Fake IT calls drive Microsoft 365 data theft
Arctic Wolf reports that attackers pose as internal IT staff and trick executives into using a fake Microsoft 365 sign-in page. The attackers then reuse the captured session to download cloud data and demand money.
- Report priority
- High
- Involves
- Microsoft 365
What is known
- The attack requires a target to answer a fake IT or help desk call and follow the caller's instructions.
- The caller directs the person to an authentication-themed address controlled by the attacker.
- That site intercepts the Microsoft 365 sign-in, capturing the password and using the person's multifactor authentication approval to obtain a session token, which lets the attacker reuse the completed sign-in.
- The attacker reuses that token through proxy services, searches the victim's cloud accounts and downloads data from services including SharePoint, OneDrive, Exchange and Box.
What to do
If someone received an unexpected IT call, give your IT or security team the time, caller information, account used and full web address visited. Entra ID and Microsoft 365 administrators should check sign-in and audit records around that time for unusual residential-proxy access, access to My Signins, My Profile or My Apps, SharePoint SearchQueryPerformed events, and bulk access to mail or files. Matching activity needs investigation but doesn't by itself confirm data theft. Finding no matches doesn't rule out compromise of that account or other accounts.
Identity administrators should configure Conditional Access rules that restrict when accounts can sign in and require phishing-resistant multifactor authentication, such as passkeys. Confirm that the intended accounts are covered. Organizations should limit unnecessary SharePoint access and train employees and help desk staff to verify unexpected IT calls before visiting a sign-in page or approving authentication. If someone followed the caller's instructions, ask the security team to assess the account and review the indicators in the reported campaign. Prevention settings alone don't establish whether an earlier sign-in was compromised.
Reported details
Arctic Wolf tracks the reported activity as PREY-0058 and notes tradecraft overlap with Mandiant's UNC6671. It says Cinder may be a rebrand or continuation of Pink, but these labels don't establish one proven actor identity. Lures use addresses matching <victim organization.<lure domain, while captured session tokens are reportedly replayed through services such as NodeMaven and IP addresses selected to resemble the victim's location and network provider.