securityaffairs.com 8 Sept 2026, 07:41 UTC

Fake IT Support Calls Let Attackers Hijack Microsoft 365 Sessions

Fake IT Support Calls Let Attackers Hijack Microsoft 365 Sessions
CyberSIXT Evidence Panel Source marked as original reporting
Threat Actor
PREY-0058

ATTACKERS are bypassing endpoint security by calling victims and impersonating internal IT help desk staff, directing executives to rogue authentication portals. The campaign, tracked as PREY-0058, focuses on Microsoft 365 and SaaS environments, where real-time man-in-the-middle pages intercept credentials and MFA approvals.

Victims’ sign-in sessions are then replayed using residential proxy networks that match their geographic location, often via NodeMaven, allowing attackers to bypass impossible travel alerts and proceed to data harvesting.

Once inside, the criminals conduct discovery against SharePoint and Entra ID, mapping repositories and draining files from OneDrive, Exchange and Box before issuing extortion demands. Indicators of compromise include Microsoft sign-ins from residential proxies or hosting networks, unusual early-session pages such as OfficeHome, My Signins, My Profile and My Apps, and surge activity in MailItemsAccessed from proxy IP addresses.

Defenders should monitor for unusual SharePoint search queries that enumerate sites and files and for large, rapid access to emails, as well as heavy file access or downloads from a single user.

Practical responses proposed by the reporting include requiring managed devices for Microsoft 365, blocking or challenging access from proxy networks, and employing phishing-resistant MFA such as FIDO2 keys or device-bound passkeys; organisations are also advised to limit access to sensitive SharePoint data, enable Continuous Access Evaluation, and train staff and help-desk teams to verify unexpected IT calls through trusted channels. Artic Wolf released IoCs to accompany the alerts.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline