CloudSEK said BigBear 2.0’s admin panel held 5,137 credential records tied to 461 organizations in more than 40 countries, including 4,148 captured session cookies and 1,032 plaintext passwords.
At least 474 records showed completed Microsoft 365 logins where attackers stole authenticated session cookies after users passed MFA, letting them reuse the session without another challenge.
The service runs on Evilginx2 and uses country-matched residential proxies plus code that disables FIDO2/WebAuthn on phishing pages, weakening location checks and steering victims toward phishable methods.
IT services and managed service providers made up 151 of the targeted organizations, a high-value sector because staff often hold privileged access to customer environments and admin systems.
Researchers said BigBear 2.0 turns session hijacking into a scalable phishing-as-a-service model, pushing defenders to treat cookies and tokens as high-value credentials and revoke sessions—not just reset passwords—after compromise.