Microsoft 365 Users Hit with Data Theft and Extortion Attacks via IT Help Desk Vishing
A widespread data theft and extortion threat cluster has been targeting Microsoft 365 users through IT help desk vishing, adversary-in-the-middle token theft, and residential-proxy sign-ins. The activity, tracked by Arctic Wolf under the moniker PREY-0058, mainly singles out directors, vice presidents, and other executive staff. According to researchers, the attacks begin with threat actors impersonating internal IT or help desk personnel in phone calls and directing prospective targets to an authentication-themed URL.
The captured tokens are subsequently leveraged in session replay attacks originating from proxy infrastructure, such as NodeMaven. After initial access, the threat actors perform discovery techniques against SharePoint and Entra ID. In the final step, the threat actors perform en masse collection and exfiltration from SharePoint, OneDrive, Exchange, and Box.
Arctic Wolf advises organizations to implement Conditional Access policies, deploy phishing-resistant MFA, restrict the scope of data that users have access to in SharePoint, and educate employees and help desk staff about vishing risks. Defenders can disrupt this activity by detecting anomalous residential-proxy token replay, SharePoint discovery and bulk access, mailbox harvesting, and newly registered authentication-themed lure infrastructure.