INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
IOC - Cloud Data Theft via IT Help Desk Vishing
| 2026-09-09 02:06 MEDIUM HIGH RANSOMWARE & EXTORTION DATA BREACH PHISHING & SOCIAL ENGINEERING
Executive Summary
AI-generated
On September 9, 2026, a cloud data theft and extortion incident was reported, where attackers used IT help desk vishing and residential proxies to target Microsoft 365 users. The attack is believed to be associated with self-named extortion brands including BlackFile, Pink, Helix, Cinder, and Redact, which may represent affiliates or changing brands rather than a single actor identity. The incident has affected an unknown number of executives at Microsoft 365, primarily directors, vice presidents, and other high-level staff members. Attackers impersonated internal IT personnel via phone calls to direct targets to authentication-themed URLs that harvested credentials and multi-factor authentication approvals, which were then used in session replay attacks originating from proxy infrastructure such as NodeMaven. The current status of the incident is unclear, but it has been tracked by Arctic Wolf under PREY-0058 and shares similarities with other reported threats, including GTIG's UNC6671 reporting and public reports by ReliaQuest, Unit 42, Okta, and CrowdStrike.
Technical Mitigations AI-generated
• Use Conditional Access policies to restrict access to sensitive data and applications.
• Block or hunt for lure domains such as <a href="/auth/login?next=/detail/tveMf6ABGvYhsJJTnBwD" class="ioc-censored-pill text-decoration-none" title="Protected IoC: Sign in to view" data-bs-toggle="tooltip"><span class="badge bg-black text-warning border border-warning border-opacity-75 font-monospace ioc-lock-tag align-middle"><i class="bi bi-lock-fill me-1"></i>[IOC HIDDEN • LOGIN REQUIRED]</span></a>, <a href="/auth/login?next=/detail/tveMf6ABGvYhsJJTnBwD" class="ioc-censored-pill text-decoration-none" title="Protected IoC: Sign in to view" data-bs-toggle="tooltip"><span class="badge bg-black text-warning border border-warning border-opacity-75 font-monospace ioc-lock-tag align-middle"><i class="bi bi-lock-fill me-1"></i>[IOC HIDDEN • LOGIN REQUIRED]</span></a>, <a href="/auth/login?next=/detail/tveMf6ABGvYhsJJTnBwD" class="ioc-censored-pill text-decoration-none" title="Protected IoC: Sign in to view" data-bs-toggle="tooltip"><span class="badge bg-black text-warning border border-warning border-opacity-75 font-monospace ioc-lock-tag align-middle"><i class="bi bi-lock-fill me-1"></i>[IOC HIDDEN • LOGIN REQUIRED]</span></a>, <a href="/auth/login?next=/detail/tveMf6ABGvYhsJJTnBwD" class="ioc-censored-pill text-decoration-none" title="Protected IoC: Sign in to view" data-bs-toggle="tooltip"><span class="badge bg-black text-warning border border-warning border-opacity-75 font-monospace ioc-lock-tag align-middle"><i class="bi bi-lock-fill me-1"></i>[IOC HIDDEN • LOGIN REQUIRED]</span></a>, <a href="/auth/login?next=/detail/tveMf6ABGvYhsJJTnBwD" class="ioc-censored-pill text-decoration-none" title="Protected IoC: Sign in to view" data-bs-toggle="tooltip"><span class="badge bg-black text-warning border border-warning border-opacity-75 font-monospace ioc-lock-tag align-middle"><i class="bi bi-lock-fill me-1"></i>[IOC HIDDEN • LOGIN REQUIRED]</span></a>, <a href="/auth/login?next=/detail/tveMf6ABGvYhsJJTnBwD" class="ioc-censored-pill text-decoration-none" title="Protected IoC: Sign in to view" data-bs-toggle="tooltip"><span class="badge bg-black text-warning border border-warning border-opacity-75 font-monospace ioc-lock-tag align-middle"><i class="bi bi-lock-fill me-1"></i>[IOC HIDDEN • LOGIN REQUIRED]</span></a>, <a href="/auth/login?next=/detail/tveMf6ABGvYhsJJTnBwD" class="ioc-censored-pill text-decoration-none" title="Protected IoC: Sign in to view" data-bs-toggle="tooltip"><span class="badge bg-black text-warning border border-warning border-opacity-75 font-monospace ioc-lock-tag align-middle"><i class="bi bi-lock-fill me-1"></i>[IOC HIDDEN • LOGIN REQUIRED]</span></a>, <a href="/auth/login?next=/detail/tveMf6ABGvYhsJJTnBwD" class="ioc-censored-pill text-decoration-none" title="Protected IoC: Sign in to view" data-bs-toggle="tooltip"><span class="badge bg-black text-warning border border-warning border-opacity-75 font-monospace ioc-lock-tag align-middle"><i class="bi bi-lock-fill me-1"></i>[IOC HIDDEN • LOGIN REQUIRED]</span></a>, <a href="/auth/login?next=/detail/tveMf6ABGvYhsJJTnBwD" class="ioc-censored-pill text-decoration-none" title="Protected IoC: Sign in to view" data-bs-toggle="tooltip"><span class="badge bg-black text-warning border border-warning border-opacity-75 font-monospace ioc-lock-tag align-middle"><i class="bi bi-lock-fill me-1"></i>[IOC HIDDEN • LOGIN REQUIRED]</span></a>.
• Detect and prevent session replay attacks originating from proxy infrastructure such as NodeMaven.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected
Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.
ou•••••.com
mf•••••.com
no•••••.com
os•••••.com
hxxp://••••••••••••••••••••
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Target & Sectors
Global Scope
technologytechnology
Incident Timeline
2026/08/08
Threat actors used phishing infrastructure to target victims via IT help desk vishing and residential proxies on August 8, 2026.
Click on any entity below to view its context and source!
tactic
Phishing
It's worth noting that the ever-evolving labels do not correspond to a single proven actor identity, but rather an amorphous set of affiliates, splinter crews, or groups using the same underlying phishing infrastructure, as indicated by Google early last month.
Sep 07, 2026
Threat actors used IT help desk vishing tactics via residential proxies to target cloud data theft and extortion.
2026/09/09
Threat actors used IT help desk vishing and residential proxies to target Microsoft 365 users, primarily executives in various industries.
Click on any entity below to view its context and source!
organisation
IOC - Cloud Data Theft and Extortion
IOC - Cloud Data Theft and Extortion via IT Help Desk Vishing and Residential Proxies.
organisation
Residential Proxies
IOC - Cloud Data Theft and Extortion via IT Help Desk Vishing and Residential Proxies.
organisation
BlackFile
The cluster has been associated with self-named extortion brands including BlackFile, Pink, Helix, Cinder, and Redact.
organisation
Redact
The cluster has been associated with self-named extortion brands including BlackFile, Pink, Helix, Cinder, and Redact.
organisation
Microsoft 365
Ravie Lakshmanan
Sep 07, 2026
Phishing / Identity Security
Threat hunters have disclosed details of a widespread data theft and extortion threat cluster that's targeting Microsoft 365 and other software-as-a-service (SaaS) offerings through information technology (IT) help desk vishing, adversary-in-the-middle (AitM) token theft, and residential-proxy sign-ins.
Fake IT Calls Target Executives in Microsoft 365 Data Theft and Extortion Attacks.
…below -
assignpasskey[.]com
mfaregister[.]com
nowsso[.]com
oskeysetup[.]com
oursso[.]com
passkey-mfa[.]com
passkeydeploy[.]com
registermymfa[.]com
setpasskey[.]com
The attacks lead to an operator-controlled AitM Microsoft 365 login flow that's designed to harvest credentials and multi-factor authentication (MFA) approvals to obtain access to authenticated session tokens.
organisation
Microsoft 365 Data Theft and Extortion Attacks
Fake IT Calls Target Executives in Microsoft 365 Data Theft and Extortion Attacks.
organisation
Google
The activity, which mainly singles out directors, vice presidents, and other executive staff, is being
tracked
by Arctic Wolf under the moniker
PREY-0058
, adding it shares significant tradecraft similarities with a data extortion group that Google-owned Mandiant calls
UNC6671
.
organisation
Mandiant
The activity, which mainly singles out directors, vice presidents, and other executive staff, is being
tracked
by Arctic Wolf under the moniker
PREY-0058
, adding it shares significant tradecraft similarities with a data extortion group that Google-owned Mandiant calls
UNC6671
.
organisation
Cinder
It also said that the data extortion threat actor known as Cinder likely represents yet another rebrand or a possible continuation of Pink operations, citing overlaps between organizations listed on the Cinder leak site and those connected to Pink.
organisation
OneDrive
"
In the final step, the threat actors perform en masse collection and exfiltration from SharePoint, OneDrive, Exchange, and Box, after which extortion demands are sent to victims.
organisation
Exchange
"
In the final step, the threat actors perform en masse collection and exfiltration from SharePoint, OneDrive, Exchange, and Box, after which extortion demands are sent to victims.
organisation
PREY-0058
Arctic Wolf tracks this activity as PREY-0058.
What's notable about PREY-0058 is the absence of endpoint malware deployment or network-based lateral movement.
organisation
GTIG
It has substantial behavioral overlap with GTIG's UNC6671 reporting and public reporting by ReliaQuest, Unit 42, Okta, and CrowdStrike.
organisation
ReliaQuest
It has substantial behavioral overlap with GTIG's UNC6671 reporting and public reporting by ReliaQuest, Unit 42, Okta, and CrowdStrike.
organisation
CrowdStrike
It has substantial behavioral overlap with GTIG's UNC6671 reporting and public reporting by ReliaQuest, Unit 42, Okta, and CrowdStrike.
organisation
Conditional Access
To counter the threat, organizations are advised to implement Conditional Access policies, deploy phishing-resistant MFA, restrict the scope of data that users have access to in SharePoint, and educate employees and help desk staff about vishing risks.
organisation
Microsoft
…below -
assignpasskey[.]com
mfaregister[.]com
nowsso[.]com
oskeysetup[.]com
oursso[.]com
passkey-mfa[.]com
passkeydeploy[.]com
registermymfa[.]com
setpasskey[.]com
The attacks lead to an operator-controlled AitM Microsoft 365 login flow that's designed to harvest credentials and multi-factor authentication (MFA) approvals to obtain access to authenticated session tokens.
organisation
assignpasskey[.]com
Some of the lure domains flagged by Arctic Wolf are listed below -
assignpasskey[.]com
mfaregister[.]com
nowsso[.]com
oskeysetup[.]com
oursso[.]com
passkey-mfa[.]com
passkeydeploy[.]com
registermymfa[.]com
setpasskey[.]com
The attacks lead to an operator-controlled AitM Microsoft 365 login flow that's designed to harvest credentials and multi-factor authentication (MFA) a…
organisation
mfaregister[.]com
Some of the lure domains flagged by Arctic Wolf are listed below -
assignpasskey[.]com
mfaregister[.]com
nowsso[.]com
oskeysetup[.]com
oursso[.]com
passkey-mfa[.]com
passkeydeploy[.]com
registermymfa[.]com
setpasskey[.]com
The attacks lead to an operator-controlled AitM Microsoft 365 login flow that's designed to harvest credentials and multi-factor authentication (MFA) a…
organisation
oskeysetup[.]com
Some of the lure domains flagged by Arctic Wolf are listed below -
assignpasskey[.]com
mfaregister[.]com
nowsso[.]com
oskeysetup[.]com
oursso[.]com
passkey-mfa[.]com
passkeydeploy[.]com
registermymfa[.]com
setpasskey[.]com
The attacks lead to an operator-controlled AitM Microsoft 365 login flow that's designed to harvest credentials and multi-factor authentication (MFA) a…
organisation
oursso[.]com
Some of the lure domains flagged by Arctic Wolf are listed below -
assignpasskey[.]com
mfaregister[.]com
nowsso[.]com
oskeysetup[.]com
oursso[.]com
passkey-mfa[.]com
passkeydeploy[.]com
registermymfa[.]com
setpasskey[.]com
The attacks lead to an operator-controlled AitM Microsoft 365 login flow that's designed to harvest credentials and multi-factor authentication (MFA) a…
organisation
passkeydeploy[.]com
Some of the lure domains flagged by Arctic Wolf are listed below -
assignpasskey[.]com
mfaregister[.]com
nowsso[.]com
oskeysetup[.]com
oursso[.]com
passkey-mfa[.]com
passkeydeploy[.]com
registermymfa[.]com
setpasskey[.]com
The attacks lead to an operator-controlled AitM Microsoft 365 login flow that's designed to harvest credentials and multi-factor authentication (MFA) a…
organisation
MFA
Some of the lure domains flagged by Arctic Wolf are listed below -
assignpasskey[.]com
mfaregister[.]com
nowsso[.]com
oskeysetup[.]com
oursso[.]com
passkey-mfa[.]com
passkeydeploy[.]com
registermymfa[.]com
setpasskey[.]com
The attacks lead to an operator-controlled AitM Microsoft 365 login flow that's designed to harvest credentials and multi-factor authentication (MFA) a…
organisation
NodeMaven
The captured tokens are subsequently leveraged in session replay attacks originating from proxy infrastructure, such as NodeMaven, and from IP addresses that resolve to the same geographical location and ASN as the victim.
organisation
IP
The captured tokens are subsequently leveraged in session replay attacks originating from proxy infrastructure, such as NodeMaven, and from IP addresses that resolve to the same geographical location and ASN as the victim.
organisation
ASN
The captured tokens are subsequently leveraged in session replay attacks originating from proxy infrastructure, such as NodeMaven, and from IP addresses that resolve to the same geographical location and ASN as the victim.
organisation
SharePoint
"After initial access, the threat actors perform discovery techniques against SharePoint and Entra ID.
organisation
Entra ID
"After initial access, the threat actors perform discovery techniques against SharePoint and Entra ID.
Tactical Metrics
Metrics
infrastructure
Microsoft 365
Affected Product
Click for context!
Ravie Lakshmanan
Sep 07, 2026
Phishing / Identity Security
Threat hunters have disclosed details of a widespread data theft and extortion threat cluster that's targeting Microsoft 365 and other software-as-a-service (SaaS) offerings through information technology (IT) help desk vishing, adversary-in-the-middle (AitM) token theft, and residential-proxy sign-ins.
Fake IT Calls Target Executives in Microsoft 365 Data Theft and Extortion Attacks.
…below -
assignpasskey[.]com
mfaregister[.]com
nowsso[.]com
oskeysetup[.]com
oursso[.]com
passkey-mfa[.]com
passkeydeploy[.]com
registermymfa[.]com
setpasskey[.]com
The attacks lead to an operator-controlled AitM Microsoft 365 login flow that's designed to harvest credentials and multi-factor authentication (MFA) approvals to obtain access to authenticated session tokens.
Intelligence Sources
The Hacker News
2026-09-07
AlienVault OTX
2026-09-09
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-09T06:28
Comprehensive Tactical Telemetry
Highly Correlated Entities
28x
organisation
Identified Entity
IOC - Cloud Data Theft and Extortion
entity
4x
tactic
Cyber Operation Type
Extortion
tactic
3x
industry
Targeted Sector
Technology
sector
2x
timeline
Temporal Reference
2026/08/08
date
Contextual Telemetry
Context Block
5 METRICS
infrastructure
Affected Product
Microsoft 365
software
tactic
MITRE ATT&CK Technique
T1566 - Phishing
technique
general metric
Sep
7
sep
general metric
Ravie Lakshmanan
2,026
ravie lakshmanan
general metric
Microsoft
365
microsoft
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.