PREY-0058: IT help-desk vishing + AiTM token theft → M365/SaaS data extortion
Arctic Wolf Pack Alert (3 September 2026) tracks PREY-0058: executives (directors/VPs) are cold-called by actors impersonating internal IT/help desk and steered to authentication-themed lure domains (assignpasskey.com, mfaregister.com, nowsso.com, oskeysetup.com, oursso.com, passkey-mfa.com, passkeydeploy.com, registermymfa.com, setpasskey.com and org-specific subdomains). An operator-gated AiTM Microsoft 365 login harvests credentials and MFA approvals; stolen sessions are replayed via residential proxies (notably NodeMaven, often same geo/ASN as the victim). Post-access discovery hits SharePoint/Entra (SearchQueryPerformed with contentclass:STS_Site/STS_Web and indexdocid pagination), then bulk exfil from SharePoint, OneDrive, Exchange, and Box — no endpoint malware or network lateral movement observed. Overlaps GTIG UNC6671 tradecraft; related extortion brands cited include BlackFile, Pink, Helix, Cinder, and Redact (affiliate/rebrands, not a single proven identity). Targets primarily US construction/engineering, healthcare/pharma, real estate, finance, professional services. Defences: phishing-resistant MFA (FIDO2/device-bound passkeys), Conditional Access (device compliance; block proxy/hosting ASN), Continuous Access Evaluation, tighten SharePoint scope, train staff that IT will not cold-call for passkey enrolment. Wire: The Hacker News (7 Sep 2026). Distinct from BigBear Evilginx2 PhaaS already on desk.
- Product
- Microsoft 365 / Entra ID / SharePoint / Exchange Online (and connected SaaS e.g. Box)
- Exploited in Australia?
- unknown
- Patch to
- Phishing-resistant MFA (FIDO2/passkeys); Conditional Access for device trust and proxy/hosting blocks; CAE; limit SharePoint blast radius; hunt NodeMaven/residential-proxy token replay and SharePoint STS_Site discovery; verify unexpected IT/passkey calls out-of-band
Primary: Arctic Wolf Pack Alert — PREY-0058 (3 Sep 2026) · The Hacker News (7 Sep 2026)
