Published: · Region: Global · Category: cyber

New PREY-0058 Campaign Uses Fake Help Desk Calls to Steal Microsoft 365 Cloud Sessions

Attackers behind the PREY-0058 campaign are combining voice phishing with lookalike login pages to hijack Microsoft 365 session tokens and then exfiltrate data from services including SharePoint, OneDrive, Exchange and Box.

A new attack campaign against Microsoft 365 users is turning help desk-style phone calls into a way to steal active cloud sessions and quietly drain corporate data.

The operation, tracked as PREY-0058, targets organizations that use Microsoft 365. According to a technical report, the attackers begin with vishing — voice phishing — by calling employees and posing as support staff. During the call, they direct the victim to a fake login page that closely mimics a legitimate Microsoft 365 or identity provider portal.

This page sits behind an adversary-in-the-middle setup: a proxy that intercepts everything the user types and everything the real service returns. When the victim enters their credentials and any additional verification codes, the proxy passes them through to Microsoft, completes the real login in the background, and captures the resulting session token.

Instead of logging in directly from obvious attacker infrastructure, PREY-0058 operators replay the stolen tokens through residential proxies. These are internet connections that resemble ordinary home or office users, making the malicious access harder to distinguish from normal traffic.

With valid tokens, the attackers can access a range of linked cloud services, including SharePoint, OneDrive, Exchange and Box, and exfiltrate stored files and email. The campaign has reportedly been used to steal data for extortion.

Because the attackers rely on hijacked sessions rather than brute-forcing passwords, traditional defenses can be slow to spot the intrusion. Organizations may not see clear warning signs until large volumes of data have already been accessed or downloaded.

In the near term, defenders will be watching how widely PREY-0058’s techniques spread, what changes Microsoft makes to session and token handling, and whether companies tighten internal processes to verify unexpected support calls before employees follow instructions or enter credentials.

Sources