Helpnetsecurity
Vishing Attacks Target Executives for Microsoft 365 Data Theft
Article Content
A wave of data theft and extortion targeting Microsoft 365 and other SaaS accounts has emerged, tracked by Arctic Wolf as PREY-0058. The attackers use vishing calls impersonating IT help desk staff to trick executives into providing credentials and multi-factor authentication (MFA) approvals. This method involves adversary-in-the-middle (AiTM) attacks, where attackers capture session tokens for unauthorized access. The primary targets are directors and vice presidents across various sectors, including healthcare, finance, and real estate. The attack infrastructure has been linked to residential proxies, specifically NodeMaven. Arctic Wolf notes that the extortion group Cinder may be a rebranding of Pink, with overlapping victim lists. Organizations are advised to implement stronger Conditional Access policies and phishing-resistant MFA solutions to mitigate these threats.
Key Points: • Attackers impersonate IT staff to gain access to Microsoft 365 accounts. • Targets include executives in sectors like healthcare and finance. • Organizations should enhance security measures against vishing and AiTM attacks.
Ask AI about this cluster
Answers cite the sources they use
Analyzing cluster data...
Referenced clusters
Something went wrong. Please try again.