BigBear 2.0 Evilginx2 PhaaS: MFA bypass at 258 orgs; 5,137 credential records
CloudSEK (7 September 2026) details BigBear 2.0, an Evilginx2-based phishing-as-a-service panel targeting Microsoft 365 with an "offy" phishlet. Researchers obtained admin access to the operator panel (alias "General Boss"): 42 VPS nodes over the campaign lifecycle (many on Vultr/The Constant Company), geo-matched residential proxies, Telegram exfiltration bots for at least five affiliates, and cookie replay after victims complete MFA. Panel telemetry cited by CloudSEK: 5,137 credential records (474 complete MFA-bypassed authentications, 1,032 plaintext passwords, 4,148 session cookies) across 3,331 unique victim IPs in 40+ countries; BleepingComputer notes 258 organisations with at least one completed MFA-bypass compromise (461 in the broader targeting set). Custom JS can weaken phishing-resistant MFA (FIDO2/WebAuthn) toward weaker methods. Operation still active at publish time. Primary: CloudSEK blog; wire: BleepingComputer (7 Sep 2026).
- Product
- Microsoft 365 / Entra ID (targeted via AiTM phishing)
- Exploited in Australia?
- unknown
- Patch to
- Enforce phishing-resistant MFA (FIDO2/passkeys); conditional access / token protection; hunt unexpected M365 session cookies and Impossible Travel; user reporting of fake Microsoft login pages
Primary: CloudSEK — Tracking BigBear 2.0 Evilginx2 PhaaS (7 Sep 2026) · BleepingComputer (7 Sep 2026)
