Cybersecurity experts have uncovered a significant data theft and extortion operation targeting Microsoft 365 and other software-as-a-service (SaaS) platforms. The campaign, known as PREY-0058, employs tactics such as impersonating IT support via vishing and exploiting adversary-in-the-middle (AitM) token theft. These attacks primarily target senior executives like directors and vice presidents.
Overview of the Threat Campaign
Arctic Wolf, a cybersecurity firm, is monitoring this threat under the codename PREY-0058. The operation shares similarities with another data extortion group tracked by Mandiant, a Google-owned entity, known as UNC6671. Interestingly, the threat actor identified as Cinder appears to be a rebranding or continuation of previous operations associated with the Pink group.
The campaign does not link to a single entity but involves various affiliates or groups using the same phishing infrastructure. This lack of a centralized identity complicates efforts to counteract these threats.
Attack Methods and Techniques
The attack strategy begins with threat actors masquerading as IT help desk personnel, contacting targets by phone and directing them to authentication-themed URLs. Notable domains used in these scams include assignpasskey[.]com and mfaregister[.]com. The goal is to harvest login credentials and multi-factor authentication (MFA) approvals.
Once the credentials are obtained, attackers use the tokens for session replay attacks. These attacks often originate from proxy infrastructure, such as NodeMaven, and occur from IP addresses that match the victim’s location.
Impact and Mitigation Strategies
After gaining access, attackers conduct a discovery process on platforms like SharePoint and Entra ID to gather detailed account information. They perform bulk data collection from SharePoint, OneDrive, Exchange, and Box, followed by extortion demands to the victims.
Despite the absence of endpoint malware or lateral network movements, the threat is significant. The campaign’s infrastructure includes numerous subdomains impersonating legitimate companies, with targets spread across sectors such as construction, healthcare, and finance.
Organizations are advised to adopt Conditional Access policies, enforce phishing-resistant MFA, and restrict data access in SharePoint. Employee education on vishing threats is also crucial. Arctic Wolf suggests monitoring for unusual token replay activity and newly registered lure domains as part of a defensive strategy.
As cyber threats evolve, staying informed and implementing robust security measures remain vital for protecting sensitive data and organizational integrity.
