VYPR
breachPublished Sep 7, 2026· 1 source

Executives Targeted in Microsoft 365 Data Theft via Vishing and Token Hijacking

A sophisticated threat cluster is targeting executives with Microsoft 365 data theft and extortion, using vishing, AitM token theft, and residential proxies.

Threat hunters have identified a significant and evolving threat cluster, tracked as PREY-0058 by Arctic Wolf, that is actively targeting Microsoft 365 and other Software-as-a-Service (SaaS) platforms. This campaign employs a multi-pronged approach, combining IT help desk vishing (voice phishing), adversary-in-the-middle (AitM) token theft, and the use of residential proxies to mask malicious sign-in activity. The primary targets are high-value individuals within organizations, including directors and vice presidents, indicating a focus on individuals with privileged access and sensitive information.

The attack chains typically commence with threat actors impersonating internal IT support or help desk personnel. These actors initiate phone calls to prospective victims, guiding them to a specially crafted authentication-themed URL. These lure domains, such as assignpasskey[.]com and mfaregister[.]com, are designed to mimic legitimate login pages. The ultimate goal of these fake portals is to trick users into entering their credentials and approving multi-factor authentication (MFA) prompts, thereby harvesting active session tokens.

Once the session tokens are captured, the attackers leverage them in session replay attacks. This technique allows them to bypass traditional authentication mechanisms by using the stolen tokens to impersonate legitimate users. The malicious activity originates from proxy infrastructure, including services like NodeMaven, and utilizes IP addresses that geographically align with the victim's location and Autonomous System Number (ASN). This sophisticated masking makes it exceptionally difficult for security teams to distinguish between legitimate and malicious network traffic.

Initial access through these stolen tokens often involves applications like 'My Signins,' 'My Profile,' and 'My Apps,' which provide the attackers with valuable account details and a view of the victim's accessible applications. Following this initial reconnaissance, the threat actors pivot to discovery techniques within the victim's environment, focusing on Microsoft's SharePoint and Entra ID (formerly Azure Active Directory). These discovery efforts involve specific search queries designed to map out SharePoint sites and web resources, often using wildcard searches for pagination.

The final stage of the attack involves the large-scale collection and exfiltration of data from critical services such as SharePoint, OneDrive, Exchange, and Box. After successfully extracting sensitive information, the threat actors engage in extortion, demanding payment from the victims to prevent the public release of the stolen data. Notably, this campaign has been observed to operate without deploying endpoint malware or engaging in traditional network-based lateral movement, relying instead on compromised credentials and session tokens.

Arctic Wolf has noted significant tradecraft similarities between PREY-0058 and a threat cluster previously identified by Mandiant as UNC6671. Furthermore, overlaps with the data extortion group Cinder and its potential connection to previous Pink operations suggest a fluid landscape of threat actors potentially sharing infrastructure or evolving from common origins. The amorphous nature of these labels highlights the dynamic and often interconnected ecosystem of cybercriminal affiliates and splinter groups.

The victims of this campaign are primarily located in the United States, spanning industries such as construction and engineering, healthcare and pharmaceuticals, real estate, finance, and professional services. To mitigate this threat, organizations are strongly advised to implement robust security measures. These include deploying Conditional Access policies, enforcing phishing-resistant MFA, restricting user access scopes within SharePoint, and conducting comprehensive employee training on vishing risks and suspicious authentication requests.

Defenders can enhance their detection capabilities by monitoring for anomalous residential-proxy token replay activity, unusual SharePoint discovery patterns, bulk access attempts, mailbox harvesting, and the emergence of newly registered authentication-themed lure infrastructure. Proactive monitoring and layered security defenses are crucial to disrupting these sophisticated data theft and extortion operations.

Synthesized by Vypr AI