SECURITY researchers have uncovered a new phishing‑as‑a‑service operation dubbed BigBear 2.0, built on the Evilginx2 adversary‑in‑the‑middle framework. CloudSEK says the operation has already exfiltrated more than 5,100 Microsoft 365 credential records from victims, with the researchers gaining admin access to the threat actor panel and observing 3,331 unique victim IPs across more than 40 countries.
The campaign reportedly used 42 VPS nodes (primarily hosted by The Constant Company LLC, a Vultr service) configured with an “offy” phishlet targeting Microsoft 365, and operators described as “General Boss” deployed geo‑matched residential proxy pools, real‑time Telegram exfiltration and automated cookie replay to bypass MFA and maintain persistence.
The findings indicate 5,137 credential records exposed across 461 organisations, including 4,148 session cookies, 1,032 plaintext passwords and 474 completed MFA‑bypassed authentications. India, France, Saudi Arabia, New Zealand and Germany were among the most‑targeted countries.
CloudSEK notes that IT service and managed service providers were the most impacted sector, warning that a compromise of an IT provider could enable downstream supply‑chain attacks and grant attackers access to Azure AD, on‑prem AD, RMM tools and password managers.
Practical responses suggested include revoking suspicious sessions and refresh tokens, forcing re‑authentication, resetting compromised passwords, adopting phishing‑resistant authentication (FIDO2/WebAuthn), and tightening conditional access policies and device requirements. The report concludes that stolen session cookies could enable access to email, Teams, SharePoint, OneDrive, Entra ID and connected SaaS apps, with potential for business email compromise and broader data or infrastructure theft.