Tracking BigBear 2.0 Evilginx2 Phishing Campaign

Published September 7, 2026

BigBear 2.0 is a phishing-as-a-service tool that steals Microsoft 365 login details, even when users have two-factor authentication. Attackers set up fake login pages to trick people into entering their work emails and passwords, then use tricks like fake locations and stolen session tokens to break into accounts.

Report priority
Medium
Targets
Threat actor: General Boss+3 more

How it works

  • Attackers set up fake Microsoft 365 login pages on hacked websites or rented servers.
  • When victims enter their work email and password, the fake page sends those details to the attackers.
  • The attackers also use fake internet addresses and stolen session tokens to bypass two-factor authentication, letting them take over real accounts.
  • Custom code blocks extra security like FIDO2 keys, and rented computers spread across many countries help avoid detection.
  • This lets attackers move freely inside the victim's Microsoft 365 account after stealing credentials.

What to do

If you work for a company in the British Indian Ocean Territory, France, Germany, or the energy/technology sectors and use Microsoft 365 for work emails or files, check if your company received phishing emails or fake login pages asking for your Microsoft 365 password. If you clicked on a suspicious link and entered your credentials, contact your company's IT team to report the incident and ask if they've seen similar attacks. Microsoft 365 does not provide a direct check for stolen credentials, but you can review recent sign-in activity in your account settings under 'Security' or 'Activity' to spot unauthorized logins.

If you suspect your account was compromised, change your Microsoft 365 password immediately and enable additional security settings like app-specific passwords or security keys. Microsoft also offers a security dashboard where you can review suspicious activity. If your company uses Microsoft Defender for Office 365, enable phishing protection to block fake login pages in the future.

Technical details

Affected software: Threat actor: General Boss, Technology, Energy, Targets: British Indian Ocean Territory, France, Germany

In June 2026, attackers rented 42 servers to run fake Microsoft 365 login pages. They tricked employees at a French energy company into entering their work credentials on these pages. The attackers then used stolen session tokens and fake locations to break into the real accounts, sending stolen data to a Telegram chat. Over 5,000 credentials were stolen from victims in 40+ countries, including 474 full logins that bypassed two-factor authentication.

In June 2026, researchers identified BigBear 2.0, a rebranded Evilginx2-based phishing-as-a-service (PhaaS) framework targeting Microsoft 365 credentials. Operated by "General Boss," the campaign deployed 42 virtual private server (VPS) nodes (primarily on Vultr) using the "offy" phishlet configuration. Attackers leveraged adversary-in-the-middle (AiTM) techniques, geo-matched residential proxies across 69 countries, and automated cookie replay to bypass multi-factor authentication (MFA), exfiltrating 5,137 credential records, including 474 full MFA-bypassed authentications, 1,032 plaintext passwords, and 4,148 session cookies, from 3,331 unique victim IPs in over 40 countries.

The PhaaS platform was leased to at least five affiliate operators, with custom JavaScript injections disabling FIDO2/WebAuthn MFA and residential proxies evading anti-bot defenses, enabling persistent access to compromised Microsoft 365 accounts. The campaign was tracked under OTX-6a9ef10da8f75f1218af678c.