CloudSEK reported that BigBear 2.0, a phishing-as-a-service platform allegedly operated by “General Boss,” used a rebranded Evilginx2 adversary-in-the-middle (AiTM) framework to target Microsoft 365 users. Its offy proxy intercepted passwords and post-MFA session cookies, allowing attackers to replay authenticated sessions and bypass MFA. Researchers found 5,137 captured credential records tied to 461 organizations and 3,331 victim IP addresses across more than 40 countries; IT services firms and managed service providers were the most targeted, with India accounting for the largest share of victims.
The platform used a centralized multi-tenant administration panel controlling 42 VPS nodes and supplied stolen credentials to at least five affiliates through Telegram. BigBear 2.0 also deployed custom JavaScript intended to suppress FIDO2/WebAuthn prompts, block Microsoft anti-phishing telemetry, and select “Keep Me Signed In,” while geo-matched residential proxies helped evade location-based controls. Organizations should investigate suspicious Microsoft 365 session activity and prioritize detection of Evilginx/BigBear cookie and header artifacts, associated infrastructure, and Telegram-based credential-exfiltration traffic.

Get the infrastructure and lures behind it.
2 events from the most recent confirmed update back to the earliest known activity.
After accessing the BigBear 2.0 administrative panel, CloudSEK reported 5,137 stolen records tied to 461 organizations, including 474 complete authenticated sessions and 4,148 session cookies. It also identified 42 VPS nodes, at least five affiliates, and campaign infrastructure and Telegram bot indicators.
CloudSEK's TRIAD discovered BigBear 2.0, describing it as a rebranded Evilginx2-based phishing-as-a-service platform operated under the alias "General Boss." The platform used the "offy" adversary-in-the-middle configuration against Microsoft 365 authentication, capturing passwords and post-MFA session cookies for replay.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 23 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
3 references tracked. Mallory keeps watching after this page renders.
cyberaccord.com
Open sourcemalware.news
Open sourcecloudsek.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.