Fake IT Calls Steal Microsoft 365 Tokens, Target Executives

Fake IT Calls Steal Microsoft 365 Tokens, Target Executives

Estimated reading time: 5 minutes · Last updated:

Arctic Wolf has flagged a threat cluster it calls PREY-0058 that uses fake IT help-desk calls to lure executives into malicious authentication pages and harvest Microsoft 365 session tokens. The attack chain combines vishing, an operator-controlled AitM Microsoft 365 login flow and token replay via residential proxies to access SharePoint, OneDrive, Exchange and other SaaS repositories. Targets are primarily senior staff in the U.S., concentrating on executives across industries such as construction and engineering; healthcare and pharmaceuticals; real estate and property management; finance; and professional services. Arctic Wolf says the operation prioritizes token theft over deploying endpoint malware, which changes both detection priorities and the mitigations defenders should apply.

Initial sign-in activity involves applications such as 'My Signins,' 'My Profile,' 'My Apps,' which reveal account details and the applications available to the victim,

Steven Campbell, Trevor Daher, Stefan Hostetler and Joshua Riccio

Key takeaways

  • Threat cluster: Arctic Wolf is tracking the activity under the moniker PREY-0058 and links it to tooling that shares tradecraft with Mandiant-tracked UNC6671.
  • Primary tactic: Attackers begin with vishing impersonating internal IT, then run an operator-controlled AitM Microsoft 365 login flow to capture credentials and MFA approvals.
  • Infrastructure: Researchers identified lure domains such as assignpasskey[.]com and passkey-mfa[.]com and found hundreds of entries impersonating real companies.
  • Key mitigations: Arctic Wolf recommends Conditional Access, phishing-resistant MFA, narrowing SharePoint access and detecting residential-proxy token replay.

How the attack chain turns a phone call into Microsoft 365 session theft

The campaign starts with voice calls in which attackers pose as internal IT or help-desk staff and shepherd targets to authentication-themed URLs built on a pattern such as <victim>.<lure domain>. Once a user attempts to sign in, operators position an operator-controlled AitM Microsoft 365 login flow between the target and the real service. That flow captures credentials and multi-factor approvals and converts them into authenticated session tokens the victim no longer controls.

Those tokens are valuable because they bypass endpoint controls: with a valid token, an attacker can call APIs and access web applications as the user without deploying malware on the device. The threat actors then replay the captured sessions from proxy infrastructure — the analysis names NodeMaven as an example — and from IP addresses that resolve to the same geographic region and autonomous system as the victim, making the access look legitimate to basic location checks.

Targets, scale and the impersonation infrastructure defenders must track

Arctic Wolf reports that most victims are U.S.-based directors, vice presidents and other executives, with incidents clustered in sectors including construction and engineering; healthcare and pharmaceuticals; real estate and property management; finance; and professional services. The attackers register lure domains that mimic authentication and passkey workflows; examples flagged include assignpasskey[.]com, mfaregister[.]com and passkeydeploy[.]com.

Analysis of the lure infrastructure turned up hundreds of entries impersonating real companies, a pattern that lets the attackers craft believable pretexts for each target. The examination also ties overlaps between identities used on extortion leak sites and previously observed campaigns, with Arctic Wolf noting similarities to groups Mandiant calls UNC6671 and to actors using the Cinder and Pink labels.

What defenders can detect and the controls Arctic Wolf recommends

Because these campaigns avoid installing endpoint malware or performing lateral network movement, Arctic Wolf frames detection around identity activity and unusual access patterns. Practical signals to hunt for include anomalous residential-proxy token replay, bulk SharePoint discovery and access, mass mailbox harvesting, and sign-ins from newly registered authentication-themed lure domains.

On controls, Arctic Wolf recommends Conditional Access policies that block or step up risky sign-ins, and the adoption of phishing-resistant MFA methods so that approval prompts and passkeys cannot be trivially replayed. The guidance also includes restricting the scope of users' SharePoint access and training help-desk staff and executives to treat unsolicited authentication calls as high-risk, because the chain begins with social engineering by phone.

Why token-based extortion without malware raises different priorities

Because the actors do not deploy endpoint malware or move laterally within networks, traditional incident-response playbooks that center on host containment are less effective. Instead, Arctic Wolf advises defenders to assume compromise when tokens display abnormal discovery patterns or when large-scale exfiltration from SharePoint, OneDrive or Exchange is observed; Arctic Wolf describes those stages as occurring before extortion notices are sent.

This model also elevates identity hygiene: tightening app consent, auditing third-party token lifetimes, and monitoring service principals and OAuth authorizations become immediate priorities. Arctic Wolf says the multiplicity of names — PREY-0058, UNC6671, Cinder, Pink — points to overlapping affiliates and shared phishing infrastructure rather than a single proven actor identity, so defenders should treat sightings as part of a broader ecosystem of token-focused abuse.

Lure domains flagged in the Arctic Wolf analysis
Domain Suggested purpose Notes
assignpasskey[.]com Passkey setup imitation Flagged by Arctic Wolf
mfaregister[.]com MFA registration lure Flagged by Arctic Wolf
passkey-mfa[.]com Authentication-themed lure Flagged by Arctic Wolf

How the campaign could evolve — two-sided view

The case for

  • Vendors and enterprises adopt phishing-resistant MFA and tighter Conditional Access, reducing the success rate of AitM token captures.
  • Security teams build detections for residential-proxy token replay and SharePoint discovery, enabling faster containment before large-scale exfiltration.

The case against

  • Attackers widen their lure infrastructure and refine domain impersonations, increasing successful contacts with senior staff.
  • Affiliates and splinter groups reuse the same phishing and AitM tooling, keeping attribution difficult and enabling rapid campaigns across sectors.

What to be careful about

  • Mass exfiltration from cloud storage without endpoint alarms since access appears as valid sessions.
  • Credential and token replay from residential proxies that mimic victim geolocation and evade simple IP checks.
  • Widespread domain impersonation that makes automated URL filtering less reliable without up-to-date blocklists.
  • Targeting of senior staff increases the chance of high-value data disclosure and follow-on extortion.

The bottom line

The PREY-0058 cluster shifts the battlefield from compromised hosts to stolen session tokens, forcing defenders to make identity telemetry the first line of detection. Because attackers harvest and replay tokens from residential proxies, organisations should prioritise phishing-resistant MFA, tighten Conditional Access and audit SharePoint and Exchange access patterns. Tracking and quickly blocking newly registered authentication lures and monitoring for large-scale discovery queries are practical short-term steps. Longer term, coordinated vendor guidance and timely disclosures by affected organisations will be essential to disrupt the ecosystem of reused phishing infrastructure.

What to watch

  • Watch for Arctic Wolf to publish updates to its PREY-0058 indicators and an expanded list of authentication-themed lure domains; no date has been set.
  • Watch for public breach notifications from companies named on extortion sites such as Cinder that could confirm affected organizations; no date has been set.

Frequently asked questions

How do attackers capture Microsoft 365 session tokens in these campaigns?

Attackers use vishing to lure targets to authentication-themed URLs and run an operator-controlled AitM Microsoft 365 login flow that captures credentials and MFA approvals, converting them into session tokens that can be replayed from proxies.

Which organizations and roles are being targeted?

According to Arctic Wolf, PREY-0058 focuses on directors, vice presidents and other executive staff across U.S. sectors such as construction and engineering, healthcare and pharmaceuticals, real estate, and finance.

What immediate controls reduce the risk of token replay?

Arctic Wolf recommends Conditional Access policies, adoption of phishing-resistant MFA, restricting SharePoint access scope, and monitoring for anomalous residential-proxy token replay and bulk SharePoint discovery.



Share:

Categories

Newest course every month

Advertise your offline course to a wider audience with our landing page.

You May Also Like

Proofpoint links the BlueMoon exploit kit to four espionage clusters, including APT31; CISA gave agencies until 18 September 2026 to...
Cylake funding: Nir Zuk's AI-native startup raised $245M by convertible note, bringing total to $290M and targeting regulated on-premises customers.
Arctic Wolf links PREY-0058 vishing and AitM pages to Microsoft 365 token theft from executives and session replay via residential...