Fake IT Calls Target Executives in Microsoft 365 Data Theft and Extortion Attacks
A threat cluster designated PREY-0058 (linked to UNC6671 and possibly Cinder/Pink) is targeting executives via IT help desk vishing to steal Microsoft 365 session tokens through adversary-in-the-middle (AitM) attacks Attackers use authentication-themed lure domains (e.g., assignpasskey.com, mfaregister.com) to capture credentials and MFA approvals, then replay tokens from residential proxies mimicking the victim's geography and ASN The operation involves no endpoint malware or lateral movement;
Analysis
TL;DR
- A threat cluster designated PREY-0058 (linked to UNC6671 and possibly Cinder/Pink) is targeting executives via IT help desk vishing to steal Microsoft 365 session tokens through adversary-in-the-middle (AitM) attacks
- Attackers use authentication-themed lure domains (e.g., assignpasskey.com, mfaregister.com) to capture credentials and MFA approvals, then replay tokens from residential proxies mimicking the victim's geography and ASN
- The operation involves no endpoint malware or lateral movement; instead, actors directly exfiltrate data from SharePoint, OneDrive, Exchange, and Box before sending extortion demands
- Targets span U.S. industries including construction, healthcare, real estate, finance, and professional services, with hundreds of subdomains impersonating real companies
- Mitigation recommendations include Conditional Access policies, phishing-resistant MFA, SharePoint data access restrictions, and vishing awareness training
Why It Matters
This attack pattern represents a significant escalation in identity-based threats against enterprise Microsoft 365 environments, exploiting the trust gap between employees and internal IT support channels. The use of residential proxies to mimic victim geography and ASN makes detection through traditional IP-based controls exceptionally difficult, challenging existing security monitoring approaches.
Technical Details
- Attack vector: Vishing calls impersonating internal IT/help desk, directing targets to authentication-themed URLs following the pattern
<victim organization>.<lure domain> - Lure domains flagged: assignpasskey.com, mfaregister.com, nowsso.com, oskeysetup.com, oursso.com, passkey-mfa.com, passkeydeploy.com, registermymfa.com, setpasskey.com
- AitM token theft: Operator-controlled Microsoft 365 login flow harvests credentials, MFA approvals, and session tokens without triggering traditional security alerts
- Token replay: Captured tokens are replayed from NodeMaven proxy infrastructure and IPs resolving to the same geographical location and ASN as the victim, bypassing location-based anomaly detection
- Post-access reconnaissance: Initial sign-ins probe "My Signins," "My Profile," and "My Apps"; SharePoint discovery uses SearchQueryPerformed events with contentclass:STS_Site, contentclass:STS_Web, and wildcard searches via indexdocid for pagination
- Exfiltration targets: SharePoint, OneDrive, Exchange, and Box — followed by extortion demands
Industry Insight
- The convergence of vishing, AitM proxy infrastructure, and residential proxy token replay represents a new baseline for high-value executive targeting; organizations should prioritize phishing-resistant MFA (FIDO2/WebAuthn) over SMS or push-based MFA, which are trivially bypassed by this attack chain
- The absence of malware and lateral movement means traditional endpoint detection and network monitoring will likely miss this activity entirely — defenders must shift focus to identity and sign-in anomaly detection, particularly around residential-proxy token replay and bulk SharePoint access patterns
- The amorphous, rebranding nature of these threat groups (PREY-0058/UNC6671/Cinder/Pink) suggests a shared infrastructure ecosystem; threat intelligence sharing around lure domain registration patterns and NodeMaven proxy indicators should be prioritized across the security community
Disclaimer: The above content is generated by AI and is for reference only.