THREAT hunters have disclosed a broad data theft and extortion operation targeting Microsoft 365 and other SaaS services, chiefly aimed at directors, vice presidents and other executives. The campaign uses IT help desk vishing and adversary-in-the-middle token theft, with sign-ins from residential proxies to harvest credentials and MFA approvals, allowing session tokens to be replayed.
After initial access, the attackers perform discovery against SharePoint and Entra ID, then exfiltrate data from SharePoint, OneDrive, Exchange and Box before issuing extortion demands. The activity is associated with PREY-0058 and shares notable tradecraft with UNC6671, with overlaps suggesting possible rebrands or continuations of related groups, though researchers emphasise that labels do not pin the activity to a single actor.
The threat architecture relies on impersonating internal IT staff and directing targets to authentication-themed lure domains such as assignpasskey[.]com and passkey-mfa[.]com, followed by an operator-controlled AITM 365 login flow. Notably, there is no deployment of endpoint malware or network lateral movement in the described chain. Victims span the United States across construction, healthcare, real estate, finance and professional services.
To counter, Arctic Wolf recommends strong Conditional Access, phishing-resistant MFA, limiting data access in SharePoint, and staff education about vishing risks; defenders are urged to detect anomalous residential-proxy token replay, SharePoint bulk access, mailbox harvesting and newly registered lure infrastructure.