Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Tracking BigBear 2.0 Evilginx2 Phishing Campaign

0
Medium
Published: 09/07/2026 (09/07/2026, 17:14:53 UTC)
Source: AlienVault OTX General

Description

In June 2026, researchers uncovered BigBear 2.0, a rebranded Evilginx2-based phishing-as-a-service framework targeting Microsoft 365 credentials globally. The operation, managed by operator 'General Boss', deployed 42 VPS nodes primarily hosted on Vultr infrastructure, utilizing the 'offy' phishlet configuration. The platform employed adversary-in-the-middle techniques with geo-matched residential proxy pools across 69 countries, real-time Telegram exfiltration, and automated cookie replay to bypass MFA. The campaign exfiltrated 5,137 credential records including 474 complete MFA-bypassed authentications, 1,032 plaintext passwords, and 4,148 session cookies, affecting 3,331 unique victim IPs across 40+ countries. The multi-user PhaaS panel was leased to at least five identified affiliate operators. Custom JavaScript injections disabled FIDO2/WebAuthn MFA while residential proxies bypassed anti-bot detection, enabling persistent access to compromised Microsoft 365 environments.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/08/2026, 05:24:10 UTC

Technical Analysis

BigBear 2.0 is a rebranded Evilginx2-based phishing-as-a-service framework discovered in June 2026. It targets Microsoft 365 credentials globally by deploying 42 VPS nodes mainly on Vultr infrastructure and using the 'offy' phishlet configuration. The platform employs adversary-in-the-middle attacks combined with geo-matched residential proxy pools across 69 countries to evade detection and bypass multi-factor authentication (MFA), including disabling FIDO2/WebAuthn via custom JavaScript injections. The campaign exfiltrated 5,137 credential records, including 474 full MFA-bypassed authentications, 1,032 plaintext passwords, and 4,148 session cookies, affecting over 3,300 unique victim IPs in more than 40 countries. The service is multi-user and leased to at least five affiliate operators, with real-time data exfiltration via Telegram and automated cookie replay to maintain persistent access to compromised Microsoft 365 environments.

Potential Impact

The campaign compromises Microsoft 365 accounts by bypassing MFA protections, including advanced FIDO2/WebAuthn methods, enabling attackers to gain persistent unauthorized access. The exfiltration of plaintext passwords and session cookies allows attackers to impersonate users and maintain long-term access to victim environments. This undermines the security of affected organizations and individuals globally, potentially leading to data breaches, unauthorized access to sensitive information, and further exploitation within compromised networks.

Defensive Guidance

No direct patch or fix applies as this is a phishing campaign leveraging social engineering and technical bypasses of MFA. Organizations should enforce strong phishing awareness training, monitor for suspicious login activity, and consider additional protective measures such as conditional access policies and anomaly detection. Since this is a phishing-as-a-service operation, vigilance against phishing attempts and rapid incident response to compromised accounts are critical. The vendor advisory or authoritative source does not indicate any automated remediation or patch availability.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Author
AlienVault
Tlp
white
References
["https://www.cloudsek.com/blog/tracking-bigbear-2-0-evilginx2-phishing-campaign"]
Adversary
General Boss
Pulse Id
6a9ef10da8f75f1218af678c
Threat Score
null

Indicators of Compromise

Domain

ValueDescriptionCopy
domaindronalms.com
domainccpipharma.com
domainknowncontractor.com
domainhnospascualfadon.com
domainannastudios-paros.com
domainarrmmy.com
domaincaptelind.com
domaincifutura.com
domaindaengrentacar.com
domaindataclust.com
domaindnsforward.com
domainhaliotisbar.com
domainhoaivt.com
domainhotelmidtownsurat.com
domainkgsscans.com
domainkonceptenterprises.com
domainofftic.com
domainplanisteradmin.com
domainrootreseller.com
domainsoil-management.com
domainvaltteri.net
domainvirextec.com
domainlogin.evil-domain.com
domainlogin.konceptenterprises.com
domainmanagement.daengrentacar.com
domainmanagement.michaelmarcotte.com

Ip

ValueDescriptionCopy
ip130.94.113.184
ip130.94.82.180
ip130.94.82.230
ip38.54.124.58
ip38.54.124.88
ip38.60.250.157

Url

ValueDescriptionCopy
urlhttp://management.daengrentacar.com/meetings

Threat ID: 6a9f9801acd9273b49092aa9

Added to database: 09/08/2026, 05:07:13 UTC

Last enriched: 09/08/2026, 05:24:10 UTC

Last updated: 09/08/2026, 13:03:56 UTC

Views: 42

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses