A newly uncovered phishing campaign named BigBear 2.0 is using a rebranded Evilginx2 framework to steal session cookies from Microsoft 365 users—even after multi-factor authentication (MFA) is completed.
How BigBear 2.0 Works
The attack starts when a target clicks a link in a phishing email, which leads them to a fake Microsoft sign-in page. From there, traffic is relayed to the real service while the attacker captures both login credentials and the session cookie returned by Microsoft once authentication—including MFA—is successful. By intercepting this cookie, the attacker can hijack an authenticated session and access Microsoft 365 resources, including email, SharePoint, Teams, and applications using single sign-on.
Scope, Impact & Infrastructure
CloudSEK discovered BigBear 2.0 in June 2026 by accessing the attacker’s admin panel. The operation spans 42 virtual private server nodes. It has amassed over 5,100 stolen records linked to 461 organizations and more than 3,300 victim IPs across 40+ countries. Among these records are nearly 1,000 passwords and over 4,100 session cookies, with nearly 500 cases where the attacker obtained full authenticated sessions. IT service providers and managed service providers (MSPs) have been hit particularly hard, posing downstream risks to their clients.
Techniques, Tactics, and Tools
BigBear 2.0 uses residential proxies that match the victim’s country and scripts to steer users away from security-key-based MFA in favor of less secure codes or push notifications. Once Microsoft validates the credentials, the phishing proxy intercepts the session cookie and enables the attacker to impersonate the user without bypassing the MFA mechanism itself—it steals the “proof” of authentication afterward.
Indicators & Defensive Measures
CloudSEK’s analysis includes IP addresses of BigBear VPS nodes, phishing domains used in the campaign, phishing page URLs, and HTTP headers and cookies associated with Evilginx and BigBear sessions. These indicators offer defenders tangible leads when hunting for compromise.
To mitigate risk, organizations are urged to treat stolen session cookies as more than just password issues. This means resetting passwords, revoking active sessions and tokens, and enforcing fresh sign-ins. Additional best practices include reviewing forwarding rules, OAuth grants, and unusual sign-in activity.
The most robust defense is deploying phishing-resistant MFA—security keys or passkeys using FIDO2 or WebAuthn standards. Other recommendations include conditional access policies, shorter session lifetimes, monitoring residential IPs, and scrutinizing email links that look like login pages, even if they show valid SSL certificates.
BigBear 2.0 combines cookie theft, geo-matched proxies, and an affiliate model. It shows that while MFA blocks many threats, attackers are adapting to capture what happens after MFA succeeds. Being aware of session hijacking techniques and reinforcing login security holistically have become essential.
What to Watch For
Organizations should look out for unfamiliar browser sessions, especially from residential IPs, odd HTTP headers tied to Evilginx/BigBear frameworks, and phishing domains mimicking Microsoft services. Teams should verify that MFA-resistant measures are actually enforced and avoid relying on push notifications or codes alone in high-risk environments.
Analysis: BigBear 2.0 illustrates a growing trend: attackers are no longer just trying to bypass MFA—they’re using phishing to hijack valid sessions. The rulebook is changing. For defenders, this means that strengthening authentication methods alone will not suffice. Session controls, faster revocation, and thorough monitoring are now as critical as the MFA itself. Statistics showing thousands of stolen sessions and credentials underscore how widespread this risk is. What matters now is how organizations adapt their defenses—deploying phishing-resistant authentication, shortening session windows and educating users not to trust links—even those that look familiar.