Fake IT Calls Target Executives in Microsoft 365 Data Theft and Extortion Attacks
A sophisticated data theft and extortion campaign, dubbed PREY-0058, is targeting executives at various organizations, primarily in the construction, healthcare, real estate, finance, and professional services sectors. The attackers use vishing tactics to trick employees into clicking links leading to authentication-themed URLs, ultimately harvesting credentials and MFA approvals to steal data from Microsoft 365 and other SaaS platforms. The campaign is linked to previous extortion groups like Cinder and Pink, utilizing residential proxies and a complex infrastructure of impersonated domains.
A widespread data theft and extortion campaign, dubbed PREY-0058, is targeting executives at various organizations, primarily in the construction, healthcare, real estate, finance, and professional services sectors. The attackers use vishing tactics to trick employees into clicking links leading to authentication-themed URLs, ultimately harvesting credentials and multi-factor authentication (MFA) approvals to steal data from Microsoft 365 and other SaaS platforms. The campaign is linked to previous extortion groups like Cinder and Pink, utilizing residential proxies and a complex infrastructure of impersonated domains.
Initial sign-in activity involves applications such as 'My Signins,' 'My Profile,' 'My Apps,' which reveal account details and the applications available to the victim. After initial access, the threat actors perform discovery techniques against SharePoint and Entra ID. SharePoint discovery includes SearchQueryPerformed events with contentclass:STS_Site, contentclass:STS_Web, and wildcard searches using indexdocid for pagination.
The campaign begins with threat actors impersonating internal IT or help desk personnel via phone calls, directing victims to authentication-themed URLs. These URLs lead to a Microsoft 365 login flow controlled by the attackers, designed to steal credentials and MFA approvals. The captured tokens are then leveraged in session replay attacks originating from proxy infrastructure, such as NodeMaven, and from IP addresses resolving to the same geographical location and ASN as the victim.
The targets are spread across the U.S. The campaign involves a complex infrastructure of impersonated domains, and the threat actors perform en masse collection and exfiltration from SharePoint, OneDrive, Exchange, and Box, after which extortion demands are sent to victims. Notably, the campaign lacks endpoint malware deployment or network-based lateral movement.
To counter the threat, organizations are advised to implement Conditional Access policies, deploy phishing-resistant MFA, restrict the scope of data that users have access to in SharePoint, and educate employees and help desk staff about vishing risks. Defenders can disrupt this activity by detecting anomalous residential-proxy token replay, SharePoint discovery and bulk access, mailbox harvesting, and newly registered authentication-themed lure infrastructure.
