Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

Exploiting Microsoft 365 Vulnerabilities: A New Social Engineering Attack


Exploiting Microsoft 365 Vulnerabilities: A New Social Engineering Attack

  • Threat actors bypass endpoint security by posing as internal IT staff via phone calls and targeting Microsoft 365 and SaaS environments.
  • Victims' credentials and multi-factor approvals are intercepted in real-time using adversary-in-the-middle panels.
  • Stolen session tokens are replayed using residential proxy networks that match the victim's exact geographic location.
  • Threat actors focus on massive data harvesting after initial access, targeting SharePoint and Entra ID.
  • Detection methods include monitoring Microsoft 365 sign-ins from residential proxies and analyzing unusual SearchQueryPerformed events in SharePoint.
  • Prevention methods include requiring managed devices, phishing-resistant MFA, and limiting users' access to sensitive data.



  • A recent threat cluster tracked as PREY-0058 has been identified as a new social engineering attack that bypasses endpoint security entirely by targeting Microsoft 365 and SaaS environments. Attackers pose as internal IT help desk staff via phone calls and direct executives toward rogue authentication portals. These attacks most frequently target Directors, Vice Presidents, and other executive staff. Once victims land on these pages, adversary-in-the-middle panels intercept credentials and multi-factor approvals in real time.

    Stolen session tokens are then replayed using residential proxy networks that match the victim’s exact geographic location. "Stolen sessions are replayed from residential proxy infrastructure, most notably NodeMaven, often from IP addresses that resolve to the same geo-location and network (ASN) as the victim," states Artic Wolf. "Initial sign-in activity involves applications such as 'My Signins', 'My Profile', 'My Apps', which reveal account details and the applications available to the victim."

    Intruders waste no time once they slip past the front door, immediately shifting focus to massive data harvesting. After initial access, the threat actors perform discovery techniques against SharePoint and Entra ID. SharePoint discovery includes SearchQueryPerformed events with contentclass:STS_Site, contentclass:STS_Web, and wildcard searches using indexdocid for pagination. They map out repositories and drain sensitive files from OneDrive, Exchange, and Box before dropping a heavy extortion demand.

    To detect these attacks, monitor Microsoft 365 sign-ins coming from residential proxies or hosting networks such as NodeMaven. Suspicious activity is more likely when several common Microsoft account pages are accessed at the start of a session, especially OfficeHome, My Signins, My Profile, My Apps and Microsoft Account Controls. Alerts should also consider changes from a user’s normal sign-in pattern, such as a different location, ISP, browser, operating system or user agent.

    In SharePoint, look for unusual SearchQueryPerformed events that map or enumerate sites and files. In Exchange, watch for large numbers of MailItemsAccessed events in a short time, especially when they come from hosting or proxy IPs. Also monitor heavy SharePoint and OneDrive file access or downloads from one user, particularly when scripting tools such as Python requests or Microsoft Graph are used. Finally, watch for new phishing domains that imitate your organization and target passkey or MFA registration.

    To reduce the risk, require managed devices for Microsoft 365 and block or challenge access from proxy and hosting networks. Use phishing-resistant MFA such as FIDO2 keys or device-bound passkeys, which can stop AI TM attacks. Limit users’ access to sensitive SharePoint data, enable Continuous Access Evaluation, and train employees and help-desk teams to verify unexpected IT calls through a trusted channel.

    Artic Wolf also released Indicators of Compromise (IoCs) for these attacks.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/Exploiting-Microsoft-365-Vulnerabilities-A-New-Social-Engineering-Attack-ehn.shtml

  • https://securityaffairs.com/198634/cyber-crime/it-help-desk-impersonation-lets-hackers-bypass-mfa.html


  • Published: Tue Sep 8 05:38:16 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us