AI News Feed
Market watch
Cybersecurity

Microsoft 365 users hit by phishing campaigns impersonating IT support

Researchers warn of ongoing phishing campaigns impersonating IT support to steal Microsoft 365 credentials and bypass MFA.

CloudSEK said some groups are using BigBear 2.0, a new phishing-as-a-service framework that lets criminals intercept passwords and authenticated session cookies. Arctic Wolf separately described a threat actor it calls PREY-0058, saying the group is not a rebrand of older organizations. The firm believes affiliates, splinter crews, and other cohorts are sharing the same phishing infrastructure, blurring the lines between groups.

The attack method is similar across campaigns. Attackers call victims, approach them through Microsoft Teams, or send email, introducing themselves as members of the IT help desk there to resolve a specific issue. They then persuade the victim to grant remote access or to enter credentials on a spoofed Microsoft 365 login page. The fake site, built with BigBear 2.0 or a comparable tool, sits behind an attacker-in-the-middle proxy between the victim and legitimate Microsoft infrastructure. That proxy harvests passwords, MFA codes, and session cookies, and replays them through an API to hijack a legitimate authentication session.

Once access is obtained, the attackers mainly focus on exfiltrating sensitive data from Outlook, Teams, SharePoint, and OneDrive; ransomware deployment is rarely seen, the researchers said.

CloudSEK said BigBear 2.0 had been used to exfiltrate more than 5,000 credential records, including 474 complete MFA-bypassed authentications, 1,032 plaintext passwords, and 4,148 session cookies. Those records affected 3,331 unique victim IPs across 40-plus countries, and the operation was still active at the time of writing. The multi-user PhaaS panel is leased to at least five affiliate operators identified through live Telegram exfiltration bots, each receiving stolen credentials in real time, CloudSEK said. Speaking to BleepingComputer, CloudSEK said the campaign targeted 461 organizations, 258 of which had at least one set of credentials compromised.

Arctic Wolf's researchers said the attackers are primarily focused on US-based businesses in construction and engineering, healthcare and pharmaceuticals, real estate and property management, finance, and professional services, The Hacker News reported. They advise organizations to implement conditional access policies, deploy phishing-resistant MFA, and restrict the scope of data users can access through SharePoint. Employee education about phishing remains essential.

"Defenders can disrupt this activity by detecting anomalous residential-proxy token replay, SharePoint discovery and bulk access, mailbox harvesting, and newly registered authentication-themed lure infrastructure," Arctic Wolf said. Phishing-resistant MFA methods, including passkeys, YubiKeys, and FIDO2/WebAuthn authentication, cryptographically tie authentication to the legitimate site, making it impossible for the authentication to simply be forwarded to an attacker.