Connect with us

NEWS

Fake IT Calls Steal Microsoft 365 Tokens Without Malware

Arctic Wolf’s PREY-0058 cluster phones executives, steals Microsoft 365 session tokens, and empties SharePoint through residential proxies without dropping malware.

Published

on

Arctic Wolf is tracking a data-theft cluster that phones directors and vice presidents, steals their Microsoft 365 session tokens, and copies SharePoint, OneDrive, Exchange and Box files without dropping malware. The firm labels the activity PREY-0058.

Operators pose as internal IT, walk the target to a passkey-themed login page, and replay the captured session from a residential IP in the same city and network as the victim. Impossible-travel checks stay quiet because the address looks local, and endpoint tools never see a payload.

The Call Goes to the Vice President

Arctic Wolf analysts Steven Campbell, Trevor Daher, Stefan Hostetler and Joshua Riccio, writing in hunting notes for PREY-0058 dated September 3, 2026, say the callers most often aim at directors, vice presidents and other executive staff. That is a choice about access, not about who clicks the most mail.

An executive account can already open contracts, board packs, patient files or deal rooms. Help desks are used to treating those people as a priority, and a travelling vice president is a believable candidate for a rushed sign-in. The phone call supplies the urgency that a cold email no longer can.

The lure is an authentication URL built as the victim’s organisation name plus a root domain that sounds like a passkey or MFA rollout. Arctic Wolf found hundreds of those subdomains impersonating real companies. The nine root domains it listed are all about enrolment, not invoices or payroll.

PASSKEY LURE DOMAINS ARCTIC WOLF FLAGGED

  • assignpasskey.com: Passkey assignment wording on a lookalike enrolment host.
  • mfaregister.com: MFA registration wording used as the help-desk pretext.
  • nowsso.com: Single sign-on urgency baked into the hostname.
  • oskeysetup.com: Operating-system key setup language for a rushed call.
  • oursso.com: Internal-sounding SSO branding on an attacker domain.
  • passkey-mfa.com: Combined passkey and MFA wording on one lure.
  • passkeydeploy.com: Deployment language that matches an IT rollout script.
  • registermymfa.com: First-person MFA registration phrasing aimed at staff.
  • setpasskey.com: Short passkey-setup hostname used in the same cluster.

A live operator sits behind an adversary-in-the-middle panel and gates each victim by hand, so the fake Microsoft 365 login can capture the password and the MFA approval in one sitting. The prize is not the password file. It is the authenticated session token that follows a successful sign-in.

Stolen Tokens Come Back Through Residential IPs

Once the token is in hand, the operators replay it through residential proxy networks, most often NodeMaven, from addresses that resolve to the same geography and ASN as the victim. Arctic Wolf also logged DataImpulse, Luminati, Massive, ProxyRack, Shifter, Soax and Yilu on those sign-ins.

A replayed session from a home-looking IP produces no failed login and no fresh MFA prompt. The tenant sees a user who already passed the challenge, coming in from a plausible place. That is why a second factor on the original call does not stop the next hour of work. MFA proved someone was present. It said nothing about who held the cookie afterwards.

First hops inside the tenant are quiet. Sign-ins hit OfficeHome, My Sign-ins, My Profile, My Apps and Microsoft Account Controls v2, which show the account’s history and the apps it can open. Then the operators enumerate Entra ID and SharePoint. There is still no implant, no remote-access tool, and no move across the corporate network. Arctic Wolf says it observed no endpoint malware and no network-based lateral movement in this cluster.

Google Threat Intelligence Group, which tracks overlapping tradecraft as UNC6671, has been describing the same phone-to-token path since May 2026. Callers reach staff on personal mobiles, sometimes spoofing the real help-desk number, and send them to subdomains such as company.createssopasskey.com. After the session is live, scripts pull data from Microsoft 365 and Okta while operators delete password-reset mail, security alerts and MFA-change notices so the mailbox does not warn the user.

How PREY-0058 Empties SharePoint After the Login

After the token is replayed, the operators do not hunt for a domain admin. They search SharePoint the way a new hire with too many permissions would, then they pull everything that account can already open, including OneDrive, Exchange and Box, and they send the extortion note once the haul is out.

SharePoint discovery uses SearchQueryPerformed events with contentclass:STS_Site and contentclass:STS_Web, plus wildcard pagination on indexdocid. Arctic Wolf says those queries are consistent across cases and rare for ordinary users in its MDR customer base. Collection then shows up as heavy FileAccessed and FileDownloaded volume, while Exchange collection shows MailItemsAccessed bursts.

HUNT SIGNALS IN MICROSOFT 365 AUDIT LOGS

Signal Where it lands What Arctic Wolf flags
SearchQueryPerformed with contentclass:STS_Site or STS_Web, plus indexdocid pagination SharePoint audit Site mapping that is rare for a normal user
MailItemsAccessed with ClientAppId 9199bf20-a13f-4107-85dc-02114787ef48 and API ID c999ed3e-27ae-4cb3-b3a2-46b056af63d3 Exchange A pair that matches the collection toolkit, especially in short bursts
High-volume FileAccessed and FileDownloaded from one account SharePoint and OneDrive Confidence rises when the IP is a proxy or the user agent is python-requests, Microsoft.Graph.Client or python-httpx
Sign-in chain through OfficeHome, My Sign-ins, My Profile and My Apps Entra sign-in logs A residential-proxy source at the start of the session

Exfil IPs used to resolve to hosting networks such as PrivateLayer (AS51582), ReliableSite.Net (AS23470) and Bl Networks (AS399629). Arctic Wolf says the same residential proxy used for the first sign-in, including NodeMaven, has more recently carried the copy-out traffic as well, which strips another easy contrast between login and theft.

The Mailbox Harvest Signature

On Exchange, the ClientAppId and API ID pair above is the practical fingerprint. Confidence goes up when a large number of matching MailItemsAccessed events fire in a short window, which looks like a script rather than a person clicking through mail, or when the client IP sits on a datacentre or residential-proxy range.

Google Threat Intelligence Group documented the scale of the SharePoint side in May 2026. In one intrusion the operators used a Python script from a remote IP to pull over a million SharePoint files and OneDrive objects. In another they raced through tens of thousands of SharePoint file actions. They also searched internal indexes for the strings “confidential” and “SSN” to rank what to steal first.

Later jobs often logged FileAccessed rather than FileDownloaded, because the script fetched document URLs with a valid session cookie instead of issuing a formal download. A SOC that only alerts on FileDownloaded will treat that as browsing. User-agent mismatch is the tell: the client app may spoof Microsoft Office while the recorded agent is python-requests/2.28.1 or Windows PowerShell.

The intent of this attack is to exfiltrate as much data as possible from SharePoint in order to force the victim to pay a significant sum of money to prevent the data from being leaked. The more data that an individual user has access to, the more can be stolen as the result of a single successful phishing account compromise.

Steven Campbell, Trevor Daher, Stefan Hostetler and Joshua Riccio, Arctic Wolf, PREY-0058 hunting notes

PREY-0058 victims in Arctic Wolf’s set are mostly US firms in construction and engineering, healthcare and pharmaceuticals, real estate and property management, finance, and professional services. Those trades live in shared document libraries. Publishing the files is the lever. Nobody needs to encrypt a server.

Four Brands, One Help Desk Script

The labels keep moving. Arctic Wolf folds PREY-0058 in with tradecraft that Google Threat Intelligence Group calls UNC6671, and with public notes from ReliaQuest, Unit 42, Okta and CrowdStrike. The cluster has been tied to self-named extortion brands including BlackFile, Pink, Helix, Cinder and Redact. Arctic Wolf says those names may be affiliates, rebrands or shared tooling rather than one proven crew, and it assesses with moderate confidence that Cinder is a rebrand or continuation of Pink because leak-site victims overlap with Pink-attributed phishing hosts.

Google Threat Intelligence Group, in an August 6, 2026 update by Tyler McLellan and Austin Larsen, still treats UNC6671 as active after BlackFile’s advertised retirement in May 2026, and it ties the same phone-and-relay baseline to Redact, Pink, Helix and Falcon. Shared root domains such as passkeyhelpdesk.com, passkeydeploy.com and setupsso.com targeted organisations later listed on different leak sites, and the phishing templates matched across hosts.

THE EXTORTION BRAND CALENDAR

  1. Early 2026: UNC6671 appears under the BlackFile name, using help-desk calls and adversary-in-the-middle pages against Microsoft 365 and Okta. Google Threat Intelligence Group later says the set hit dozens of organisations in North America, Australia and the UK.
  2. January 7 to May 12, 2026: Eighteen BlackFile bitcoin wallets receive 141.65 BTC, about $10.69 million at the time of the transfers.
  3. May 11, 2026: A public shutdown notice goes up for the BlackFile leak site. Payments to the same wallets continue after that date.
  4. June 27, 2026: Redact posts that BlackFile was hijacked by an exiled affiliate and presents a single Tox ID and PGP key as the new channel.
  5. June 1 to July 31, 2026: New phishing domains appear about once every 1.6 days, faster than the 28 root domains seen from April 1 to May 31 at one every 2.2 days. Seven domains go live in a 72-hour window from July 20 to July 22.
  6. August 6, 2026: Google Threat Intelligence Group publishes the multi-brand map. On that date, 7 of 8 still-resolving phishing domains do not use wildcard DNS, which the authors read as targeted selection rather than mass spray.
  7. September 3, 2026: Arctic Wolf publishes the PREY-0058 pack, adding Cinder to the brand list and documenting residential-proxy replay against Microsoft 365, SharePoint, OneDrive, Exchange and Box.

Google Threat Intelligence Group counted 141.65 bitcoin in tracked payments to those 18 wallets. Opening demands typically ran from $1 million to $3 million or more, then dropped by 50% to 75% in talks. In more than 53% of tracked cases in that window, final payments averaged $750,000, about 10.2 BTC. Targeting narrowed from broad enterprise verticals in April and May toward technology, transport and hospitality in June, then toward financial, private-equity and legal firms in July.

When a firm stayed silent, UNC6671 flooded staff inboxes from throwaway Gmail accounts, left threatening voicemails for C-suite numbers, and in severe cases used swatting against company personnel. The first note was often unbranded, with a 72-hour clock and a Tox or Session ID, and only named BlackFile once the victim replied.

Microsoft Made Passkeys the Default on September 1

Two days before Arctic Wolf dated its pack, Microsoft began a tenant-by-tenant shift that makes the phone script easier to believe. On September 1, 2026, Microsoft started rolling out passkeys as the default method in Entra ID. Users who still have SMS or voice MFA get a passkey prompt the next time they complete multifactor authentication. Microsoft says it will retire Microsoft-provided SMS and voice delivery on February 1, 2027.

A real passkey is origin-bound. A FIDO2 key or device-bound passkey will not mint a valid assertion for assignpasskey.com. That is why Arctic Wolf and Google Threat Intelligence Group both tell firms to move executives onto phishing-resistant methods. The current calls still work because the victim is not asked to touch a hardware key on the real login host. The victim is asked to “enrol” on a lookalike page, then types a password and approves a push or code while the relay steals the session.

UNC6671 callers have continued to call targeted employees on their personal mobile numbers, circumventing corporate security controls. In at least some recent cases, the threat actor has spoofed the legitimate helpdesk phone number adding an air of legitimacy. During these phone calls, operating under the false pretext of an urgent helpdesk mandate to enable FIDO2 passkeys or update multi-factor authentication enrollment, the caller directs the employee to a lookalike credential-harvesting subdomain.

Tyler McLellan and Austin Larsen, Google Threat Intelligence Group, August 6, 2026 analysis

Microsoft lists Windows Hello for Business, FIDO2 security keys, passkeys (including passkeys in Microsoft Authenticator) and certificate-based authentication as phishing-resistant options. Authenticator push and one-time codes are not in that set. A help-desk culture that still cold-calls staff to “finish MFA setup” hands the operators their lines. Arctic Wolf’s rule is the inverse: internal IT should not cold-call users to register passkeys or change sign-in methods, and staff should check any such request on a channel they already trust.

What Stops a Replayed Microsoft 365 Session

A stolen cookie dies when the tenant will not honour it from an unmanaged device, an untrusted network or a session that no longer matches the user. Extra MFA prompts on the original call do not do that work, because the prompt already succeeded. Device trust, shorter sessions and a smaller SharePoint blast radius are the controls that still bite after the phone goes dead.

Arctic Wolf’s pack tells defenders to require managed or compliant devices for Microsoft 365 access, so a replay from attacker kit fails the device check. It also tells them to block or step up authentication for proxy, anonymiser and hosting ranges, and to turn on continuous access evaluation in Entra so a location change can kill a session in near real time. Microsoft’s CAE notes say a token exported to a machine outside a trusted network can be blocked when location policy is in force, and that Exchange Online and SharePoint Online can treat a move off a compliant network as a reason to re-authenticate even if the access token has not expired.

CONTROLS THAT CUT A REPLAYED SESSION

  • Device trust: Conditional Access that requires an Intune-compliant or Entra-joined device stops a cookie replayed from a proxy laptop.
  • Phishing-resistant sign-in: FIDO2 keys and device-bound passkeys will not complete on a lure domain, which ends the relay if that is the only way in.
  • SharePoint scope: Group-based site access and sensitivity labels shrink what one phished vice president can copy.
  • Session lifetime: Google Threat Intelligence Group tells firms to force re-authentication at least once per work day and to shorten idle timeouts during an active calling wave.
  • Audit hunts: Watch residential-proxy token replay, the SharePoint search patterns above, mailbox harvest bursts, and new passkey-themed domains that contain the company name as a subdomain.
  • Help-desk rule: No inbound call resets MFA or enrols a passkey; staff call back on a number already on file, including for executives.

Google Threat Intelligence Group is explicit that these break-ins are not a flaw in Microsoft 365 or Okta products. They are social engineering against people who can already see too much, followed by bearer tokens that still travel. Limit the library one login can open, bind the session to a managed device, and the same phone call leaves with far less.

Harry is the editor and lead writer of CUMBERNAULD MEDIA, which he runs as an independent publication after a decade in journalism spent moving from reporting to editing. His habit is to open the document before the summary of it. A company result is read from the filing rather than the press release, a court or regulatory decision from the judgment itself, a scientific finding from the paper and its methods section rather than the headline claim, and a sporting sanction from the governing body's own ruling. That approach shapes coverage across news, business and technology as much as science, sports and entertainment, and it carries into the lifestyle, travel, auto and gaming pages, where product specifications are checked against the manufacturer's sheet and, where possible, against Harry's own testing. Every number is checked before publication, and where a source's figures are disputed the story says so. Corrections follow a public policy and are marked on the page. Readers anywhere in the world who write in get a reply from him, and the address is support@cumbernauld-media.com.

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Trending