IT Help-Desk Vishing and Evilginx2 PhaaS Campaigns Hijack Microsoft 365 Sessions to Fuel Extortion
Three overlapping disclosures — Arctic Wolf's PREY-0058/UNC6671 vishing, Microsoft's Storm-3121/Storm-3032 tracking, and CloudSEK's infiltration of the BigBear 2.0 phishing-as-a-service panel — detail how attackers defeat MFA, steal Microsoft 365 session…
Reports published September 8-11, 2026 cover two distinct but related waves of Microsoft 365 session-hijacking activity. First, a voice-phishing (vishing) campaign: Arctic Wolf tracks a cluster dubbed PREY-0058, sharing tradecraft with Google Threat Intelligence's UNC6671, in which callers impersonating internal IT help desks talk mostly US-based executives (construction, healthcare, real estate, finance, professional services) through fake passkey/MFA setups that route them to adversary-in-the-middle (AiTM) panels harvesting credentials, MFA approvals, and session tokens. Microsoft Security Research has tracked similar activity since May 2026, attributing initial access to Storm-3121 (linked to ShinyHunters and Falcon extortion) and Storm-3032 (the Helix extortion operation descended from BlackFile); lures include passkey/MFA/SSO update requests by phone, SMS, and Teams messages from compromised accounts, using domains such as add-passkey[.]com and contoso[.]add-passkey[.]com, plus device-code authentication flows that yield valid OAuth tokens bypassing MFA. Post-compromise, attackers register their own MFA methods for persistence that survives password resets, enumerate tenants via Microsoft Graph, and exfiltrate SharePoint, OneDrive, Exchange Online, and Box data at deliberately low rates (under 1,000 files or messages per hour), with the python-httpx user agent observed in high-volume access; stolen sessions are replayed through residential proxies (Arctic Wolf cites NodeMaven) matched to victims' geography and ASN to defeat impossible-travel and location-based Conditional Access. Separately, CloudSEK gained admin access in June 2026 to the BigBear 2.0 phishing-as-a-service panel, an Evilginx2-based AiTM platform using the 'offy' phishlet against Microsoft 365, operated under the alias 'General Boss' by at least five affiliates across 42 VPS nodes (mostly on Vultr). It captured 5,137 credential records across 461 organizations in over 40 countries — including 4,148 session cookies, 1,032 plaintext passwords, and 474 completed post-MFA authentications from 3,331 victim IPs — using custom code to disable FIDO2/WebAuthn on phishing pages, geo-matched residential proxies, Telegram exfiltration, and automated cookie replay. IT services and managed service providers were the most-targeted sector (151 of 461 organizations per CSO Online), raising downstream supply-chain risk. Sources diverge slightly on extortion branding: Arctic Wolf lists BlackFile, Pink,…
- Tracking identifiers: Arctic Wolf's PREY-0058, Google Threat Intelligence's UNC6671, Microsoft's Storm-3121 and Storm-3032 (campaign observed since May 2026), and CloudSEK's BigBear 2.0 PhaaS (panel infiltrated June 2026).
- Vishing tradecraft: callers impersonating internal IT help desks push fake passkey/MFA/SSO updates via phone, SMS, and Teams messages from compromised accounts, using lure domains such as add-passkey[.]com and contoso[.]add-passkey[.]com.
- Token theft methods: AiTM reverse proxies capture credentials, MFA approvals, session cookies, and tokens; device-code authentication flows issue OAuth tokens to attacker-controlled apps, exposing SaaS including Salesforce, Slack, and…
- BigBear 2.0 scale: 5,137 credential records across 461 organizations in 40+ countries, including 4,148 session cookies, 1,032 plaintext passwords, 474 completed post-MFA authentications, and 3,331 unique victim IPs.
- BigBear 2.0 infrastructure: Evilginx2-based with the 'offy' phishlet, operator alias 'General Boss', at least five affiliates, 42 VPS nodes mostly on Vultr, Telegram exfiltration, and custom code disabling FIDO2/WebAuthn on phishing pages.
- Victim targeting: vishing focuses on US-based executives in construction, healthcare, real estate, finance, and professional services; BigBear 2.0 most heavily hit IT services and MSPs (151 of 461 organizations), creating supply-chain risk.
- Evasion: residential proxies (NodeMaven per Arctic Wolf) matched to victim country, geo, and ASN defeat impossible-travel and location-based Conditional Access; cloud data collection throttled below 1,000 files or emails per hour;…
- Attribution: Microsoft links Storm-3121 to ShinyHunters/Falcon extortion and Storm-3032 to Helix (descended from BlackFile); Google TI links related activity (UNC6671) to BlackFile, Helix, Falcon, Pink, and Redact; Arctic Wolf also cites…
Coverage timelineoldest first · each row is one article
- · 8d agoIT Help Desk Impersonation Lets Hackers Bypass MFA
Security Affairs· 72
Arctic Wolf tracks PREY-0058 posing as IT help desk to steal Microsoft 365 sessions via AiTM panels, then extorting executives after SaaS data theft.