PREY-0058 Threat Cluster Uses Social Engineering to Bypass Endpoint Security
A new threat cluster tracked as PREY-0058 has been discovered to bypass endpoint security through social engineering. Attackers pose as internal IT help desk staff via phone calls and direct executives toward rogue authentication portals.
Once victims land on these pages, adversary-in-the-middle panels intercept credentials and multi-factor approvals in real time.
The stolen session tokens are then replayed using residential proxy networks that match the victim's exact geographic location.
Intruders waste no time once they slip past the front door, immediately shifting focus to massive data harvesting.
To detect these attacks, monitor Microsoft 365 sign-ins coming from residential proxies or hosting networks such as NodeMaven.