INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Hackers Impersonate IT Help Desk to Bypass Multi-Factor Authentication

| 2026-09-05 18:11 CRITICAL HIGH PHISHING & SOCIAL ENGINEERING
Executive Summary
AI-generated
A widespread threat cluster tracked as PREY-0058 bypassed endpoint security entirely by targeting Microsoft 365 and SaaS environments through pure social engineering, with attackers posing as internal IT help desk staff via phone calls to direct executives toward rogue authentication portals. The attack worked by impersonating victims over the phone, intercepting credentials in real-time using adversary-in-the-middle panels, and replaying stolen session tokens from residential proxy networks that matched the victim's exact geographic location. As a result of this incident, at least several high-profile targets were affected, including executives such as Directors, Vice Presidents, and other executive staff. The current status is unclear, but it has been reported that attackers immediately shifted focus to massive data harvesting after bypassing endpoint security, draining sensitive files from OneDrive, Exchange, and Box before dropping a heavy extortion demand.
Technical Mitigations AI-generated
• Network Intrusion Prevention (ATT&CK mitigation for Phishing): Network intrusion prevention systems and systems designed to scan and remove malicious email attachments or links can be used to block activity. • Restrict Web-Based Content (ATT&CK mitigation for Phishing): Determine if certain websites or attachment types (ex: .scr, .exe, .pif, .cpl, etc.) that can be used for phishing are necessary for business operations and consider bloc • User Training (ATT&CK mitigation for Impersonation): Train users to be aware of impersonation tricks and how to counter them, for example confirming incoming requests through an independent platform like a phone call or in- • Threat Intelligence Program (ATT&CK mitigation for Impersonation): Threat intelligence helps defenders and users be aware of and defend against common lures and active campaigns that have been used for impersonation. • Audit (ATT&CK mitigation for Social Engineering): Enables correlation of email/identity/SaaS/endpoint activity that appears legitimate.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected

Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.

24ab9f••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
av•••••.com
he•••••.com
po•••••.com
pa•••••.com
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
ShinyHuntersShinyHunters
Target & Sectors
Global Scope healthhealth manufacturingmanufacturing technologytechnology
Incident Timeline
‎Between January and April 2026
Threat actors, affiliated with the ShinyHunters / UNC6671 group, used a Spring Ring social engineering operation to impersonate IT help desk personnel via compromised Microsoft Teams accounts between January and April 2026.
tactic Social Engineering
tactic Impersonate
victims 150 employees
general_metric 10 companies
‎2026/09/05
Threat actors used voice phishing to impersonate IT staff and trick victims into accessing authentication-themed URLs, often targeting Microsoft 365 environments.
organisation Bridewell BCON
organisation BlackFile → Redact → Pink / Helix / Falcon
organisation Microsoft Teams
organisation MFA
organisation AiTM
organisation OneDrive, Exchange
organisation Microsoft 365
organisation SharePoint
organisation OneDrive
organisation Okta, Salesforce and Snowflake
organisation PREY-0058
organisation Entra ID
organisation Microsoft Graph
organisation Passkey-Themed AiTM Infrastructure
threat_actor ShinyHunters
organisation NTLM
organisation RMM
organisation PetitPotam
organisation NodeMaven
organisation IP
organisation ASN
organisation OfficeHome
organisation Microsoft Account Controls
organisation Alerts
organisation ISP
organisation Exchange
organisation Continuous Access Evaluation
organisation SecurityAffairs
‎September 08, 2026
Attackers posing as IT staff bypassed endpoint security by stealing Microsoft 365 sessions and draining SaaS data, then demanded extortion.
tactic Extortion
infrastructure Microsoft 365
general_metric 365 Microsoft
tactic Impersonation
tactic T1684.001 - Impersonation
organisation Microsoft
‎2026/09/08
Threat actors affiliated with ShinyHunters and UNC6671 used phone-based vishing tactics to target individuals, claiming they had compromised access to their personal data.
Tactical Metrics
Metrics
infrastructure
‎Microsoft 365
Affected Product
Metrics
victims
150
Employees