In a significant cybersecurity development, the BigBear 2.0 phishing operation is utilizing advanced techniques to breach Microsoft 365 accounts. This campaign effectively bypasses multi-factor authentication (MFA) by capturing session cookies, posing a serious threat to digital security.
How BigBear 2.0 Operates
BigBear 2.0 is an iteration of the Evilginx2 framework, specifically rebranded to target Microsoft 365 users. By sending deceptive sign-in links via email, the campaign reroutes victims to a counterfeit Microsoft sign-in page. Here, it intercepts the user’s credentials and session data while simultaneously redirecting their traffic to the legitimate service.
The operation, uncovered by CloudSEK analysts in June 2026, involves a network of 42 virtual private server nodes. Researchers connected the campaign to an individual known as General Boss, uncovering over 5,137 compromised records from various organizations and individuals across more than 40 countries.
Technical Exploits and Impact
The phishing scheme employs an adversary-in-the-middle approach, capturing session cookies post-authentication. These cookies allow attackers to impersonate users across Microsoft services such as Teams, SharePoint, and OneDrive without needing their passwords again. By leveraging residential proxies, the operation evades detection and circumvents security key authentication.
With 474 complete session captures and thousands of session cookies and passwords exposed, the implications for IT services and managed service providers are particularly concerning. A single compromised provider could potentially grant attackers access to numerous client environments.
Mitigation Strategies and Future Outlook
Organizations must approach stolen cookies as identity threats rather than simple password issues. Immediate actions include password resets, session revocation, and monitoring for unauthorized access. Employing phishing-resistant authentication methods, such as FIDO2 or WebAuthn, can significantly mitigate risks.
As phishing tactics evolve, maintaining vigilant security protocols is crucial. Monitoring unusual IP activity and implementing robust email filtering can help detect and prevent such threats. Continuous adaptation to emerging cyber threats will be essential for maintaining operational security.
Users should remain cautious of unexpected sign-in prompts and verify their authenticity through known channels rather than email links. BigBear 2.0 highlights the necessity of combining MFA with advanced security practices to safeguard sensitive data and maintain trust in digital communications.
