Yaamlabs

Identity

PREY-0058: fake IT calls that steal Microsoft 365 sessions

Arctic Wolf's PREY-0058 calls executives as IT, sends them to a fake passkey page and relays the real Microsoft 365 login to steal the session.

On September 3, Arctic Wolf published research on PREY-0058, a data theft and extortion cluster that phones directors, vice presidents and other senior staff while posing as their own IT help desk. The caller talks the executive through what sounds like a routine passkey or MFA (multi-factor authentication) enrollment on a page named after their company. That page is an adversary-in-the-middle (AitM) proxy: the victim completes a genuine Microsoft 365 sign-in, and the attacker keeps the session.

Victims are mainly US organizations in construction and engineering, healthcare and pharmaceuticals, real estate, finance and professional services. Arctic Wolf says the tradecraft overlaps heavily with UNC6671, a group Google's Threat Intelligence Group has tracked since spring as it moved from broad enterprise targets to financial services. Law firm Goodwin reports that dozens of US private equity firms, hedge funds and asset managers were breached in a four-day window in July. If your executives sign in with passwords plus push, SMS or code-based MFA, this campaign can take over their accounts.

How it works

The call comes first, often to the executive's personal mobile. Google reports that the callers spoof real help desk numbers and describe an urgent, mandatory security migration: the company is "rolling out passkeys" and the executive needs to enroll today. Genuine passkeys would have stopped this attack, for reasons explained below.

The caller then reads out a link on a domain such as setpasskey[.]com, passkey-mfa[.]com, mfaregister[.]com or passkeydeploy[.]com, with a subdomain built from the victim organization's name, in the pattern <victim organization>.<lure domain>. To someone listening on the phone, "yourcompany dot setpasskey dot com" sounds like an internal address. Google counted more than 60 such root domains registered between April and August 2026, and found that most do not use wildcard DNS, so each subdomain is created for a specific target.

A static phishing page can only collect a password, and a one-time code typed into it expires within seconds. An AitM proxy forwards everything the victim types to the real Microsoft sign-in service and returns Microsoft's real responses, including the MFA prompt. The executive approves the push or types the code, and Microsoft issues a session cookie to the party it is talking to: the proxy. The proxy passes a copy to the victim, whose sign-in appears to work, and keeps one for the operator.

A session cookie records that MFA has already been passed, so whoever presents it is not challenged again until the session expires or is revoked. EvilTokens reached the same outcome earlier this month by keeping the victim on the real Microsoft page and abusing the device code flow. PREY-0058 puts the victim on a fake domain and relays the real flow through it.

Phishing-resistant methods break the relay. A FIDO2 security key or passkey signs a challenge that includes the web origin the browser is actually on. On yourcompany.setpasskey.com the browser either finds no credential for that site or produces a signature Microsoft will not accept for login.microsoftonline.com. Number matching, push approval and SMS codes have no such binding, so they are relayed like everything else.

What attackers are doing

Once the operator holds a session, they replay it from residential proxy networks, most often NodeMaven, choosing exit IP addresses in the victim's own region and on similar networks so the sign-in does not look foreign. Their first stops are the My Sign-ins and My Account portals, which generate the Entra audit events "User started security info registration" and "User registered security info". Google also reports that the operators deleted password reset confirmations and MFA change alerts from the mailbox before the victim saw them.

Collection follows. In Exchange Online, Arctic Wolf saw bulk MailItemsAccessed and AttachmentAccessed events through the One Outlook Web client. In SharePoint and OneDrive, search queries such as contentclass:STS_Site, contentclass:STS_Web and wildcard queries mapped every site before bulk FileAccessed and FileDownloaded events, first with a python-requests user agent and more recently with spoofed Chrome strings. Box was hit the same way. Arctic Wolf found no malware on endpoints and no lateral movement on the network in these intrusions.

Extortion arrives over the Tox messenger, typically with a 72-hour deadline and an offer of sample files as proof. The brands behind the demands have changed often: BlackFile, which announced a shutdown in May, then Redact, Pink, Helix and Cinder. Researchers note that these names may be affiliates or rebrands rather than one proven actor. Google tracked 141.65 BTC, about $10.69 million, reaching BlackFile wallets between January 7 and May 12. Opening demands ran from $1 million to $3 million, negotiations usually cut them by 50 to 75%, and the average final payment was about $750,000.

The broader trend matches. Mandiant's M-Trends 2026 report found that voice phishing was the initial access vector in 11% of the intrusions it investigated in 2025, second only to exploits, while email phishing fell to 6%.

What to do

  1. Start with phishing-resistant sign-in for executives. In the Microsoft Entra admin center, create a Conditional Access policy targeting a group of executives, finance staff and admins, and under Grant choose Require authentication strength, then Phishing-resistant MFA. Enroll FIDO2 keys or passkeys for those users before you turn the policy on, and run it in report-only mode for a few days.
  2. Add a second policy requiring a compliant or hybrid-joined device, so a stolen cookie replayed from the attacker's browser fails, even from a residential IP in the right city.
  3. Change the help desk script. Your help desk never phones users to enroll passkeys or MFA, and staff should hear that from you in advance. Anyone who gets such a call hangs up and calls the help desk back on the number from the intranet. Resets and new MFA methods need a second check the caller cannot control, such as manager approval recorded in a ticket.
  4. Block the lure infrastructure. Arctic Wolf's indicators of compromise on GitHub list the lure domains, the proxy providers and three autonomous system numbers (ASNs, the IDs of the networks) used for exfiltration: AS51582, AS23470 and AS399629. Add them to DNS filtering and to Conditional Access named locations.

To check whether you were hit, filter Entra ID Protection risk detections for Anomalous token and, if you have Microsoft 365 E5, Attacker in the Middle, which fires when a session is linked to a known malicious reverse proxy. In the sign-in logs, look for a successful MFA sign-in followed within minutes by activity from a different IP address and ASN (the AutonomousSystemNumber field in SigninLogs) under the same Session ID. In the Unified Audit Log, search for "User registered security info" from unfamiliar IP addresses, SearchQueryPerformed events containing contentclass:STS_Site, and hundreds of FileAccessed events in one session.

For a confirmed account, reset the password and revoke sessions with Revoke-MgUserSignInSession -UserId <UPN>, because a password reset alone does not end a session the attacker already holds. Then delete any MFA methods and devices the user does not recognise, remove new inbox rules and forwarding, and review app consents under Enterprise applications for grants made after the sign-in.

We test help desk verification and executive sign-in policies in our safeguarding and hardening work, and our security operations team hunts for the relayed sessions and bulk SharePoint reads described above. Open the chat, and Yaali, our AI agent, will pass your question to an engineer.


Sources: Arctic Wolf, Arctic Wolf IOCs on GitHub, The Hacker News, Help Net Security, RH-ISAC, Google Threat Intelligence Group, Goodwin, Google M-Trends 2026, Help Net Security on M-Trends 2026, Microsoft token theft playbook, Microsoft Entra ID Protection risk detections, Microsoft Entra linkable identifiers.

Back to the blog, or read this post on the full site.