Threat hunters have revealed information about a large-scale data theft and extortion threat group that is focusing on Microsoft 365 and other software-as-a-service (SaaS) platforms through IT help desk vishing, adversary-in-the-middle (AitM) token theft, and residential-proxy sign-ins.
This activity primarily targets directors, vice presidents, and other high-ranking officials, and is being monitored by Arctic Wolf under the name PREY-0058. It has notable similarities in tactics to a data extortion group identified by Google-owned Mandiant as UNC6671.
Additionally, it has been suggested that the data extortion actor known as Cinder may be another rebranding or a potential continuation of Pink operations, as there are connections between the organizations listed on the Cinder leak site and those associated with Pink.
It is important to highlight that the constantly changing names do not refer to a single identifiable actor, but rather a fluid collection of affiliates, splinter groups, or entities utilizing the same phishing infrastructure, as noted by Google earlier last month.
The attack sequences commence with the threat actors posing as internal IT or help desk staff during phone calls, guiding potential victims to an authentication-themed URL that follows the format: .. Below are some of the lure domains identified by Arctic Wolf:
- assignpasskey[.]com
- mfaregister[.]com
- nowsso[.]com
- oskeysetup[.]com
- oursso[.]com
- passkey-mfa[.]com
- passkeydeploy[.]com
- registermymfa[.]com
- setpasskey[.]com
The attacks lead to an operator-controlled AitM Microsoft 365 login process designed to capture credentials and multi-factor authentication (MFA) approvals to gain access to authenticated session tokens. These tokens are then used in session replay attacks that originate from proxy infrastructure, such as NodeMaven, and from IP addresses that correspond to the same geographical area and ASN as the victim.
According to researchers Steven Campbell, Trevor Daher, Stefan Hostetler, and Joshua Riccio, “Initial sign-in activity involves applications such as ‘My Signins,’ ‘My Profile,’ ‘My Apps,’ which reveal account details and the applications available to the victim.”
“After gaining initial access, the threat actors utilize discovery techniques against SharePoint and Entra ID. SharePoint discovery includes SearchQueryPerformed events with contentclass:STS_Site, contentclass:STS_Web, and wildcard searches using indexdocid for pagination.”
In the concluding phase, the threat actors carry out mass collection and exfiltration from SharePoint, OneDrive, Exchange, and Box, after which they send extortion demands to the victims.
What stands out about PREY-0058 is the lack of endpoint malware deployment or lateral movement within the network. Further examination of subdomains across the lure infrastructure has revealed hundreds of entries impersonating legitimate companies.
The targets are distributed across the U.S., mainly in sectors such as construction and engineering, healthcare and pharmaceuticals, real estate and property management, finance, and professional services.
To mitigate this threat, organizations are recommended to implement Conditional Access policies, deploy phishing-resistant MFA, limit user access to data in SharePoint, and educate employees and help desk personnel about the risks of vishing.
Arctic Wolf stated, “Defenders can disrupt this activity by detecting anomalous residential-proxy token replay, SharePoint discovery and bulk access, mailbox harvesting, and newly registered authentication-themed lure infrastructure.”
Source: Original article
