AUTO-UPDATED

IT Help Desk Impersonation Lets Hackers Bypass MFA

The threat cluster PREY-0058 is bypassing endpoint security by using social engineering and phone-based impersonation to steal Microsoft 365 credentials and session tokens from corporate executives.

Key Points

  • Attackers pose as internal IT help desk staff to direct victims toward rogue authentication portals designed to intercept multi-factor authentication.
  • The group uses residential proxy networks like NodeMaven to replay stolen session tokens from the victim's geographic location, effectively bypassing impossible travel alerts.
  • Once inside, intruders perform discovery on SharePoint and Entra ID to map sensitive repositories and exfiltrate data from OneDrive, Exchange, and Box.
  • Arctic Wolf researchers identified that these attacks specifically target high-level personnel, including Directors and Vice Presidents.
  • Security teams are advised to monitor for unusual SearchQueryPerformed events and block access from known proxy or hosting networks.

Why it Matters

These attacks demonstrate a shift toward human-centric exploitation that renders traditional endpoint security and standard multi-factor authentication ineffective. By bypassing technical safeguards, this method forces organizations to rethink their reliance on legacy authentication and prioritize phishing-resistant measures like FIDO2 keys.
Securityaffairs.com Published by Pierluigi Paganini
Read original