HackMyIP
← Back to News
2026-09-07 The Hacker News

Fake IT Help Desk Calls Used to Steal Microsoft 365 Data from Executives

PhishingData BreachThreat Intel

Threat hunters at Arctic Wolf have uncovered a widespread data theft and extortion campaign, tracked as PREY-0058, that targets Microsoft 365 and other SaaS platforms by impersonating internal IT help desk staff over the phone. The operation primarily targets directors, vice presidents, and other C-suite executives, luring them to adversary-in-the-middle (AitM) login pages hosted on look-alike domains such as assignpasskey[.]com, mfaregister[.]com, nowsso[.]com, passkeydeploy[.]com, and registermymfa[.]com. Arctic Wolf notes significant tradecraft overlap with UNC6671, a cluster tracked by Mandiant, as well as the data extortion group Cinder, which is believed to be a rebrand of the Pink operations. Researchers caution these evolving labels reflect an amorphous network of affiliates sharing infrastructure rather than a single confirmed actor.

The attack chain begins with a vishing call during which the operator instructs the victim to visit an authentication-themed URL following the pattern – victim organization.lure domain – where credentials and MFA approvals are harvested. Captured session tokens are then replayed through residential proxy infrastructure, including the NodeMaven network, using IP addresses that geolocate to the same region and ASN as the victim to evade detection. Once authenticated, the attackers enumerate the victim's Microsoft 365 environment through apps like My Signins, My Profile, and My Apps, then pivot to discovery against SharePoint and Entra ID via SearchQueryPerformed events.

In the final stage, the threat actors perform bulk data collection and exfiltration from SharePoint, OneDrive, Exchange, and Box before issuing extortion demands. Notably, PREY-0058 operates without deploying endpoint malware or performing network-based lateral movement, relying entirely on token theft and session replay. Subdomain analysis of the lure infrastructure has revealed hundreds of entries impersonating legitimate companies, indicating a broad and ongoing targeting campaign. Organizations concerned about credential exposure can run their addresses through the email breach checker, while security teams should monitor for sign-ins routed through anonymizing services using the VPN/proxy detector and enforce phishing-resistant authentication methods such as FIDO2 hardware keys.

Source: The Hacker News →

Related Tools

Check whether this kind of story affects you — free, no signup:

Email Breach Check →Privacy Checkup →

Related Guides

Learn the background behind this story:

What is a data breach? →Credential stuffing attacks →How to check for an email breach →