hacker-news · Crawled Sep 7, 2026
Fake IT Calls Target Executives in Microsoft 365 Data Theft and Extortion Attacks
9 IoCs 1 Actors 1 Malware
Read original article ↗
AI Summary
A threat cluster tracked as PREY-0058 by Arctic Wolf is conducting data theft and extortion attacks targeting Microsoft 365 users, primarily executives, through vishing (voice phishing) and adversary-in-the-middle (AitM) attacks. Attackers impersonate IT help desk personnel and direct victims to malicious authentication pages using domains that mimic legitimate services, such as 'mfaregister[.]com', to steal credentials and MFA tokens. These tokens are then replayed via residential proxy infrastructure to access Microsoft 365 services, enabling large-scale data exfiltration from SharePoint, OneDrive, Exchange, and Box without deploying malware or moving laterally within networks.
AI-extracted · verify before operational use
Extracted Entities 2 found
Indicators of Compromise 9 extracted
| Type | Value | Detail |
|---|---|---|
| Domain | assignpasskey[.]com | Details → |
| Domain | mfaregister[.]com | Details → |
| Domain | nowsso[.]com | Details → |
| Domain | oskeysetup[.]com | Details → |
| Domain | oursso[.]com | Details → |
| Domain | passkey-mfa[.]com | Details → |
| Domain | passkeydeploy[.]com | Details → |
| Domain | registermymfa[.]com | Details → |
| Domain | setpasskey[.]com | Details → |
MITRE ATT&CK TTPs 21 techniques
T1003 OS Credential Dumping · Credential Access T1020 Automated Exfiltration · Exfiltration T1027 Obfuscated Files or Information · Defense Evasion T1059 Command and Scripting Interpreter · Execution T1059.001 PowerShell · Execution T1059.003 Windows Command Shell · Execution T1071.001 Web Protocols · Command And Control T1071.004 DNS · Command And Control T1078 Valid Accounts · Defense Evasion T1087 Account Discovery · Discovery T1133 External Remote Services · Persistence T1190 Exploit Public-Facing Application · Initial Access T1213 Data from Information Repositories · Collection T1486 Data Encrypted for Impact · Impact T1496 Resource Hijacking · Impact T1530 Data from Cloud Storage · Collection T1531 Account Access Removal · Impact T1555 Credentials from Password Stores · Credential Access T1566 Phishing · Initial Access T1566.002 Spearphishing Link · Initial Access T1611 Escape to Host · Privilege Escalation