Fake IT Calls Target Executives in Microsoft 365 Data Theft and Extortion Attacks
Arctic Wolf tracks PREY-0058, a vishing and AitM token-theft crew targeting Microsoft 365 executives for data theft and extortion.
Arctic Wolf disclosed a widespread data theft and extortion cluster, PREY-0058, which overlaps with Mandiant's UNC6671 and possibly the Pink/Cinder extortion groups. Attackers impersonate IT help desk staff by phone, direct executives to authentication-themed lure domains, and run adversary-in-the-middle Microsoft 365 logins to harvest credentials, MFA approvals, and session tokens replayed via residential proxies such as NodeMaven. After access, they run discovery in SharePoint and Entra ID, then bulk-exfiltrate data from SharePoint, OneDrive, Exchange, and Box before sending extortion demands. Targets are primarily US construction, healthcare, real estate, finance, and professional services organizations.
- Uses help desk vishing and AitM login pages on domains like mfaregister[.]com and nowsso[.]com
- Replays stolen tokens from residential proxies geo-matched to victims; no endpoint malware or lateral movement
- Bulk collection from SharePoint, OneDrive, Exchange, and Box followed by extortion demands
- Tradecraft overlaps with Mandiant-tracked UNC6671 and the Cinder leak site linked to Pink operations
- Defenders urged to deploy phishing-resistant MFA, Conditional Access, and SharePoint data scoping
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| domain | assignpasskey.com | the lure domains flagged by Arctic Wolf are listed below - assignpasskey[.]com mfaregister[.]com nowsso[.]com oskeysetup[.]com oursso[.] |
| domain | mfaregister.com | agged by Arctic Wolf are listed below - assignpasskey[.]com mfaregister[.]com nowsso[.]com oskeysetup[.]com oursso[.]com passkey-mfa[.] |
| domain | nowsso.com | lf are listed below - assignpasskey[.]com mfaregister[.]com nowsso[.]com oskeysetup[.]com oursso[.]com passkey-mfa[.]com passkeyde |
| domain | oskeysetup.com | below - assignpasskey[.]com mfaregister[.]com nowsso[.]com oskeysetup[.]com oursso[.]com passkey-mfa[.]com passkeydeploy[.]com regist |
| domain | oursso.com | sskey[.]com mfaregister[.]com nowsso[.]com oskeysetup[.]com oursso[.]com passkey-mfa[.]com passkeydeploy[.]com registermymfa[.]com |
| domain | passkeydeploy.com | owsso[.]com oskeysetup[.]com oursso[.]com passkey-mfa[.]com passkeydeploy[.]com registermymfa[.]com setpasskey[.]com The attacks lead to |
| domain | passkey-mfa.com | faregister[.]com nowsso[.]com oskeysetup[.]com oursso[.]com passkey-mfa[.]com passkeydeploy[.]com registermymfa[.]com setpasskey[.]com |
| domain | registermymfa.com | up[.]com oursso[.]com passkey-mfa[.]com passkeydeploy[.]com registermymfa[.]com setpasskey[.]com The attacks lead to an operator-controll |
| domain | setpasskey.com | m passkey-mfa[.]com passkeydeploy[.]com registermymfa[.]com setpasskey[.]com The attacks lead to an operator-controlled AitM Microsoft |
Full article516 words · extracted from thehackernews.com · click to collapse
Ravie LakshmananSep 07, 2026Phishing / Identity Security
Threat hunters have disclosed details of a widespread data theft and extortion threat cluster that's targeting Microsoft 365 and other software-as-a-service (SaaS) offerings through information technology (IT) help desk vishing, adversary-in-the-middle (AitM) token theft, and residential-proxy sign-ins.
The activity, which mainly singles out directors, vice presidents, and other executive staff, is being tracked by Arctic Wolf under the moniker PREY-0058. The operation shares significant tradecraft similarities with a data extortion group that Google-owned Mandiant calls UNC6671.
It also said that the data extortion threat actor known as Cinder likely represents yet another rebrand or a possible continuation of Pink operations, citing overlaps between organizations listed on the Cinder leak site and those connected to Pink.
It's worth noting that the ever-evolving labels do not correspond to a single proven actor identity, but rather an amorphous set of affiliates, splinter crews, or groups using the same underlying phishing infrastructure, as indicated by Google early last month.
Attack chains begin with the threat actors impersonating internal IT or help desk personnel in phone calls and directing prospective targets to an authentication-themed URL that follows the pattern: <victim organization>.<lure domain>. Some of the lure domains flagged by Arctic Wolf are listed below -
- assignpasskey[.]com
- mfaregister[.]com
- nowsso[.]com
- oskeysetup[.]com
- oursso[.]com
- passkey-mfa[.]com
- passkeydeploy[.]com
- registermymfa[.]com
- setpasskey[.]com
The attacks lead to an operator-controlled AitM Microsoft 365 login flow that's designed to harvest credentials and multi-factor authentication (MFA) approvals to obtain access to authenticated session tokens. The captured tokens are subsequently leveraged in session replay attacks originating from proxy infrastructure, such as NodeMaven, and from IP addresses that resolve to the same geographical location and ASN as the victim.
"Initial sign-in activity involves applications such as 'My Signins,' 'My Profile,' 'My Apps,' which reveal account details and the applications available to the victim," researchers Steven Campbell, Trevor Daher, Stefan Hostetler, and Joshua Riccio said in an analysis.
"After initial access, the threat actors perform discovery techniques against SharePoint and Entra ID. SharePoint discovery includes SearchQueryPerformed events with contentclass:STS_Site, contentclass:STS_Web, and wildcard searches using indexdocid for pagination."
In the final step, the threat actors perform en masse collection and exfiltration from SharePoint, OneDrive, Exchange, and Box, after which extortion demands are sent to victims.
What's notable about PREY-0058 is the absence of endpoint malware deployment or network-based lateral movement. Further analysis of subdomains across the lure infrastructure has uncovered hundreds of entries impersonating real companies.
The targets are spread across the U.S., primarily in construction and engineering, healthcare and pharmaceuticals, real estate and property management, finance, and professional services.
To counter the threat, organizations are advised to implement Conditional Access policies, deploy phishing-resistant MFA, restrict the scope of data that users have access to in SharePoint, and educate employees and help desk staff about vishing risks.
"Defenders can disrupt this activity by detecting anomalous residential-proxy token replay, SharePoint discovery and bulk access, mailbox harvesting, and newly registered authentication-themed lure infrastructure," Arctic Wolf said.
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2026/09/microsoft-365-attackers-use-help-desk.html