CTIPilot

BigBear 2.0

tool · tool:bigbear-phaas

Evilginx2-based phishing-as-a-service (PhaaS) panel targeting Microsoft 365 exclusively via an adversary-in-the-middle reverse-proxy phishlet ('offy'); leased to multiple affiliate operators. Documented by CloudSEK (2026-09-07), whose researchers gained administrator access to the operator's control panel; operator alias 'General Boss'.

Aliases: BigBear

Coverage timeline
1
first 2026-09-08 → last 2026-09-08
Peak priority
high
1 high
Sources cited
2
2 hosts
Sections touched
1
active-threats
Co-occurring entities
2
see Co-occurring entities below
ATT&CK techniques
4
pinned v19.2 · see below

ATT&CK techniques

4 techniques observed across 1 entry, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

Initial Access TA0001

T1566.002Phishing: Spearphishing Link×1

Adversaries may send spearphishing emails with a malicious link in an attempt to gain access to victim systems. Spearphishing with a link is a specific variant of spearphishing. It is different from other forms of spearphishing in that it employs the use of links to download malware contained in email, instead of attaching malicious files to the email itself, to avoid defenses that may inspect email attachments. Spearphishing may also involve social engineering techniques, such as posing as a trusted source.

Evidence: 2026-09-08/bigbear-2-0-phaas-m365-aitm-fido2-bypass · ATT&CK page ↗

Credential Access TA0006

T1111Multi-Factor Authentication Interception×1

Adversaries may target multi-factor authentication (MFA) mechanisms, (i.e., smart cards, token generators, etc.) to gain access to credentials that can be used to access systems, services, and network resources. Use of MFA is recommended and provides a higher level of security than usernames and passwords alone, but organizations should be aware of techniques that could be used to intercept and bypass these security mechanisms.

Evidence: 2026-09-08/bigbear-2-0-phaas-m365-aitm-fido2-bypass · ATT&CK page ↗

T1539Steal Web Session Cookie×1

An adversary may steal web application or service session cookies and use them to gain access to web applications or Internet services as an authenticated user without needing credentials. Web applications and services often use session cookies as an authentication token after a user has authenticated to a website.

Evidence: 2026-09-08/bigbear-2-0-phaas-m365-aitm-fido2-bypass · ATT&CK page ↗

Lateral Movement TA0008

T1550.004Use Alternate Authentication Material: Web Session Cookie×1

Adversaries can use stolen session cookies to authenticate to web applications and services. This technique bypasses some multi-factor authentication protocols since the session is already authenticated.

Evidence: 2026-09-08/bigbear-2-0-phaas-m365-aitm-fido2-bypass · ATT&CK page ↗

Story timeline

  1. 2026-09-08BigBear 2.0, an Evilginx2-based Microsoft 365 phishing-as-a-service panel that JavaScript-disables FIDO2/WebAuthn to force victims onto phishable MFA, leased to at least five affiliates
    active-threatsCloudSEK gained admin access to the panel and found custom code specifically written to defeat the one MFA class that structurally resists this attack

Where this entity is cited

  • active-threats1

Source distribution

  • bleepingcomputer.com1 (50%)
  • cloudsek.com1 (50%)

Co-occurring entities

Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Entries about BigBear 2.0 (1)

2026-09-08 · view entry permalink →

HIGHNATOB2

BigBear 2.0, an Evilginx2-based Microsoft 365 phishing-as-a-service panel that JavaScript-disables FIDO2/WebAuthn to force victims onto phishable MFA, leased to at least five affiliates

CloudSEK's TRIAD team gained administrator access to the control panel of BigBear 2.0, a rebranded, Evilginx2-based adversary-in-the-middle phishing-as-a-service operation targeting Microsoft 365 exclusively, and published full technical findings on 2026-09-07 (CloudSEK, 2026-09-07). Victims reach the operation by clicking a phishing link typically delivered via email, which proxies them to what appears to be the legitimate Microsoft login page (CloudSEK, 2026-09-07). The panel managed 42 VPS nodes running Evilginx2's reverse-proxy engine on a single phishlet that proxies the entire authentication flow between the victim and Microsoft's own login domain: the victim's password is captured in plaintext as it passes through, and after the victim completes MFA, Microsoft's own session cookie is captured off the wire before it reaches the victim's browser, because the proxy terminates the victim's TLS session before opening its own to Microsoft (CloudSEK, 2026-09-07). That cookie is bound to the browser session but not to any device or location, so importing it into an attacker-controlled browser inherits the fully authenticated session, TOTP, push and SMS MFA are all structurally bypassed this way, since the proxy never has to defeat the second factor, only wait for the legitimate user to clear it (CloudSEK, 2026-09-07; BleepingComputer, 2026-09-07).

What distinguishes this operation from stock Evilginx2 deployments is custom JavaScript injected into every proxied login page that monkey-patches the browser's PublicKeyCredential/navigator.credentials API, forcing a fallback away from FIDO2/WebAuthn, the one MFA class immune to AiTM replay, because its cryptographic assertion is bound to the legitimate origin domain and fails outright when the browser's actual origin is the phishing domain rather than Microsoft's own (CloudSEK, 2026-09-07). The same injected code blocks outbound requests to Microsoft's own anti-phishing telemetry and canary-token endpoints and auto-enables "Keep me signed in" to maximize the stolen session's lifetime (CloudSEK, 2026-09-07). The panel exposes a REST API that automatically replays captured cookies against Microsoft 365, and a keepalive feature abuses captured refresh tokens (typically valid around 90 days on a sliding window) to periodically refresh session cookies well past their nominal expiry (CloudSEK, 2026-09-07). A geo-matched residential-proxy pool spanning 69 countries routes relayed traffic through an IP in the victim's own country, defeating Microsoft's location-anomaly detection and satisfying IP-based Conditional Access checks that key on geolocation rather than device state (CloudSEK, 2026-09-07).

At the time of CloudSEK's writing the panel had captured 5,137 credential records (474 complete MFA-bypassed sessions, 1,032 plaintext passwords, and 4,148 session cookies) from 3,331 unique victim IPs across more than 40 countries (CloudSEK, 2026-09-07). BleepingComputer's own review of CloudSEK's dataset gives the organizational scale directly: 258 distinct organizations had at least one completed MFA-bypass compromise, out of 461 organizations that appear in the broader targeting dataset (BleepingComputer, 2026-09-07). CloudSEK describes the operation as still active as of its report, but also records that the threat actor has deleted 26 of the panel's 42 observed VPS nodes since late July 2026 as apparent counter-forensic activity following detection (CloudSEK, 2026-09-07); BleepingComputer separately reports that, as of its own writing, BigBear's administration panel remains reachable while the phishing infrastructure itself has been offline for nearly three weeks (BleepingComputer, 2026-09-07), consistent with an operator tearing down active phishing nodes under pressure while the panel and its captured-credential dataset persist. The service is leased to at least five identified affiliate operators, each receiving stolen credentials in real time through dedicated Telegram bots (CloudSEK, 2026-09-07; BleepingComputer, 2026-09-07). IT-services and managed-service-provider organizations were the single largest targeted sector, which CloudSEK notes is disproportionate because a compromised IT provider's privileged access to client Azure AD, on-premises AD, RMM tooling and password managers enables downstream supply-chain compromise of its customers (CloudSEK, 2026-09-07).

Triage: the vendor-neutral tell is a session-cookie-authenticated action with no matching interactive MFA challenge in the same session lineage, or a token-issuance event immediately followed by activity from a network location or device-compliance state inconsistent with the device that originally enrolled; a legitimate user re-using a cached session from a known device does not produce this mismatch, which is what separates the AiTM replay from ordinary session persistence.

The panel has exfiltrated 5,137 credential records (including 474 complete MFA-bypassed authentications, 1,032 plaintext passwords, and 4,148 session cookies) affecting 3,331 unique victim IPs across 40+ countries

Since late July 2026 the threat actor has deleted 26 of the 42 observed VPS nodes from the panel, evidence of active counter-forensic operations in response to detection.

CloudSEK

At the time of writing, the administration panel remains online, while the phishing infrastructure has been offline for nearly three weeks.

BleepingComputer (Bill Toulas) 2026-09-07

FIDO2 (hardware security keys, platform authenticators like Apple Face ID / Windows Hello) uses origin-bound credentials. The cryptographic assertion is tied to the origin domain (e.g., login.microsoftonline.com). When Evilginx2 proxies traffic, the origin seen by the browser is the phishing domain (login.evil-domain.com), not the real Microsoft domain. The FIDO2 assertion fails because the origin does not match the credential's registered origin. This is the only MFA method that structurally prevents AiTM phishing.

CloudSEK

Researchers at cybersecurity company CloudSEK gained administrator access to the control panel and found that the service managed 42 VPS nodes, all configured to target Microsoft 365 as part of the observed operation.

BleepingComputer
threat08 Sep 04:45Zmulti-sourceOpen finding ↗