BigBear 2.0 Phishing Campaign Compromises Thousands of Microsoft 365 Credentials
CloudSEK's TRIAD discovered BigBear 2.0, a rebranded Evilginx2-based phishing-as-a-service framework, in June 2026.
The panel was observed managing 42 VPS nodes over the campaign lifecycle, primarily hosted by The Constant Company LLC (Vultr), and configured with the 'offy' phishlet targeting Microsoft 365 exclusively.
The operator deployed geo-matched residential proxy pools, real-time Telegram exfiltration, and automated cookie replay to bypass MFA and maintain persistent access.