Microsoft 365 Data Theft

Overview

Threat hunters have uncovered a widespread data theft and extortion campaign targeting Microsoft 365 and other SaaS platforms. The activity, tracked as PREY‑0058 by Arctic Wolf, leverages IT help desk vishing, adversary‑in‑the‑middle (AiTM) token theft, and residential‑proxy sign‑ins to compromise executive accounts.

Attack Chain

  • Fake IT calls: Threat actors impersonate internal IT or help desk staff, directing victims to authentication‑themed URLs.
  • Lure domains: Examples include assignpasskey[.]com, mfaregister[.]com, nowsso[.]com, oskeysetup[.]com, and passkey-mfa[.]com.
  • AiTM login flow: Operators harvest credentials and MFA approvals, capturing authenticated session tokens.
  • Session replay: Tokens are replayed via proxy infrastructure like NodeMaven, often from IPs near the victim’s location.

Post‑Compromise Activity

  • Discovery: Attackers query SharePoint (STS_Site, STS_Web, indexdocid) and Entra ID for account and application details.
  • Collection: Bulk exfiltration from SharePoint, OneDrive, Exchange, and Box.
  • Extortion: Victims receive demands after data theft.

Notable Characteristics

  • No malware deployment: PREY‑0058 relies entirely on phishing infrastructure, not endpoint compromise.
  • Infrastructure scale: Hundreds of subdomains impersonating real companies.
  • Target sectors: U.S. organizations in construction, healthcare, real estate, finance, and professional services.
  • Group overlaps: Tradecraft similarities with UNC6671 and possible continuation of Pink operations under the Cinder label.

Defensive Guidance

Organizations should:

  • Implement Conditional Access to restrict risky sign‑ins.
  • Deploy phishing‑resistant MFA such as FIDO2 or certificate‑based authentication.
  • Restrict SharePoint access to minimize exposure.
  • Educate staff on vishing and social engineering tactics.
  • Detect anomalies like residential‑proxy token replay, bulk SharePoint access, and mailbox harvesting.

Expert in the Cloud Insight

PREY‑0058 illustrates how human trust is the new attack surface. By combining vishing with AiTM token theft, attackers bypass traditional defenses and directly target executive accounts. The lesson is clear: phishing‑resistant MFA, strict access policies, and vigilant monitoring are essential to disrupt modern extortion campaigns.

Be the first to comment

Leave a Reply

Your email address will not be published.


*


This site uses Akismet to reduce spam. Learn how your comment data is processed.