet configuration. The platform employed adversary-in-the-middle techniques with geo-matched residential proxy pools across 69 countries, real-time Telegram exfiltration, and automated cookie replay to bypass MFA. The campaign exfiltrated 5,137 credential records including 474 complete MFA-bypassed authentications, 1,032 plaintext passwords, and 4,148 session cookies, affecting 3,331 unique victim IPs across 40+ countries. The multi-user PhaaS panel was leased to at least five identified affiliate operators. Custom JavaScript injections disabled FIDO2/WebAuthn MFA while residential proxies bypassed anti-bot detection, enabling persistent access to compromised Microsoft 365 environments.
AI Analysis
Technical Summary
BigBear 2.0 is a rebranded Evilginx2-based phishing-as-a-service framework discovered in June 2026. It targets Microsoft 365 credentials globally by deploying 42 VPS nodes mainly on Vultr infrastructure and using the 'offy' phishlet configuration. The platform employs adversary-in-the-middle attacks combined with geo-matched residential proxy pools across 69 countries to evade detection and bypass multi-factor authentication (MFA), including disabling FIDO2/WebAuthn via custom JavaScript injections. The campaign exfiltrated 5,137 credential records, including 474 full MFA-bypassed authentications, 1,032 plaintext passwords, and 4,148 session cookies, affecting over 3,300 unique victim IPs in more than 40 countries. The service is multi-user and leased to at least five affiliate operators, with real-time data exfiltration via Telegram and automated cookie replay to maintain persistent access to compromised Microsoft 365 environments.
Potential Impact
The campaign compromises Microsoft 365 accounts by bypassing MFA protections, including advanced FIDO2/WebAuthn methods, enabling attackers to gain persistent unauthorized access. The exfiltration of plaintext passwords and session cookies allows attackers to impersonate users and maintain long-term access to victim environments. This undermines the security of affected organizations and individuals globally, potentially leading to data breaches, unauthorized access to sensitive information, and further exploitation within compromised networks.
Mitigation Recommendations
No direct patch or fix applies as this is a phishing campaign leveraging social engineering and technical bypasses of MFA. Organizations should enforce strong phishing awareness training, monitor for suspicious login activity, and consider additional protective measures such as conditional access policies and anomaly detection. Since this is a phishing-as-a-service operation, vigilance against phishing attempts and rapid incident response to compromised accounts are critical. The vendor advisory or authoritative source does not indicate any automated remediation or patch availability.
Indicators of Compromise
- domain: dronalms.com
- domain: ccpipharma.com
- domain: knowncontractor.com
- domain: hnospascualfadon.com
- ip: 130.94.113.184
- ip: 130.94.82.180
- ip: 130.94.82.230
- ip: 38.54.124.58
- ip: 38.54.124.88
- url: http://management.daengrentacar.com/meetings
- domain: annastudios-paros.com
- domain: arrmmy.com
- domain: captelind.com
- domain: cifutura.com
- domain: daengrentacar.com
- domain: dataclust.com
- domain: dnsforward.com
- domain: haliotisbar.com
- domain: hoaivt.com
- domain: hotelmidtownsurat.com
- domain: kgsscans.com
- domain: konceptenterprises.com
- domain: offtic.com
- domain: planisteradmin.com
- domain: rootreseller.com
- domain: soil-management.com
- domain: valtteri.net
- domain: virextec.com
- domain: login.evil-domain.com
- domain: login.konceptenterprises.com
- domain: management.daengrentacar.com
- domain: management.michaelmarcotte.com
- ip: 38.60.250.157
Tracking BigBear 2.0 Evilginx2 Phishing Campaign
Description
In June 2026, researchers uncovered BigBear 2.0, a rebranded Evilginx2-based phishing-as-a-service framework targeting Microsoft 365 credentials globally. The operation, managed by operator 'General Boss', deployed 42 VPS nodes primarily hosted on Vultr infrastructure, utilizing the 'offy' phishlet configuration. The platform employed adversary-in-the-middle techniques with geo-matched residential proxy pools across 69 countries, real-time Telegram exfiltration, and automated cookie replay to bypass MFA. The campaign exfiltrated 5,137 credential records including 474 complete MFA-bypassed authentications, 1,032 plaintext passwords, and 4,148 session cookies, affecting 3,331 unique victim IPs across 40+ countries. The multi-user PhaaS panel was leased to at least five identified affiliate operators. Custom JavaScript injections disabled FIDO2/WebAuthn MFA while residential proxies bypassed anti-bot detection, enabling persistent access to compromised Microsoft 365 environments.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
BigBear 2.0 is a rebranded Evilginx2-based phishing-as-a-service framework discovered in June 2026. It targets Microsoft 365 credentials globally by deploying 42 VPS nodes mainly on Vultr infrastructure and using the 'offy' phishlet configuration. The platform employs adversary-in-the-middle attacks combined with geo-matched residential proxy pools across 69 countries to evade detection and bypass multi-factor authentication (MFA), including disabling FIDO2/WebAuthn via custom JavaScript injections. The campaign exfiltrated 5,137 credential records, including 474 full MFA-bypassed authentications, 1,032 plaintext passwords, and 4,148 session cookies, affecting over 3,300 unique victim IPs in more than 40 countries. The service is multi-user and leased to at least five affiliate operators, with real-time data exfiltration via Telegram and automated cookie replay to maintain persistent access to compromised Microsoft 365 environments.
Potential Impact
The campaign compromises Microsoft 365 accounts by bypassing MFA protections, including advanced FIDO2/WebAuthn methods, enabling attackers to gain persistent unauthorized access. The exfiltration of plaintext passwords and session cookies allows attackers to impersonate users and maintain long-term access to victim environments. This undermines the security of affected organizations and individuals globally, potentially leading to data breaches, unauthorized access to sensitive information, and further exploitation within compromised networks.
Defensive Guidance
No direct patch or fix applies as this is a phishing campaign leveraging social engineering and technical bypasses of MFA. Organizations should enforce strong phishing awareness training, monitor for suspicious login activity, and consider additional protective measures such as conditional access policies and anomaly detection. Since this is a phishing-as-a-service operation, vigilance against phishing attempts and rapid incident response to compromised accounts are critical. The vendor advisory or authoritative source does not indicate any automated remediation or patch availability.
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://www.cloudsek.com/blog/tracking-bigbear-2-0-evilginx2-phishing-campaign"]
- Adversary
- General Boss
- Pulse Id
- 6a9ef10da8f75f1218af678c
- Threat Score
- null
Indicators of Compromise
Domain
| Value | Description | Copy |
|---|---|---|
domaindronalms.com | — | |
domainccpipharma.com | — | |
domainknowncontractor.com | — | |
domainhnospascualfadon.com | — | |
domainannastudios-paros.com | — | |
domainarrmmy.com | — | |
domaincaptelind.com | — | |
domaincifutura.com | — | |
domaindaengrentacar.com | — | |
domaindataclust.com | — | |
domaindnsforward.com | — | |
domainhaliotisbar.com | — | |
domainhoaivt.com | — | |
domainhotelmidtownsurat.com | — | |
domainkgsscans.com | — | |
domainkonceptenterprises.com | — | |
domainofftic.com | — | |
domainplanisteradmin.com | — | |
domainrootreseller.com | — | |
domainsoil-management.com | — | |
domainvaltteri.net | — | |
domainvirextec.com | — | |
domainlogin.evil-domain.com | — | |
domainlogin.konceptenterprises.com | — | |
domainmanagement.daengrentacar.com | — | |
domainmanagement.michaelmarcotte.com | — |
Ip
| Value | Description | Copy |
|---|---|---|
ip130.94.113.184 | — | |
ip130.94.82.180 | — | |
ip130.94.82.230 | — | |
ip38.54.124.58 | — | |
ip38.54.124.88 | — | |
ip38.60.250.157 | — |
Url
| Value | Description | Copy |
|---|---|---|
urlhttp://management.daengrentacar.com/meetings | — |
Threat ID: 6a9f9801acd9273b49092aa9
Added to database: 09/08/2026, 05:07:13 UTC
Last enriched: 09/08/2026, 05:24:10 UTC
Last updated: 09/08/2026, 13:03:56 UTC
Views: 42
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.