Microsoft 365 Accounts Hijacked Through IT Help-Desk Vishing Calls
Arctic Wolf has identified a wave of data theft and extortion targeting Microsoft 365 and other SaaS accounts. The attacks, tracked under the name PREY-0058, involve IT help-desk vishing calls, stolen session tokens, and sign-ins routed through residential proxies.
The attackers pose as internal IT staff to gain access to executive-level employees' credentials, often through what seems like routine passkey or MFA setup. They then use an operator-controlled adversary-in-the-middle (AiTM) panel to catch the password and MFA approval, pulling an authenticated session token in the process.
The threat actors systematically map out stored data from SharePoint site by site and page by page before performing bulk collection and exfiltration from SaaS providers such as Box. They also use residential proxy networks for initial access and exfiltration, generating MailItemsAccessed events in Exchange collection and high volumes of FileAccessed and FileDownloaded events in SharePoint and OneDrive collection.
Arctic Wolf advises organizations to tighten Conditional Access, swap in phishing-resistant MFA, cut down on single SharePoint account reach, and train help-desk staff to spot vishing calls. They also published indicators of compromise for organizations to check their own logs against this cluster.