Skip to content

Anatomy of a phishing kit

CASE FILE BIGBEAR

BigBear 2.0: the phishing kit that walked over MFA at 258 organizations - a deep dive

In June 2026, CloudSEK analysts obtained admin access to the control panel of a phishing service called BigBear 2.0. Inside was the ledger of an industry: an Evilginx2 kit leased to affiliates, a proxy replaying the real Microsoft 365 login page in real time, and MFA walked over at 258 organizations across 40+ countries — France in second place. This case file doesn't autopsy one incident, but the tool that produces them at scale.

Thomas Ferreira 16 min read
CASE FILE BIGBEAR BigBear 2.0: the phishing kit that walked over MFA at 258 organizations - a deep dive

In June 2026, CloudSEK analysts didn’t merely observe a phishing service from the outside: they walked into its dashboard. “In June 2026, CloudSEK’s TRIAD discovered BigBear 2.0, a rebranded Evilginx2-based phishing-as-a-service framework and was able to gain admin access to the threat actor panel,” the report published on 7 September states. Inside was the raw ledger of a criminal industry: 5,137 Microsoft 365 credentials exfiltrated, including 474 authentications where MFA was actually bypassed — and France in second place among affected countries.

This case file opens a new series, “Anatomy of a phishing kit.” Unlike our incident autopsies — France Travail, the Brest hospital, fake bank advisors —, it tells the story not of a victim, but of the tool that produces them at scale. Its reference source is CloudSEK’s primary report, “Tracking BigBear 2.0 Evilginx2 Phishing Campaign” (Gagan Aggarwal, 7 September 2026), based on the researchers’ direct access to the panel; BleepingComputer’s follow-up (Bill Toulas, same day) confirms the figures. To it we add Microsoft’s and CISA’s publications on AiTM and phishing-resistant MFA.

One framing point, essential and stated upfront: the lesson of this case is not “MFA is useless”. MFA raises the bar considerably. But when the attack is an “adversary-in-the-middle” (AiTM) and a human clicks, it steps over the bar. The lure always arrives by email; the click is still the entry point. User vigilance and phishing-resistant authenticators aren’t at odds: they complement each other.

Key takeaways

  • The access: “In June 2026, CloudSEK’s TRIAD discovered BigBear 2.0, a rebranded Evilginx2-based phishing-as-a-service framework and was able to gain admin access to the threat actor panel” (CloudSEK, 7 September 2026). The report does not detail how this access was obtained; it is that access that gives the case its primary-source value.
  • The tally: “The panel has exfiltrated 5,137 credential records — including 474 complete MFA-bypassed authentications, 1,032 plaintext passwords, and 4,148 session cookies — affecting 3,331 unique victim IPs across 40+ countries” (CloudSEK). BleepingComputer specifies that 258 organizations suffered at least one completed MFA compromise, out of 461 targeted.
  • France: the second-most-hit country. “India is the most-targeted country with 658 records (12.8% of 5137 total), followed by France (463, 9.0%) and Saudi Arabia (353, ~6%)” (CloudSEK).
  • The mechanics: an Evilginx2 kit (“offy” phishlet) that places a reverse proxy between the victim and the real Microsoft 365 page, captures the password and the session cookie issued after MFA, and exfiltrates it “in real time” via Telegram bots to “at least five affiliate operators”. Custom JavaScript “disables FIDO2/WebAuthn MFA” to force a weaker factor.
  • The antidote: phishing-resistant MFA. CloudSEK says it of the kit itself: FIDO2 is “the only MFA method that structurally prevents AiTM phishing”; CISA names it “the gold standard”. That BigBear had to code JavaScript to neutralize FIDO2 is the best proof, in the negative, of its effectiveness.
  • The framing: Microsoft has said it since 2022 — “this is not a vulnerability in MFA”. Code-, push- or SMS-based MFA is not worthless; it is simply no longer sufficient on its own. The entry point is still the click on an email.

The case in numbers

258

organizations with at least one authentication compromised despite MFA (461 targeted in total)

CloudSEK, 07/09/2026; BleepingComputer, 07/09/2026

5,137

credentials exfiltrated: 474 MFA-bypassed authentications, 1,032 plaintext passwords, 4,148 session cookies

CloudSEK, 'Tracking BigBear 2.0', 07/09/2026

463

credentials stolen in France, the 2nd-most-hit country (9.0% of the total), behind India

CloudSEK, 07/09/2026

42

servers (VPS) driven by the panel, leased to at least 5 affiliate operators via Telegram bots

CloudSEK, 07/09/2026

Timeline

Timeline

How events unfolded

  1. 2017

    Evilginx: the open-source tool it all builds on

    Kuba Gretzky releases Evilginx, 'a man-in-the-middle attack framework used for phishing login credentials along with session cookies, which in turn allows to bypass 2-factor authentication protection' (project README). An avowed red-team tool, shipped with a warning: 'Evilginx should be used only in legitimate penetration testing assignments with written permission from to-be-phished parties.'

    Source — Evilginx, public repository of Kuba Gretzky (kgretzky)

  2. 12 July 2022

    Microsoft warns of the large-scale AiTM wave

    Microsoft documents 'a large-scale phishing campaign that used adversary-in-the-middle (AiTM) phishing sites [to] steal passwords, hijack a user's sign-in session, and skip the authentication process even if the user had enabled multifactor authentication (MFA).' The campaign 'attempted to target more than 10,000 organizations since September 2021.'

    Source — Microsoft Threat Intelligence, 12/07/2022

  3. October 2022

    CISA publishes its phishing-resistant MFA doctrine

    The US agency publishes 'Implementing Phishing-Resistant MFA': 'While any form of MFA is better than no MFA [...], phishing-resistant MFA is the gold standard and organizations should make migrating to it a high priority effort.' It names 'the only widely available phishing-resistant authentication': FIDO/WebAuthn.

    Source — CISA, 'Implementing Phishing-Resistant MFA', October 2022

  4. 2023-2024

    The AiTM PhaaS market matures

    Turnkey services proliferate: EvilProxy, surfacing on the dark web in 2022 (Resecurity), leased for '$150 for ten days'; Tycoon 2FA, active 'since at least August 2023', with over 1,100 domains detected between October 2023 and February 2024, packages 'starting at $120 for 10 days' (Sekoia.io). Bypassing legacy MFA becomes a commodity.

    Source — Resecurity (2022); Sekoia.io, Tycoon 2FA analysis (2024)

  5. June 2026

    CloudSEK gets inside the BigBear 2.0 panel

    'In June 2026, CloudSEK's TRIAD discovered BigBear 2.0, a rebranded Evilginx2-based phishing-as-a-service framework and was able to gain admin access to the threat actor panel.' The panel drove '42 VPS nodes over the campaign lifecycle — primarily hosted by The Constant Company LLC (Vultr) — configured with the 'offy' phishlet targeting Microsoft 365 exclusively.'

    Source — CloudSEK, 'Tracking BigBear 2.0', 07/09/2026

  6. Since late July 2026

    The operator covers its tracks

    'Since late July 2026 the threat actor has deleted 26 of the 42 observed VPS nodes from the panel — evidence of active counter-forensic operations in response to detection.' Only one node remains active at publication, but the admin panel itself remains accessible to researchers.

    Source — CloudSEK, 07/09/2026

  7. 7 September 2026

    CloudSEK report published, picked up by BleepingComputer

    CloudSEK publishes 'Tracking BigBear 2.0 Evilginx2 Phishing Campaign' (Gagan Aggarwal). The same day, BleepingComputer headlines: 'BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations' (Bill Toulas). The tally: 258 organizations with at least one completed compromise out of 461 targeted, 5,137 credentials exfiltrated, 40+ countries.

    Source — CloudSEK; BleepingComputer, 07/09/2026

Act 1: what CloudSEK saw from inside the panel

Most threat-intelligence reports describe a campaign from the outside: observed domains, lure samples, tallied victims. BigBear 2.0 is different because CloudSEK’s analysts were able, by their own account, to “gain admin access to the threat actor panel.” They did not estimate the volume of theft; they read the kit’s ledger. The report, honest about its limits, does not disclose the access method — and we will not speculate on it.

What the panel held fits in one summary sentence: “The panel has exfiltrated 5,137 credential records — including 474 complete MFA-bypassed authentications, 1,032 plaintext passwords, and 4,148 session cookies — affecting 3,331 unique victim IPs across 40+ countries.” Let’s break it down, because each number tells a stage.

The 1,032 plaintext passwords are the minimal loot: credentials typed on the fake page. The 4,148 session cookies are worse: each is an already-validated access token that opens the session without password or MFA. And the 474 complete authentications with MFA bypassed — 9.2% of the total — are the heart of the case: 474 times, a user did everything security asked, including validating their second factor, and the attacker ended up authenticated in their place. As CloudSEK sums up, “each complete session represents a fully compromised Microsoft 365 account”, with potential access to the mailbox, Teams, SharePoint and OneDrive, and Entra ID.

On the infrastructure side, the panel drove “42 VPS nodes over the campaign lifecycle — primarily hosted by The Constant Company LLC (Vultr) — configured with the ‘offy’ phishlet targeting Microsoft 365 exclusively.” A “phishlet” is the Evilginx configuration file describing which service to mirror and which rewrite rules to apply; “offy” is BigBear’s own, tailored for Microsoft 365. And this panel was no lone hacker’s affair: “the multi-user PhaaS panel is leased to at least five affiliate operators identified through live Telegram exfiltration bots, each receiving stolen credentials in real time.” A platform model, with a primary operator (alias “General Boss”), resellers and sub-operators.

Two more details round out the picture. First, stealth: BigBear “deployed geo-matched residential proxy pools” covering 69 countries, so the fraudulent sign-in appears to come from the same country as the victim and evades Microsoft’s geo-anomaly detection. Second, counter-forensics: “since late July 2026 the threat actor has deleted 26 of the 42 observed VPS nodes from the panel — evidence of active counter-forensic operations in response to detection.” In other words, the operator knew it was being watched. At publication, the phishing infrastructure is largely dismantled, but the admin panel itself remains accessible to researchers. The CloudSEK report makes no mention of a law-enforcement takedown or notification to authorities; we will not assert one.

Act 2: the attack chain, at the conceptual level

Attack chain

How the intrusion unfolded

Defensive reconstruction — every link you understand is a link you can break.

  1. The lure arrives by email — the click is still the entry point

    Nothing happens without a human action. The victim receives a phishing link (CloudSEK maps the technique to MITRE ATT&CK T1566.002, 'Spearphishing Link'). The URLs 'use legitimate domains (compromised or lookalike) with valid SSL certificates. Without URL reputation analysis, most email gateways permit these links' (CloudSEK). MFA raises the bar; the click, though, remains the entry point.

  2. A reverse proxy that replays the real Microsoft 365 page

    The victim doesn't land on a static copy. 'Evilginx2 phishlets operate as man-in-the-middle (AiTM) proxies: when a victim visits the phishing URL, the engine proxies all traffic between the victim and the legitimate Microsoft service' (CloudSEK). The displayed page is Microsoft's real content served through the proxy — pixel for pixel. The default phishlet, 'offy', is 'configured to intercept Microsoft 365 authentication'.

  3. The victim authenticates — including their MFA

    Login, password, then second factor: the victim completes the whole authentication, each interaction relayed to Microsoft. 'TOTP, push notification, SMS, and even voice call MFA are all equally vulnerable — the proxy captures the resulting session cookie regardless of MFA type' (CloudSEK). To force the path, custom JavaScript 'disables FIDO2/WebAuthn MFA' so 'hardware security key users fall back to phishable MFA'.

  4. The kit captures the password AND the session cookie

    Once authentication succeeds, Microsoft issues a session cookie — proof that MFA was cleared. 'The attacker never needs to know the SMS code to hijack the session' (CloudSEK). The proxy intercepts that cookie before passing it to the victim, who sees Outlook open normally, with no alert. Geo-matched residential proxies (69 countries) make the sign-in appear to come from the expected country, defeating Microsoft's anomaly detection.

  5. Real-time exfiltration to affiliates via Telegram

    The cookie and credentials leave immediately: 'Automated credential processing pipeline: capture → Telegram notification → cookie.js file attachment → Cookie API replay engine' (CloudSEK). The multi-user panel is 'leased to at least five affiliate operators', each receiving credentials 'in real time' in its own Telegram channel — a supply chain, not a lone hacker.

  6. Cookie replay and account takeover

    From their own machine, the affiliate imports the cookie and accesses the session: mailbox, Teams, SharePoint, OneDrive — no login, no MFA. A 'keepalive' mechanism 'periodically refreshes captured session cookies by reusing the refresh token', extending access. CloudSEK ties monetization to initial-access brokerage: 'session cookies enable ransomware deployment, data extortion, or BEC campaigns'.

We describe the sequence here as vendors and researchers publish it — with no operational detail that would help reproduce the attack, and no indicator-of-compromise dumps: those are in the CloudSEK report, for defenders.

The key point runs through the whole chain: AiTM breaks nothing, it relays everything. The page the victim sees is not a rough forgery, it is Microsoft’s real content rendered through the proxy. The password is correct, the second factor is correct, the source IP (a geo-matched residential proxy’s) is plausible. Microsoft “sees” a perfectly normal sign-in and issues a session cookie. It is that cookie — not the password — that is the real trophy: it embodies the fact that MFA has already been cleared, and it replays without a second factor. CloudSEK is unambiguous: “TOTP, push notification, SMS, and even voice call MFA are all equally vulnerable — the proxy captures the resulting session cookie regardless of MFA type.”

One technical detail of the kit is worth highlighting, because it is telling. BigBear ships “custom JavaScript that disables FIDO2/WebAuthn MFA”, such that “the attacker manipulates the authentication flow so the victim ends up using an alternative authentication method that is weaker or not phishing-resistant.” Translation: the kit specifically needs to prevent the victim from using their FIDO2 key, because it would resist. That is the admission, in the attacker’s own code, of what stops it.

Act 3: the AiTM ecosystem, and the legitimate tool it repurposes

BigBear 2.0 was not born in a vacuum. It belongs to a wave documented for years, and it rests on a tool that is, at origin, not criminal at all.

Evilginx: a red-team tool, presented fairly

BigBear’s technical foundation is Evilginx, released in 2017 by security researcher Kuba Gretzky. Its public repository describes it as “a man-in-the-middle attack framework used for phishing login credentials along with session cookies, which in turn allows to bypass 2-factor authentication protection.” It is not clandestine malware, but a widely used offensive-security tool — including by the phishing-simulation industry, ours included, to measure organizations’ real resilience to AiTM techniques. Its author owns the dual-use and frames it with a warning: “Evilginx should be used only in legitimate penetration testing assignments with written permission from to-be-phished parties.” The tool is not the crime; unauthorized use is. BigBear is its criminal repurposing, “rebranded” and leased to affiliates.

The AiTM wave, documented since 2022

Microsoft raised the alarm as early as 12 July 2022, describing “a large-scale phishing campaign that used adversary-in-the-middle (AiTM) phishing sites [to] steal passwords, hijack a user’s sign-in session, and skip the authentication process even if the user had enabled multifactor authentication.” The campaign “attempted to target more than 10,000 organizations since September 2021.” And Microsoft already set the frame this case reprises: “this is not a vulnerability in MFA; since AiTM phishing steals the session cookie, the attacker gets authenticated to a session on the user’s behalf, regardless of the sign-in method the latter uses.”

Since then, the AiTM phishing-as-a-service market has matured. EvilProxy, surfacing on the dark web in 2022, was leased for “$150 for ten days” per Resecurity, with payment arranged via an operator on Telegram. Tycoon 2FA, active “since at least August 2023” according to Sekoia.io, counted “over 1,100 domain names detected between October 2023 and February 2024”, with packages “starting at $120 for 10 days.” The common thread across these services is BigBear’s: lower the technical barrier so that any affiliate, without knowing how to configure a reverse proxy, can lease MFA-bypass capability. Bypassing legacy MFA has become a subscription commodity.

What actually defeats AiTM

The good news of this case is that a structural countermeasure exists — and it is named by the primary source itself.

Phishing-resistant MFA: FIDO2, passkeys

CloudSEK explains why FIDO2/WebAuthn resists where push, SMS and TOTP fail: “the cryptographic assertion is tied to the origin domain (e.g., login.microsoftonline.com). When Evilginx2 proxies traffic, the origin seen by the browser is the phishing domain […], not the real Microsoft domain. The FIDO2 assertion fails because the origin does not match the credential’s registered origin. This is the only MFA method that structurally prevents AiTM phishing.” Plainly: a FIDO2 key refuses to sign for a domain that is not the one where it was enrolled. The proxy cannot relay a signature that was never produced.

CISA turned this into doctrine as early as October 2022: “while any form of MFA is better than no MFA […], phishing-resistant MFA is the gold standard and organizations should make migrating to it a high priority effort.” It names FIDO/WebAuthn “the only widely available phishing-resistant authentication” and recommends starting with “system administrators and other high-value targets.” On the French side, ANSSI’s reference guide (“Recommendations on multifactor authentication and passwords”, ANSSI-PG-078) classes FIDO2 and FIDO U2F among the strong authentication mechanisms based on a possession factor, and explicitly prefers the use of physical hardware that has undergone a security evaluation (FIDO tokens, smart cards) — the same family CISA places at the top of its table.

The best argument, though, comes from the attacker itself: BigBear had to code JavaScript to disable FIDO2/WebAuthn and force the victim onto a phishable factor. You don’t go to that trouble against a defense that doesn’t bother you.

Conditional access and token protection

FIDO2 is not enough if it remains possible to sign in with a mere password. You need a conditional access policy that requires a phishing-resistant authentication strength for critical resources, and that restricts token usage. That is exactly what CloudSEK recommends as remediation: “reset affected passwords, revoke session and refresh tokens, force user re-authentication, enable phishing-resistant MFA — FIDO2 or WebAuthn, enforce Conditional Access, require compliant devices.” Our guide to protecting Microsoft 365 against AiTM (in French) details the concrete configuration: authentication strengths, FIDO2 enrollment without locking yourself out of the tenant, AiTM detection and token protection.

Honesty about what code-based MFA does not protect against

It has to be said without hedging: push-, SMS- or TOTP-code MFA does not protect against AiTM. These factors share a common flaw: they are not tied to the domain. A TOTP code is valid for whoever enters it within thirty seconds, on any page; a push notification approves a Microsoft event, not the victim’s exact browser. That is precisely what BigBear exploits. But “does not protect against AiTM” is not “is useless”: that MFA still blocks credential stuffing, a stolen password replayed cold, a large share of opportunistic attacks. CISA is right on both counts: “any form of MFA is better than no MFA”, and phishing-resistant is “the gold standard”. The mature strategy is not to choose, it is to prioritize.

What an SME on Microsoft 365 should do this quarter

For a 50-to-500-person organization, the goal is not perfection, it is to close the doors that are most lucrative to the attacker, in the right order.

1. Passkeys/FIDO2 for administrators first

Privileged accounts are the most rewarding targets: a single one is enough to open the whole tenant. CloudSEK notes, in fact, that the sector most targeted by BigBear was IT service providers and MSPs (151 organizations), precisely because “IT staff often have privileged access to Azure AD.” Start by equipping each global, Exchange, leadership and finance admin with two FIDO2 keys, and create a conditional access policy requiring phishing-resistant authentication for those roles. It is the best efficiency-to-price investment on Microsoft 365 — the steps are in our guide to deploying MFA in a company (in French) and the AiTM guide (in French).

2. Conditional access basics

Beyond keys, enable what your license allows: require compliant or managed devices, turn on AiTM detection (Microsoft Defender XDR, Automatic Attack Disruption) and token protection. These controls need no hardware, only configuration — and they reduce the value of a stolen cookie by binding it to a device and a context.

3. “Report before you click”

BigBear’s lure arrives by email: that is the only moment a human can break the chain before it triggers. Anchor the reflex of forwarding a suspicious message rather than clicking — report button, dedicated channel, blame-free debrief. The human factor is involved in 62% of data breaches (Verizon DBIR 2026 — see our phishing statistics for France). Training the report reflex means strengthening exactly the link AiTM attacks first.

4. Simulations that include AiTM and MFA fatigue

A simulation that only tests clicking a classic link doesn’t train for the real 2026 risk. Include AiTM-style scenarios (fake Microsoft sign-in page, second-factor prompt) and MFA-fatigue scenarios (bursts of push notifications until a weary approval). Measure report rates, debrief, repeat. That is how you turn a policy into a reflex — see our comparison against Microsoft’s Attack Simulator. And for the after-the-fact analysis of a suspicious email, our email header analyzer helps trace a message’s true origin. Find this case file and over 100 incidents in our French cyberattack database.

Verdict

BigBear 2.0 will stand as a rare X-ray: not the description of an incident seen from outside, but the ledger of a phishing kit read from its own dashboard. What that ledger shows is at once alarming and clarifying. Alarming, because 474 times, users did everything security asked — including validating their MFA — and had their session stolen; because France is the second-most-hit country; because the service leased to affiliates like ordinary software. Clarifying, because the report itself names the antidote — FIDO2, “the only MFA method that structurally prevents AiTM phishing” — and because the attacker had to code a routine to disable that very defense.

The moral, then, is not “MFA is dead.” It is more demanding and fairer: code- or push-based MFA has had its day as a sole rampart, phishing-resistant authentication must take over on sensitive accounts, and none of this excuses vigilance upstream — because the lure still arrives by email, and the click is still the entry point. The proxy can relay everything, save one thing: a FIDO2 key that refuses to sign for the wrong domain, and a user who reported instead of typing.

FAQ

What is BigBear 2.0? Per CloudSEK, “a rebranded Evilginx2-based phishing-as-a-service framework” targeting Microsoft 365 exclusively: a phishing service leased to affiliates, which places an “adversary-in-the-middle” proxy between the victim and the real Microsoft page and exfiltrates credentials and cookies via Telegram. The researchers say they obtained admin access to its panel.

How did it bypass MFA? Via an AiTM attack: the victim authenticates (password + second factor) on a proxy that relays everything to Microsoft; the proxy captures the session cookie issued after MFA. “The attacker never needs to know the SMS code to hijack the session” (CloudSEK). Microsoft: “this is not a vulnerability in MFA”.

Is France affected? Yes, in second place: “India […] followed by France (463, 9.0%) and Saudi Arabia” (CloudSEK). Credentials of French organizations are among the panel’s 5,137 records.

Is MFA now useless? No. It raises the bar and blocks most opportunistic attacks; it is simply no longer sufficient on its own against AiTM. “Any form of MFA is better than no MFA” (CISA). The countermeasure is phishing-resistant MFA on sensitive accounts, plus user vigilance.

Is Evilginx illegal? No: it is an open-source red-team tool released in 2017 by Kuba Gretzky, to be used “only in legitimate penetration testing assignments with written permission from to-be-phished parties.” BigBear is a criminal repurposing of it.

What actually stops AiTM? Phishing-resistant MFA — FIDO2, passkeys, Windows Hello for Business, certificates. CloudSEK: FIDO2 is “the only MFA method that structurally prevents AiTM phishing”. Complement with conditional access and training.


Sources:

  • CloudSEK (Gagan Aggarwal), “Tracking BigBear 2.0 Evilginx2 Phishing Campaign”, 7 September 2026 — primary source: cloudsek.com (accessed 08/09/2026)
  • BleepingComputer (Bill Toulas), “BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations”, 7 September 2026: bleepingcomputer.com (accessed 08/09/2026)
  • Microsoft Threat Intelligence, “From cookie theft to BEC: Attackers use AiTM phishing sites as entry point to further financial fraud”, 12 July 2022: microsoft.com (accessed 08/09/2026)
  • CISA, “Implementing Phishing-Resistant MFA”, fact sheet, October 2022: cisa.gov (accessed 08/09/2026)
  • ANSSI, “Recommandations relatives à l’authentification multifacteur et aux mots de passe” (ANSSI-PG-078), 8 October 2021: cyber.gouv.fr (PDF) (accessed 08/09/2026)
  • Evilginx, public repository of Kuba Gretzky (kgretzky): github.com/kgretzky/evilginx2 (accessed 08/09/2026)
  • Resecurity, “EvilProxy Phishing-as-a-Service with MFA Bypass Emerged in Dark Web”, 2022: resecurity.com (accessed 08/09/2026)
  • Sekoia.io, “Tycoon 2FA: an in-depth analysis of the latest version of the AiTM phishing kit”, 2024: blog.sekoia.io (accessed 08/09/2026)
  • Verizon, Data Breach Investigations Report 2026: verizon.com (accessed 08/09/2026)

Note: “General Boss” and the affiliate operators designated by CloudSEK are technical aliases tracked by analysts; they name no identified person, and no public judicial proceedings were known at the time of publication. The figures cited come from CloudSEK researchers’ access to the service’s panel, reproduced for descriptive and defensive purposes; this article contains no operational detail enabling reproduction of the attack and no indicators of compromise — those are in the CloudSEK report, for defenders. Where BleepingComputer (258 organizations compromised) and the primary report (461 organizations targeted, 474 complete authentications) differ in emphasis, we privilege the primary source for raw counts.

Exhibits

The case exhibits

CloudSEK (TRIAD)7 September 2026

Exhibit 01

“In June 2026, CloudSEK's TRIAD discovered BigBear 2.0, a rebranded Evilginx2-based phishing-as-a-service framework and was able to gain admin access to the threat actor panel. […] The panel has exfiltrated 5,137 credential records — including 474 complete MFA-bypassed authentications, 1,032 plaintext passwords, and 4,148 session cookies — affecting 3,331 unique victim IPs across 40+ countries.”

CloudSEK (TRIAD) — 7 September 2026 'Tracking BigBear 2.0 Evilginx2 Phishing Campaign', executive summary View source

CloudSEK (TRIAD)7 September 2026

Exhibit 02

“The cryptographic assertion is tied to the origin domain (e.g., login.microsoftonline.com). When Evilginx2 proxies traffic, the origin seen by the browser is the phishing domain […], not the real Microsoft domain. The FIDO2 assertion fails because the origin does not match the credential's registered origin. This is the only MFA method that structurally prevents AiTM phishing.”

CloudSEK (TRIAD) — 7 September 2026 'Tracking BigBear 2.0', 'Why FIDO2/WebAuthn is resistant' View source

Microsoft Threat Intelligence12 July 2022

Exhibit 03

“Note that this is not a vulnerability in MFA; since AiTM phishing steals the session cookie, the attacker gets authenticated to a session on the user's behalf, regardless of the sign-in method the latter uses. […] MFA is still very effective at stopping a wide variety of threats; its effectiveness is why AiTM phishing emerged in the first place.”

Microsoft Threat Intelligence — 12 July 2022 'From cookie theft to BEC' View source

CISAOctober 2022

Exhibit 04

“While any form of MFA is better than no MFA and will reduce an organization's attack surface, phishing-resistant MFA is the gold standard and organizations should make migrating to it a high priority effort. […] The only widely available phishing-resistant authentication is FIDO/WebAuthn authentication.”

CISA — October 2022 'Implementing Phishing-Resistant MFA' View source

Related articles