General Boss is a cybercriminal operator associated with BigBear 2.0, an Evilginx2-based phishing-as-a-service platform targeting Microsoft 365 and Microsoft Entra ID authentication. The service uses adversary-in-the-middle phishing to proxy victim authentication, steal passwords and MFA-authenticated session cookies, and enable replay of captured cloud sessions. BigBear 2.0 employs a multi-tenant affiliate model, with multiple operators receiving collected authentication material through dedicated Telegram bots. Its infrastructure uses geographically matched residential proxies to reduce location-anomaly detections. Custom browser-side modifications suppress WebAuthn/FIDO2 authentication flows, interfere with Microsoft anti-phishing telemetry, and extend stolen-session usability through persistent-sign-in and session-maintenance features. Operations targeted hundreds of organizations across more than 40 countries, particularly IT services and managed service providers, SaaS and technology organizations, oil and gas, pharmaceutical, and consulting organizations. India, France, and Saudi Arabia were among the most affected countries.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
22 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
52 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Cybercriminal operator of the BigBear 2.0 phishing-as-a-service platform, conducting adversary-in-the-middle phishing against Microsoft 365/Entra ID users to capture credentials and session cookies, bypass MFA, and enable account access.
Operator of the BigBear 2.0 phishing-as-a-service operation, enabling affiliates to steal Microsoft 365 credentials and MFA-authenticated sessions in real time.
Operates the BigBear 2.0 phishing-as-a-service platform, an Evilginx2-based adversary-in-the-middle phishing operation targeting Microsoft 365 users. The operator leases multi-tenant phishing infrastructure to affiliates, captures credentials and MFA-authenticated session cookies, exfiltrates them through Telegram bots, and enables cookie replay for persistent account access.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.