Summary
Key Points:
- A widespread data theft and extortion campaign, tracked as PREY-0058, targets Microsoft 365 and other SaaS platforms through vishing and adversary-in-the-middle (AitM) attacks.
- The campaign primarily affects executives in sectors such as construction, healthcare, finance, and real estate, leading to credential theft and unauthorized access to sensitive data stored in SharePoint, OneDrive, and Exchange.
- Organizations are recommended to implement Conditional Access policies, deploy phishing-resistant MFA, limit data access in SharePoint, and educate staff on vishing risks.
Technical Details: Attackers impersonate IT personnel to direct targets to phishing URLs for credential harvesting. They exploit captured tokens for session replay attacks using proxy infrastructure.
MITRE ATT&CK Techniques:
- T1071.001 - Application Layer Protocol: Web Protocols (Command and Control)
- T1566.001 - Phishing: Vishing (Initial Access)
- T1078 - Valid Accounts (Credential Access)
- T1213 - Data from Information Repositories (Collection)
IOCs Mentioned: None mentioned
Join the discussion — sign up to comment, upvote, and save articles.