hacker-news · Crawled Sep 7, 2026

Fake IT Calls Target Executives in Microsoft 365 Data Theft and Extortion Attacks

9 IoCs 1 Actors 1 Malware
Read original article ↗

AI Summary

A threat cluster tracked as PREY-0058 by Arctic Wolf is conducting data theft and extortion attacks targeting Microsoft 365 users, primarily executives, through vishing (voice phishing) and adversary-in-the-middle (AitM) attacks. Attackers impersonate IT help desk personnel and direct victims to malicious authentication pages using domains that mimic legitimate services, such as 'mfaregister[.]com', to steal credentials and MFA tokens. These tokens are then replayed via residential proxy infrastructure to access Microsoft 365 services, enabling large-scale data exfiltration from SharePoint, OneDrive, Exchange, and Box without deploying malware or moving laterally within networks.

AI-extracted · verify before operational use

Extracted Entities 2 found

Indicators of Compromise 9 extracted

Type Value Detail
Domain assignpasskey[.]com Details →
Domain mfaregister[.]com Details →
Domain nowsso[.]com Details →
Domain oskeysetup[.]com Details →
Domain oursso[.]com Details →
Domain passkey-mfa[.]com Details →
Domain passkeydeploy[.]com Details →
Domain registermymfa[.]com Details →
Domain setpasskey[.]com Details →

MITRE ATT&CK TTPs 21 techniques