BigBear 2.0 is a phishing-as-a-service operation built on the Evilginx2 adversary-in-the-middle framework. It targets Microsoft 365 accounts by proxying legitimate authentication flows, capturing credentials and authenticated session cookies after victims complete multi-factor authentication. The operation replays stolen cookies to hijack sessions and access Microsoft 365 services and connected single-sign-on applications without defeating the MFA factor directly. The service uses geo-matched residential proxies, automated cookie replay, virtual private server infrastructure, and Telegram-based delivery of captured data. It has been linked to an operator using the alias General Boss and to multiple affiliates. Observed victim organizations span more than 40 countries, with IT services and managed service providers particularly affected, creating potential downstream supply-chain exposure for their customers. Documented targets include organizations in India, France, Saudi Arabia, New Zealand, and Germany.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Phishing-as-a-service operation targeting Microsoft 365 credentials. The operation used adversary-in-the-middle phishing, cookie theft and replay to bypass MFA, hijack sessions, and enable persistent access. It exposed 5,137 credential records across 461 organizations and used affiliates receiving stolen credentials through dedicated Telegram bots.
A phishing-as-a-service operation targeting Microsoft 365 accounts by using adversary-in-the-middle proxy pages to capture credentials and authenticated session cookies, enabling MFA bypass through session replay. The operation used geographically matched residential proxies and provided affiliate access.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.