Fake IT Calls Steal Microsoft 365 Data From Executives — SkimNews

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- Arctic Wolf disclosed PREY-0058, a data theft and extortion campaign targeting Microsoft 365 via IT help desk vishing, AitM token theft, and residential-proxy sign-ins, with attacks mainly aimed at directors, VPs, and other executive staff
- Mandiant tracks the same tradecraft under UNC6671, and Arctic Wolf assesses data extortion group Cinder likely represents a rebrand or continuation of Pink operations based on overlap between organizations on their respective leak sites
- Attack chain starts with phone calls impersonating internal IT personnel that direct targets to authentication-themed lure domains—including assignpasskey[.]com, mfaregister[.]com, passkey-mfa[.]com, and registermymfa[.]com—leading to an AitM Microsoft 365 login flow that harvests credentials and MFA approvals
- Captured tokens are used in session replay attacks routed through NodeMaven proxy infrastructure from IPs resolving to the same geographic location and ASN as the victim, defeating crude IP-based anomaly checks
- After access, attackers run discovery against SharePoint and Entra ID using SearchQueryPerformed events with contentclass:STS_Site and contentclass:STS_Web, then en masse exfiltrate from SharePoint, OneDrive, Exchange, and Box before sending extortion demands
- Notably, the operation deploys no endpoint malware and performs no network-based lateral movement; targets span U.S. sectors including construction and engineering, healthcare and pharmaceuticals, real estate, finance, and professional services
- Subdomain analysis uncovered hundreds of entries impersonating real companies across the lure infrastructure, and Arctic Wolf advises detecting anomalous residential-proxy token replay, SharePoint bulk access, mailbox harvesting, and newly registered authentication-themed domains
Why it matters: Because PREY-0058 extracts data without deploying endpoint malware or performing lateral movement, traditional EDR and antivirus tools miss the activity entirely—leaving help desk verification protocols and phishing-resistant MFA as the practical chokepoints. The use of residential proxies matching the victim's geography and ASN defeats coarse IP-based detection, and hundreds of lure subdomains impersonating real companies signal broad, reusable targeting infrastructure rather than a one-off operation.
Ask SkimNews



