ZeroHour
Story · 1 source · 2 articlesfirst updated ()1

IT Help-Desk Vishing Crews Hijack Microsoft 365 and SaaS Accounts in Multi-Brand Extortion Operation

highThreat actorexploited in the wildimportance 78
What's new: Across the Sept 7–11, 2026 reporting window, coverage evolved from initial disclosures to full attribution and technical depth. Google/Mandiant and Arctic Wolf (Sept 7–8) established UNC6671/PREY-0058, the extortion-brand rotation, the $10.6M Bitcoin figure, and NodeMaven proxy evasion. Microsoft (Sept 9) added the May 2026 start date, the passkey-themed AiTM/device-code mechanics, and…
Merged summary · glm-5.3 · rewritten as coverage arrives

Google/Mandiant (UNC6671), Arctic Wolf (PREY-0058), and Microsoft (Storm-3121/Storm-3032) track overlapping vishing campaigns in which attackers impersonate IT help desks to steal credentials, MFA approvals, and session tokens via AiTM and device-code…

Multiple vendors are tracking one overlapping wave of vishing-driven data theft and extortion against Microsoft 365 and other SaaS environments under different names: Google Threat Intelligence/Mandiant tracks UNC6671, Arctic Wolf tracks PREY-0058 (stated to overlap UNC6671 and possibly the Pink/Cinder groups), and Microsoft Security Research attributes the initial-access tradecraft to Storm-3121 and Storm-3032. No material conflicts between sources were reported. Microsoft has observed the activity since May 2026, while Google separately traced over $10.6 million in Bitcoin payments to UNC6671-linked wallets between January 7 and May 12, 2026, with initial demands exceeding $3 million. Attackers call or text employees' personal mobile phones — supplemented by SMS lures and, per CSO Online, Teams messages from compromised accounts — while posing as internal IT help-desk staff urging urgent passkey, MFA, or SSO updates. Targets skew toward directors, VPs, and executives, primarily at US construction, healthcare, real estate, finance, and professional-services organizations; Google says UNC6671 has hit dozens of organizations across North America, Australia, and the UK, shifting toward high-value financial and legal firms from July 2026. Dark Reading highlights the BYOD exposure and reports that access is subsequently handed to extortion groups such as ShinyHunters. CSO Online notes the passkey theme is a pretext: phishable MFA is what gets bypassed, not the passkey standard. Victims are steered to authentication-themed lure domains such as mfaregister[.]com, nowsso[.]com, and add-passkey[.]com, often embedding victim organization names as subdomains (e.g., contoso.add-passkey[.]com), frequently registered via Nicenic and operational within hours. Manually gated adversary-in-the-middle (AiTM) panels harvest credentials, MFA approvals, and session tokens in real time, while device-code authentication flows issue OAuth tokens to attacker-controlled apps, exposing Salesforce, Slack, Dropbox, and other SSO applications. Arctic Wolf observed stolen sessions replayed through NodeMaven residential proxies with IPs matching victims' geo-location and ASN — defeating impossible-travel alerts — with exfiltration shifting from datacenter ASNs to that same proxy network and no endpoint malware or lateral movement observed. After access, actors pivot through identity providers into Microsoft 365, Okta, and other SaaS apps; register their own MFA methods (phone,…

  • Same overlapping activity tracked under multiple names: Google/Mandiant's UNC6671, Arctic Wolf's PREY-0058 (overlapping UNC6671), and Microsoft's Storm-3121 and Storm-3032; no source conflicts reported.
  • Microsoft has observed the campaign since May 2026; Google tracked over $10.6 million in Bitcoin payments to UNC6671-linked wallets between January 7 and May 12, 2026, with initial demands exceeding $3 million.
  • Initial access: vishing calls and SMS to employees' personal phones (plus Teams messages from compromised accounts) impersonating IT help desk staff with urgent passkey/MFA/SSO update pretexts.
  • Lure domains include mfaregister[.]com, nowsso[.]com, and add-passkey[.]com, often with victim org names as subdomains (e.g., contoso.add-passkey[.]com), registered via Nicenic and operational within hours.
  • AiTM panels harvest credentials, MFA approvals, and session tokens; device-code flows issue OAuth tokens to attacker-controlled apps, exposing Salesforce, Slack, Dropbox, and other SSO applications.
  • Stolen sessions are replayed through NodeMaven residential proxies matching victims' geo-location and ASN, defeating impossible-travel detection; no endpoint malware or lateral movement observed.
  • Persistence via attacker-registered MFA methods (phone, authenticator, software OTP) that survive token expiry and password resets; Microsoft Graph used for tenant and OAuth-grant enumeration.
  • Exfiltration from SharePoint, OneDrive, Exchange, and Box via REST APIs, deliberately throttled below 1,000 files or messages per hour, with python-httpx user agent seen in high-volume access.

Coverage timeline

  1. · 8d ago
    The Hacker News· 78
    UNC6671 Vishing Attacks Target Personal Phones to Steal SaaS Data

    Google and Mandiant attribute vishing-based SaaS data extortion attacks to UNC6671, now operating under the Redact, Pink, Helix, and Falcon brands.

  2. · 8d ago
    The Hacker News· 76
    Fake IT Calls Target Executives in Microsoft 365 Data Theft and Extortion Attacks

    Arctic Wolf tracks PREY-0058, a vishing and AitM token-theft crew targeting Microsoft 365 executives for data theft and extortion.