Threat hunters have reported a new threat cluster actively targeting executive staff within organizations, leveraging social engineering and technical exploits to compromise Microsoft 365 and other SaaS platforms. The attacks involve fake IT help desk calls, a technique known as vishing, combined with adversary-in-the-middle (AitM) token theft and the use of residential proxies for illicit sign-ins. The primary targets identified are high-level personnel, including directors and vice presidents.
The attack chain typically begins with a vishing call to an executive, impersonating IT support. The goal of this initial social engineering phase is often to trick the victim into performing an action that facilitates the subsequent technical compromise. This could involve directing them to a malicious website or convincing them to provide authentication details under the guise of troubleshooting.
Following the social engineering component, the attackers employ adversary-in-the-middle (AitM) techniques to steal authentication tokens. AitM attacks intercept communication between a user and a legitimate service, allowing the attacker to capture session cookies or other tokens that prove a user's authenticated status. With a stolen token, the attacker can bypass multi-factor authentication (MFA) and gain unauthorized access to the victim's accounts without needing their password.
Once access is gained, the threat actors utilize residential proxies for sign-ins. Residential proxies route network traffic through legitimate residential IP addresses, making the malicious sign-in attempts appear to originate from a trusted or less suspicious location. This tactic helps attackers evade detection mechanisms that flag logins from unusual or known malicious IP ranges, making it harder for security teams to identify the compromise in real-time.
The ultimate objectives of this threat cluster are data theft and extortion. After gaining access to executive Microsoft 365 accounts, attackers can exfiltrate sensitive corporate data, including emails, documents, and other files stored within the SaaS environment. This stolen data is then likely used as leverage in extortion schemes, threatening public release or sale if a ransom is not paid.
Mitigation for such attacks typically involves a multi-layered approach. Organizations are advised to implement robust security awareness training, specifically educating employees, especially executives, about vishing tactics and the importance of verifying IT support requests through official channels. Technical controls should include strong multi-factor authentication (MFA) that is resistant to token theft, such as FIDO2-based security keys, and continuous monitoring of sign-in logs for anomalous activity, including the use of residential proxies or unusual access patterns. Endpoint detection and response (EDR) solutions can also help detect and prevent the execution of malicious scripts or access to phishing sites.
This incident highlights the evolving sophistication of threat actors who combine social engineering with advanced technical exploits to target high-value individuals within organizations. The focus on executives underscores the understanding that compromising such accounts can yield significant access to sensitive information and critical business operations, making them prime targets for data theft and extortion campaigns.






