Widespread Data Theft and Extortion Threat Targets Microsoft 365 Users
Cybersecurity threat hunters have unveiled significant details regarding a large-scale data theft and extortion operation that is currently targeting Microsoft 365 and various software-as-a-service (SaaS) platforms. This operation is characterized by tactics such as vishing—voice phishing that dupes users into divulging sensitive information through impersonation—and adversary-in-the-middle (AitM) token theft, as well as the exploitation of residential proxies for unauthorized sign-ins.
The campaign, which appears to primarily focus on high-ranking executives such as directors and vice presidents, is being tracked by Arctic Wolf under the designation PREY-0058. Notably, the strategies employed by this group demonstrate remarkable similarities to those of another data extortion organization identified by Google-owned Mandiant as UNC6671. In recent observations, it has been suggested that the Cinder threat actor could potentially represent either a rebranding of or a continuation of previous Pink operations, given the overlaps noted between entities featured on the Cinder leak site and those linked to Pink.
The shifting nomenclature within the cybersecurity landscape does not denote a single, identifiable actor. Instead, it reflects a nebulous group of affiliates, splinter cells, or teams sharing a common phishing infrastructure, a sentiment echoed by Google in an analysis released last month.
These malicious activities commence with the impersonators posing as internal IT personnel during phone interactions with targets. They direct victims to a deceptive authentication-focused URL that follows the pattern:
Once victims are prompted to engage with these fraudulent sites, the operation transitions into a controlled AitM Microsoft 365 login process designed to harvest user credentials and multi-factor authentication (MFA) approvals. The goal is to gain access to authenticated session tokens, which are subsequently exploited in session replay attacks using proxy infrastructure, such as NodeMaven. Attackers often originate from IP addresses resembling the geographical location of the victim’s organization.
The initial sign-in attempts frequently involve applications such as ‘My Signins,’ ‘My Profile,’ and ‘My Apps,’ which allow attackers to glean crucial account information and identify applications available to the targeted individual. Once initial access is achieved, the threat actors deploy discovery techniques against SharePoint and Entra ID, utilizing search queries that involve specific content classes and broad wildcard searches for pagination.
The attack culminates in a mass collection and exfiltration of data from platforms like SharePoint, OneDrive, Exchange, and Box. Victims may subsequently receive extortion demands as the attackers leverage the stolen information for financial gain.
What stands out in the PREY-0058 operation is the lack of endpoint malware deployment or network-based lateral movement, which distinguishes it from many traditional attacks. In-depth analysis of the subdomains used in the lure infrastructure has revealed hundreds of entries impersonating legitimate organizations, indicating a broad attempt to mislead targets.
The majority of organizations affected by these attacks are concentrated in sectors such as construction, healthcare, pharmaceuticals, real estate, finance, and professional services, primarily across the United States. To combat these risks, experts recommend implementing Conditional Access policies, deploying phishing-resistant MFA solutions, minimizing user access to sensitive information on platforms like SharePoint, and enhancing employee education regarding vishing threats.
Defensive strategies can effectively disrupt this nefarious activity by identifying anomalies related to residential-proxy token replay, SharePoint discovery, bulk access attempts, mailbox harvesting, and the emergence of newly registered fraudulent domains that mimic authentic authentication services. The evolving nature of this threat landscape necessitates diligence among organizations to protect against these sophisticated attack methodologies.