Ethical Hacking News
Fake IT calls are targeting Microsoft 365 users, specifically executives, directors, and other high-ranking staff, in a data theft and extortion attack. The attackers use a combination of information technology (IT) help desk vishing, adversary-in-the-middle (AitM) token theft, and residential-proxy sign-ins to carry out the attacks. The attacks lead to an operator-controlled AitM Microsoft 365 login flow that is designed to harvest credentials and multi-factor authentication (MFA) approvals to obtain access to authenticated session tokens. Organizations are advised to implement Conditional Access policies, deploy phishing-resistant MFA, restrict the scope of data that users have access to in SharePoint, and educate employees and help desk staff about vishing risks.
Phishing attack PREY-0058 targets executives at Microsoft 365 users, using a combination of vishing, token theft, and residential-proxy sign-ins. The attack aims to harvest credentials and MFA approvals to obtain access to authenticated session tokens. The attackers impersonate internal IT or help desk personnel to direct targets to authentication-themed URLs. The attack leads to operator-controlled AitM Microsoft 365 login flows, followed by session replay attacks from proxy infrastructure. The attackers collect data from SharePoint, OneDrive, Exchange, and Box, and send extortion demands to victims. The targets are primarily high-ranking staff at organizations in the U.S., primarily in construction and engineering, healthcare, and finance. Organizations can counter the threat by implementing Conditional Access policies, deploying phishing-resistant MFA, and educating employees about vishing risks.
In recent months, a new type of phishing attack has emerged that is specifically targeting executives at Microsoft 365 users. The attack, dubbed PREY-0058 by Arctic Wolf, involves a combination of information technology (IT) help desk vishing, adversary-in-the-middle (AitM) token theft, and residential-proxy sign-ins. According to the data, this attack cluster has been tracked by Arctic Wolf, and it has been found to share significant tradecraft similarities with a data extortion group known as UNC6671, also referred to as Cinder.
The attack begins with a phone call from someone claiming to be an internal IT or help desk personnel, who then directs the prospective target to an authentication-themed URL that follows the pattern: .. Some of the lure domains flagged by Arctic Wolf include assignpasskey[.]com, mfaregister[.]com, nowsso[.]com, oskeysetup[.]com, oursso[.]com, passkey-mfa[.]com, passkeydeploy[.]com, registermymfa[.]com, setpasskey[.]com. The attacks lead to an operator-controlled AitM Microsoft 365 login flow that is designed to harvest credentials and multi-factor authentication (MFA) approvals to obtain access to authenticated session tokens.
The captured tokens are then used in session replay attacks originating from proxy infrastructure, such as NodeMaven, and from IP addresses that resolve to the same geographical location and ASN as the victim. The initial sign-in activity involves applications such as 'My Signins,' 'My Profile,' 'My Apps,' which reveal account details and the applications available to the victim. After initial access, the threat actors perform discovery techniques against SharePoint and Entra ID. SharePoint discovery includes SearchQueryPerformed events with contentclass:STS_Site, contentclass:STS_Web, and wildcard searches using indexdocid for pagination.
In the final step, the threat actors perform en masse collection and exfiltration from SharePoint, OneDrive, Exchange, and Box, after which extortion demands are sent to victims. It is worth noting that what is notable about PREY-0058 is the absence of endpoint malware deployment or network-based lateral movement. Further analysis of subdomains across the lure infrastructure has uncovered hundreds of entries impersonating real companies.
The targets of this attack are primarily executives, directors, and other high-ranking staff at organizations in the U.S., primarily in construction and engineering, healthcare and pharmaceuticals, real estate and property management, finance, and professional services. To counter the threat, organizations are advised to implement Conditional Access policies, deploy phishing-resistant MFA, restrict the scope of data that users have access to in SharePoint, and educate employees and help desk staff about vishing risks.
Defenders can disrupt this activity by detecting anomalous residential-proxy token replay, SharePoint discovery and bulk access, mailbox harvesting, and newly registered authentication-themed lure infrastructure, according to Arctic Wolf. The attackers also use a combination of information technology (IT) help desk vishing, adversary-in-the-middle (AitM) token theft, and residential-proxy sign-ins to carry out the attacks.
The attackers impersonate internal IT or help desk personnel in phone calls and direct prospective targets to an authentication-themed URL that follows the pattern: .. The lure domains flagged by Arctic Wolf include assignpasskey[.]com, mfaregister[.]com, nowsso[.]com, oskeysetup[.]com, oursso[.]com, passkey-mfa[.]com, passkeydeploy[.]com, registermymfa[.]com, setpasskey[.]com. The attacks lead to an operator-controlled AitM Microsoft 365 login flow that is designed to harvest credentials and multi-factor authentication (MFA) approvals to obtain access to authenticated session tokens.
The captured tokens are then used in session replay attacks originating from proxy infrastructure, such as NodeMaven, and from IP addresses that resolve to the same geographical location and ASN as the victim. The initial sign-in activity involves applications such as 'My Signins,' 'My Profile,' 'My Apps,' which reveal account details and the applications available to the victim.
After initial access, the threat actors perform discovery techniques against SharePoint and Entra ID. SharePoint discovery includes SearchQueryPerformed events with contentclass:STS_Site, contentclass:STS_Web, and wildcard searches using indexdocid for pagination. In the final step, the threat actors perform en masse collection and exfiltration from SharePoint, OneDrive, Exchange, and Box, after which extortion demands are sent to victims.
It is worth noting that what is notable about PREY-0058 is the absence of endpoint malware deployment or network-based lateral movement. Further analysis of subdomains across the lure infrastructure has uncovered hundreds of entries impersonating real companies. The attackers also use a combination of information technology (IT) help desk vishing, adversary-in-the-middle (AitM) token theft, and residential-proxy sign-ins to carry out the attacks.
The targets of this attack are primarily executives, directors, and other high-ranking staff at organizations in the U.S., primarily in construction and engineering, healthcare and pharmaceuticals, real estate and property management, finance, and professional services. To counter the threat, organizations are advised to implement Conditional Access policies, deploy phishing-resistant MFA, restrict the scope of data that users have access to in SharePoint, and educate employees and help desk staff about vishing risks.
Defenders can disrupt this activity by detecting anomalous residential-proxy token replay, SharePoint discovery and bulk access, mailbox harvesting, and newly registered authentication-themed lure infrastructure, according to Arctic Wolf. The attackers also use a combination of information technology (IT) help desk vishing, adversary-in-the-middle (AitM) token theft, and residential-proxy sign-ins to carry out the attacks.
The attackers impersonate internal IT or help desk personnel in phone calls and direct prospective targets to an authentication-themed URL that follows the pattern: .. The lure domains flagged by Arctic Wolf include assignpasskey[.]com, mfaregister[.]com, nowsso[.]com, oskeysetup[.]com, oursso[.]com, passkey-mfa[.]com, passkeydeploy[.]com, registermymfa[.]com, setpasskey[.]com. The attacks lead to an operator-controlled AitM Microsoft 365 login flow that is designed to harvest credentials and multi-factor authentication (MFA) approvals to obtain access to authenticated session tokens.
The captured tokens are then used in session replay attacks originating from proxy infrastructure, such as NodeMaven, and from IP addresses that resolve to the same geographical location and ASN as the victim. The initial sign-in activity involves applications such as 'My Signins,' 'My Profile,' 'My Apps,' which reveal account details and the applications available to the victim.
After initial access, the threat actors perform discovery techniques against SharePoint and Entra ID. SharePoint discovery includes SearchQueryPerformed events with contentclass:STS_Site, contentclass:STS_Web, and wildcard searches using indexdocid for pagination.
In the final step, the threat actors perform en masse collection and exfiltration from SharePoint, OneDrive, Exchange, and Box, after which extortion demands are sent to victims.
The attackers use a combination of information technology (IT) help desk vishing, adversary-in-the-middle (AitM) token theft, and residential-proxy sign-ins to carry out the attacks. The attackers impersonate internal IT or help desk personnel in phone calls and direct prospective targets to an authentication-themed URL that follows the pattern: .. The lure domains flagged by Arctic Wolf include assignpasskey[.]com, mfaregister[.]com, nowsso[.]com, oskeysetup[.]com, oursso[.]com, passkey-mfa[.]com, passkeydeploy[.]com, registermymfa[.]com, setpasskey[.]com. The attacks lead to an operator-controlled AitM Microsoft 365 login flow that is designed to harvest credentials and multi-factor authentication (MFA) approvals to obtain access to authenticated session tokens.
The captured tokens are then used in session replay attacks originating from proxy infrastructure, such as NodeMaven, and from IP addresses that resolve to the same geographical location and ASN as the victim. The initial sign-in activity involves applications such as 'My Signins,' 'My Profile,' 'My Apps,' which reveal account details and the applications available to the victim.
After initial access, the threat actors perform discovery techniques against SharePoint and Entra ID. SharePoint discovery includes SearchQueryPerformed events with contentclass:STS_Site, contentclass:STS_Web, and wildcard searches using indexdocid for pagination.
In the final step, the threat actors perform en masse collection and exfiltration from SharePoint, OneDrive, Exchange, and Box, after which extortion demands are sent to victims.
The attackers use a combination of information technology (IT) help desk vishing, adversary-in-the-middle (AitM) token theft, and residential-proxy sign-ins to carry out the attacks. The attackers impersonate internal IT or help desk personnel in phone calls and direct prospective targets to an authentication-themed URL that follows the pattern: .. The lure domains flagged by Arctic Wolf include assignpasskey[.]com, mfaregister[.]com, nowsso[.]com, oskeysetup[.]com, oursso[.]com, passkey-mfa[.]com, passkeydeploy[.]com, registermymfa[.]com, setpasskey[.]com. The attacks lead to an operator-controlled AitM Microsoft 365 login flow that is designed to harvest credentials and multi-factor authentication (MFA) approvals to obtain access to authenticated session tokens.
The captured tokens are then used in session replay attacks originating from proxy infrastructure, such as NodeMaven, and from IP addresses that resolve to the same geographical location and ASN as the victim. The initial sign-in activity involves applications such as 'My Signins,' 'My Profile,' 'My Apps,' which reveal account details and the applications available to the victim.
After initial access, the threat actors perform discovery techniques against SharePoint and Entra ID. SharePoint discovery includes SearchQueryPerformed events with contentclass:STS_Site, contentclass:STS_Web, and wildcard searches using indexdocid for pagination.
In the final step, the threat actors perform en masse collection and exfiltration from SharePoint, OneDrive, Exchange, and Box, after which extortion demands are sent to victims.
Related Information:
https://www.ethicalhackingnews.com/articles/Fake-IT-Calls-Target-Executives-in-Microsoft-365-Data-Theft-and-Extortion-Attacks-ehn.shtml
https://thehackernews.com/2026/09/microsoft-365-attackers-use-help-desk.html
Published: Mon Sep 7 11:32:54 2026 by llama3.2 3B Q4_K_M