How IT Help-Desk Vishing Scams Target Executives for Microsoft 365 Access

www.news4hackers.com-how-it-help-desk-vishing-scams-target-executives-for-microsoft-365-access-how-it-help-desk-vishing-scams-target-executives-for-microsoft-365-access

IT help-desk vishing calls, stolen session tokens, and sign-ins routed through residential proxies are driving a surge in data theft and extortion targeting Microsoft 365 and other SaaS accounts, according to Arctic Wolf.

Rising Threats and Campaigns

Arctic Wolf is monitoring the activity under the identifier PREY-0058 and has noted significant similarities in tactics to a data extortion group previously linked to UNC6671, as reported by the Google Threat Intelligence Group. The extortion campaigns have operated under multiple names, including BlackFile, Pink, Helix, Cinder, and Redact. Researchers suggest these labels may reflect affiliate networks, rebranding efforts, or overlapping operational relationships rather than a single unified actor.

Extortion Campaigns and Tactics

They assess with moderate confidence that Cinder represents an evolution of Pink, citing overlapping victim lists on the Cinder leak site with organizations previously targeted by Pink-linked phishing infrastructure. Analysis of subdomains used in lure campaigns revealed hundreds of domains impersonating legitimate companies. Targets are predominantly based in the United States and span industries such as construction and engineering, healthcare and pharmaceuticals, real estate and property management, finance, and professional services.

Attack Methodology

Executives, including Directors and Vice Presidents, are the primary focus of these attacks. The attack methodology involves initial contact via phone calls from individuals posing as internal IT staff. These callers guide victims through what appears to be standard passkey or MFA setup procedures, then direct them to a fabricated authentication page designed to mimic the organization’s official login portal. These pages are often hosted as subdomains incorporating the company’s name.

Technical Tactics

Behind the facade, an adversary-in-the-middle (AiTM) panel controlled by attackers intercepts credentials and MFA approvals, using them to obtain authenticated session tokens. Once inside, threat actors access pages like My Sign-ins, My Profile, and My Apps to gather account details and application mappings. They systematically explore SharePoint sites, pages, and other repositories to map stored data before initiating bulk collection.

Exfiltration and Recommendations

Exfiltration occurs from SharePoint, OneDrive, Exchange, and other SaaS platforms such as Box. Exchange data collection specifically captures MailItemsAccessed events. Arctic Wolf recommends organizations enhance Conditional Access policies to block or challenge proxy and hosting traffic, implement phishing-resistant MFA solutions that resist fake login page relays, restrict SharePoint account permissions, and train help-desk personnel to identify vishing attempts.

Targeted Industries and Executives

Defenders can disrupt these activities by detecting anomalies such as residential-proxy token replay, SharePoint discovery patterns, bulk access behaviors, and mailbox harvesting. The firm has also released indicators of compromise, including lure domains, exfiltration ASNs, and residential proxy providers associated with sign-in activity, enabling organizations to cross-reference their logs.

Technical Details and Indicators

The attacks highlight vulnerabilities in credential management and the growing sophistication of social engineering tactics targeting high-level corporate access.

According to Arctic Wolf, the firm is monitoring the activity under the identifier PREY-0058 and has noted significant similarities in tactics to a data extortion group previously linked to UNC6671, as reported by the Google Threat Intelligence Group.



About Author

en_USEnglish