VYPR
advisoryPublished Sep 8, 2026· 2 sources

BigBear 2.0 Campaign Leverages Evilginx2 to Steal Microsoft 365 Session Cookies Post-MFA

The BigBear 2.0 phishing operation, a rebranded Evilginx2 framework, targets Microsoft 365 accounts by stealing session cookies post-MFA, enabling account takeover.

A sophisticated phishing operation known as BigBear 2.0 is actively targeting Microsoft 365 accounts by employing a rebranded Evilginx2 framework. This campaign focuses on bypassing multi-factor authentication (MFA) not by breaking the authentication itself, but by stealing authenticated session cookies after MFA has been successfully completed. This allows attackers to hijack active user sessions and gain unauthorized access to sensitive data and services.

The BigBear 2.0 operation utilizes adversary-in-the-middle (AitM) techniques. Victims are lured through phishing emails containing links that direct them to proxy pages designed to mimic legitimate Microsoft sign-in portals. While the proxy relays traffic to the genuine Microsoft service, it simultaneously captures the user's credentials and, crucially, the session cookie generated after the user successfully authenticates via MFA. This stolen cookie is then replayed by the attacker in a separate browser, granting them access to the victim's Microsoft 365 environment, including applications like Teams, SharePoint, and OneDrive.

CloudSEK analysts discovered BigBear 2.0 in June 2026 after gaining access to its administrative panel. The investigation linked the operation to an actor using the alias "General Boss" and uncovered a network of 42 virtual private server (VPS) nodes. The panel contained a significant trove of compromised data, including 5,137 stolen records associated with 461 organizations and 3,331 unique victim IP addresses across more than 40 countries. This data comprised 474 complete authenticated sessions, 1,032 passwords, and 4,148 session cookies, indicating a broad reach and the potential for both immediate and persistent access.

The campaign's success hinges on its ability to capture the session cookie post-MFA. While MFA methods like one-time passwords, SMS codes, or push notifications are effective at verifying user identity during the login process, they do not inherently prevent the theft of the resulting authenticated session token. BigBear 2.0 enhances its effectiveness by using country-matched residential proxies and employing scripts designed to steer users away from more secure authentication methods like hardware security keys.

This campaign has disproportionately affected IT services and managed service providers (MSPs). The compromise of MSPs is particularly concerning, as it can provide attackers with a direct pathway into the environments of their numerous clients. At least five affiliates have been linked to the BigBear 2.0 panel, suggesting a service-based model where phishing kits are distributed and utilized by multiple actors.

To mitigate the risks posed by stolen session cookies, organizations should treat such incidents as full identity compromises. This involves resetting affected passwords, revoking active sessions and refresh tokens, and forcing re-authentication for impacted accounts. Security teams should meticulously examine mailbox forwarding rules, OAuth consent grants, unfamiliar application access, and sign-in activity for any signs of post-authentication misuse.

Long-term defenses against such attacks include the adoption of phishing-resistant authentication methods, such as FIDO2 or WebAuthn security keys and passkeys, which cryptographically bind logins to legitimate sites. Additionally, administrators should enforce compliant devices through Conditional Access policies, shorten session lifetimes, and monitor for unusual IP ranges or new browser sessions. Users should exercise caution with email links, verifying unexpected sign-in requests through trusted bookmarks rather than direct email links, as a seemingly familiar Microsoft page and a successful MFA prompt do not guarantee a direct, secure connection to the service.

The BigBear 2.0 phishing-as-a-service (PhaaS) campaign has escalated, with researchers now reporting over 5,000 compromised Microsoft credentials. This new information highlights the significant scale of the operation, which continues to leverage sophisticated techniques to target Microsoft 365 users.

Synthesized by Vypr AI