Threat Advisory

Attackers Bypass MFA to Gain Unauthorized Microsoft 365 Access

Threat: Phishing Campaign
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Arctic Wolf is tracking a widespread IT impersonation and voice-phishing cluster, PREY-0058. Threat actors target senior users through highly targeted social engineering by calling or texting victims to bypass MFA controls. If successful, attackers gain unauthorized access to Microsoft 365 and associated SaaS platforms without exploiting any software vulnerability. They then conduct rapid data exfiltration across email, file storage, and cloud document repositories. The threat actors use static residential proxy infrastructure, specifically NodeMaven Proxy, to blend into legitimate user activity and evade detection.

Once inside, they use the One Outlook Web Client App (AppID info 9199bf20-a13f-4107-85dc-02114787ef48) to retrieve mail from an abnormal API path (API ID c999ed3e-27ae-4cb3-b3a2-46b056af63d3). They then access SharePoint Online and execute broad queries via API to map accessible sites and subsites. This activity generates SearchQueryPerformed event logs. The actors also execute a wildcard query (*) to list all documents available in SharePoint and then paginate through the results.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Arctic Wolf is tracking a widespread IT impersonation and voice-phishing cluster, PREY-0058. Threat actors target senior users through highly targeted social engineering by calling or texting victims to bypass MFA controls. If successful, attackers gain unauthorized access to Microsoft 365 and associated SaaS platforms without exploiting any software vulnerability. They then conduct rapid data exfiltration across email, file storage, and cloud document repositories. The threat actors use static residential proxy infrastructure, specifically NodeMaven Proxy, to blend into legitimate user activity and evade detection.

Once inside, they use the One Outlook Web Client App (AppID info 9199bf20-a13f-4107-85dc-02114787ef48) to retrieve mail from an abnormal API path (API ID c999ed3e-27ae-4cb3-b3a2-46b056af63d3). They then access SharePoint Online and execute broad queries via API to map accessible sites and subsites. This activity generates SearchQueryPerformed event logs. The actors also execute a wildcard query (*) to list all documents available in SharePoint and then paginate through the results.[emaillocker id="1283"]

The consistent use of static residential proxy infrastructure is intended to blend into legitimate user activity and evade detection. Arctic Wolf MDR Protection has detections in place that apply to multiple stages of this attack, including suspicious identity activity, cloud reconnaissance, and bulk data access and exfiltration. The threat actors do not encrypt or destroy data; their objective is purely data theft followed by financial extortion.

THREAT PROFILE:

Tactic Technique Id Technique Sub-technique
Initial access T1566.002 Phishing Spearphishing Link
Defence Evasion T1036.005 Masquerading Match Legitimate Resource Name or Location
Credential access T1555.003 Credentials from Password Stores Credentials from Web Browsers
Collection T1005 Data from Local System -
Command and control T1071.001 Application Layer Protocol Web Protocols
Exfiltration T1041 Exfiltration Over C2 Channel -

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu