INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Hackers Impersonate IT Help Desk to Bypass Multi-Factor Authentication
| 2026-09-05 18:11 CRITICAL HIGH PHISHING & SOCIAL ENGINEERING
Executive Summary
AI-generated
A widespread threat cluster tracked as PREY-0058 bypassed endpoint security entirely by targeting Microsoft 365 and SaaS environments through pure social engineering, with attackers posing as internal IT help desk staff via phone calls to direct executives toward rogue authentication portals. The attack worked by impersonating victims over the phone, intercepting credentials in real-time using adversary-in-the-middle panels, and replaying stolen session tokens from residential proxy networks that matched the victim's exact geographic location. As a result of this incident, at least several high-profile targets were affected, including executives such as Directors, Vice Presidents, and other executive staff. The current status is unclear, but it has been reported that attackers immediately shifted focus to massive data harvesting after bypassing endpoint security, draining sensitive files from OneDrive, Exchange, and Box before dropping a heavy extortion demand.
Technical Mitigations AI-generated
• Network Intrusion Prevention (ATT&CK mitigation for Phishing): Network intrusion prevention systems and systems designed to scan and remove malicious email attachments or links can be used to block activity.
• Restrict Web-Based Content (ATT&CK mitigation for Phishing): Determine if certain websites or attachment types (ex: .scr, .exe, .pif, .cpl, etc.) that can be used for phishing are necessary for business operations and consider bloc
• User Training (ATT&CK mitigation for Impersonation): Train users to be aware of impersonation tricks and how to counter them, for example confirming incoming requests through an independent platform like a phone call or in-
• Threat Intelligence Program (ATT&CK mitigation for Impersonation): Threat intelligence helps defenders and users be aware of and defend against common lures and active campaigns that have been used for impersonation.
• Audit (ATT&CK mitigation for Social Engineering): Enables correlation of email/identity/SaaS/endpoint activity that appears legitimate.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected
Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.
24ab9f••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
av•••••.com
he•••••.com
po•••••.com
pa•••••.com
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
ShinyHuntersShinyHunters
Target & Sectors
Global Scope
healthhealth
manufacturingmanufacturing
technologytechnology
Incident Timeline
Between January and April 2026
Threat actors, affiliated with the ShinyHunters / UNC6671 group, used a Spring Ring social engineering operation to impersonate IT help desk personnel via compromised Microsoft Teams accounts between January and April 2026.
Click on any entity below to view its context and source!
tactic
Social Engineering
Between January and April 2026, a coordinated social engineering operation named Spring Ring leveraged external Microsoft Teams accounts to impersonate IT help desk personnel, targeting over 150 employees across at least 10 companies.
tactic
Impersonate
Between January and April 2026, a coordinated social engineering operation named Spring Ring leveraged external Microsoft Teams accounts to impersonate IT help desk personnel, targeting over 150 employees across at least 10 companies.
victims
150 employees
Between January and April 2026, a coordinated social engineering operation named Spring Ring leveraged external Microsoft Teams accounts to impersonate IT help desk personnel, targeting over 150 employees across at least 10 companies.
general_metric
10 companies
Between January and April 2026, a coordinated social engineering operation named Spring Ring leveraged external Microsoft Teams accounts to impersonate IT help desk personnel, targeting over 150 employees across at least 10 companies.
2026/09/05
Threat actors used voice phishing to impersonate IT staff and trick victims into accessing authentication-themed URLs, often targeting Microsoft 365 environments.
Click on any entity below to view its context and source!
organisation
Bridewell BCON
Aggregated infrastructure from an ongoing Com-affiliated voice-phishing operation targeting enterprise identity providers, correlating public reporting from Unit 42, Google GTIG, Bridewell BCON and Okta.
organisation
BlackFile → Redact → Pink / Helix / Falcon
Extortion brands rotate (BlackFile → Redact → Pink / Helix / Falcon) while intrusion tradecraft stays constant, consistent with shared phishing kits and a rented Vishing-as-a-Service platform rather than a single group.
organisation
Microsoft Teams
An Inside Look at Voice Phishing Campaigns in Microsoft Teams.
organisation
MFA
Finally, watch for new phishing domains that imitate your organization and target passkey or MFA registration.
Operators call employees - often on personal mobiles - impersonating IT or help desk staff, citing an urgent ticket or a mandatory MFA/passkey migration.
organisation
AiTM
Use phishing-resistant MFA such as FIDO2 keys or device-bound passkeys, which can stop AiTM attacks.
organisation
OneDrive, Exchange
They map out repositories and drain sensitive files from OneDrive, Exchange, and Box before dropping a heavy extortion demand.
organisation
Microsoft 365
No malware or endpoint persistence is involved; the authenticated session itself is the beachhead, followed by programmatic data extraction from Microsoft 365, SharePoint, OneDrive, Okta, Salesforce and Snowflake.
A widespread threat cluster tracked as
PREY-0058
bypasses endpoint security entirely by targeting Microsoft 365 and SaaS environments through pure social engineering.
To detect these attacks, monitor Microsoft 365 sign-ins coming from residential proxies or hosting networks such as NodeMaven.
To reduce the risk, require managed devices for Microsoft 365 and block or challenge access from proxy and hosting networks.
organisation
SharePoint
No malware or endpoint persistence is involved; the authenticated session itself is the beachhead, followed by programmatic data extraction from Microsoft 365, SharePoint, OneDrive, Okta, Salesforce and Snowflake.
“After initial access, the threat actors perform discovery techniques against SharePoint and Entra ID.” continues the report.
organisation
OneDrive
No malware or endpoint persistence is involved; the authenticated session itself is the beachhead, followed by programmatic data extraction from Microsoft 365, SharePoint, OneDrive, Okta, Salesforce and Snowflake.
Also monitor heavy SharePoint and OneDrive file access or downloads from one user, particularly when scripting tools such as Python requests or Microsoft Graph are used.
organisation
Okta, Salesforce and Snowflake
No malware or endpoint persistence is involved; the authenticated session itself is the beachhead, followed by programmatic data extraction from Microsoft 365, SharePoint, OneDrive, Okta, Salesforce and Snowflake.
organisation
PREY-0058
A widespread threat cluster tracked as
PREY-0058
bypasses endpoint security entirely by targeting Microsoft 365 and SaaS environments through pure social engineering.
organisation
Entra ID
“After initial access, the threat actors perform discovery techniques against SharePoint and Entra ID.” continues the report.
organisation
Microsoft Graph
Also monitor heavy SharePoint and OneDrive file access or downloads from one user, particularly when scripting tools such as Python requests or Microsoft Graph are used.
organisation
Passkey-Themed AiTM Infrastructure
Com-Affiliated Vishing Ecosystem: .claims and Passkey-Themed AiTM Infrastructure (ShinyHunters / UNC6671).
threat_actor
ShinyHunters
Com-Affiliated Vishing Ecosystem: .claims and Passkey-Themed AiTM Infrastructure (ShinyHunters / UNC6671).
organisation
NTLM
In advanced variants, attackers transitioned from vishing to NTLM relay attacks targeting domain controllers.
organisation
RMM
Two distinct campaigns were observed: Campaign A utilized RMM tools and obfuscated PowerShell-based RATs, while Campaign B employed tailored cloud infrastructure with PetitPotam exploitation for domain-level compromise.
organisation
PetitPotam
Two distinct campaigns were observed: Campaign A utilized RMM tools and obfuscated PowerShell-based RATs, while Campaign B employed tailored cloud infrastructure with PetitPotam exploitation for domain-level compromise.
organisation
NodeMaven
“Stolen sessions are replayed from residential proxy infrastructure, most notably NodeMaven, often from IP addresses that resolve to the same geo-location and network (ASN) as the victim.”
organisation
IP
“Stolen sessions are replayed from residential proxy infrastructure, most notably NodeMaven, often from IP addresses that resolve to the same geo-location and network (ASN) as the victim.”
organisation
ASN
“Stolen sessions are replayed from residential proxy infrastructure, most notably NodeMaven, often from IP addresses that resolve to the same geo-location and network (ASN) as the victim.”
organisation
OfficeHome
Suspicious activity is more likely when several common Microsoft account pages are accessed at the start of a session, especially OfficeHome, My Signins, My Profile, My Apps and Microsoft Account Controls.
organisation
Microsoft Account Controls
Suspicious activity is more likely when several common Microsoft account pages are accessed at the start of a session, especially OfficeHome, My Signins, My Profile, My Apps and Microsoft Account Controls.
organisation
Alerts
Alerts should also consider changes from a user’s normal sign-in pattern, such as a different location, ISP, browser, operating system or user agent.
organisation
ISP
Alerts should also consider changes from a user’s normal sign-in pattern, such as a different location, ISP, browser, operating system or user agent.
organisation
Exchange
In Exchange, watch for large numbers of MailItemsAccessed events in a short time, especially when they come from hosting or proxy IPs.
organisation
Continuous Access Evaluation
Limit users’ access to sensitive SharePoint data, enable Continuous Access Evaluation, and train employees and help-desk teams to verify unexpected IT calls through a trusted channel.
organisation
SecurityAffairs
Follow me on Twitter:
@securityaffairs
and
Facebook
and
Mastodon
Pierluigi Paganini
(
SecurityAffairs
– hacking, IT Help Desk)
September 08, 2026
Attackers posing as IT staff bypassed endpoint security by stealing Microsoft 365 sessions and draining SaaS data, then demanded extortion.
Click on any entity below to view its context and source!
tactic
Extortion
IT Help Desk Impersonation Lets Hackers Bypass MFA
Pierluigi Paganini
September 08, 2026
Attackers bypass endpoint security by posing as IT staff, stealing Microsoft 365 sessions, draining SaaS data and demanding extortion.
infrastructure
Microsoft 365
IT Help Desk Impersonation Lets Hackers Bypass MFA
Pierluigi Paganini
September 08, 2026
Attackers bypass endpoint security by posing as IT staff, stealing Microsoft 365 sessions, draining SaaS data and demanding extortion.
general_metric
365 Microsoft
IT Help Desk Impersonation Lets Hackers Bypass MFA
Pierluigi Paganini
September 08, 2026
Attackers bypass endpoint security by posing as IT staff, stealing Microsoft 365 sessions, draining SaaS data and demanding extortion.
tactic
Impersonation
IT Help Desk Impersonation Lets Hackers Bypass MFA
Pierluigi Paganini
September 08, 2026
Attackers bypass endpoint security by posing as IT staff, stealing Microsoft 365 sessions, draining SaaS data and demanding extortion.
tactic
T1684.001 - Impersonation
IT Help Desk Impersonation Lets Hackers Bypass MFA
Pierluigi Paganini
September 08, 2026
Attackers bypass endpoint security by posing as IT staff, stealing Microsoft 365 sessions, draining SaaS data and demanding extortion.
organisation
Microsoft
IT Help Desk Impersonation Lets Hackers Bypass MFA
Pierluigi Paganini
September 08, 2026
Attackers bypass endpoint security by posing as IT staff, stealing Microsoft 365 sessions, draining SaaS data and demanding extortion.
2026/09/08
Threat actors affiliated with ShinyHunters and UNC6671 used phone-based vishing tactics to target individuals, claiming they had compromised access to their personal data.
Tactical Metrics
Metrics
infrastructure
Microsoft 365
Affected Product
Click for context!
No malware or endpoint persistence is involved; the authenticated session itself is the beachhead, followed by programmatic data extraction from Microsoft 365, SharePoint, OneDrive, Okta, Salesforce and Snowflake.
IT Help Desk Impersonation Lets Hackers Bypass MFA
Pierluigi Paganini
September 08, 2026
Attackers bypass endpoint security by posing as IT staff, stealing Microsoft 365 sessions, draining SaaS data and demanding extortion.
A widespread threat cluster tracked as
PREY-0058
bypasses endpoint security entirely by targeting Microsoft 365 and SaaS environments through pure social engineering.
To detect these attacks, monitor Microsoft 365 sign-ins coming from residential proxies or hosting networks such as NodeMaven.
To reduce the risk, require managed devices for Microsoft 365 and block or challenge access from proxy and hosting networks.
Metrics
victims
150
Employees
Between January and April 2026, a coordinated social engineering operation named Spring Ring leveraged external Microsoft Teams accounts to impersonate IT help desk personnel, targeting over 150 employees across at least 10 companies.
Intelligence Sources
Security Affairs
2026-09-08
IT Help Desk Impersonation Lets Hackers Bypass MFA
Security Affairs
AlienVault OTX
2026-09-05
AlienVault OTX
2026-08-31
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-06T11:40
Comprehensive Tactical Telemetry
Highly Correlated Entities
28x
organisation
Identified Entity
Bridewell BCON
entity
9x
industry
Targeted Sector
Finance
sector
5x
tactic
Cyber Operation Type
Phishing
tactic
4x
tactic
MITRE ATT&CK Technique
T1566 - Phishing
technique
3x
timeline
Temporal Reference
Between January and April 2026
date
Contextual Telemetry
Context Block
5 METRICS
infrastructure
Affected Product
Microsoft 365
software
general metric
Microsoft
365
microsoft
threat actor
APT Group
ShinyHunters
actor
victims
Employees
150
employees
general metric
Companies
10
companies
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.