SECURITY·중요도 8·2026. 09. 07.·The Hacker News

Fake IT Calls Target Executives in Microsoft 365 Data Theft and Extortion Attacks

── KO ──────────────────

Microsoft 365를 목표로 하는 데이터 도용 및 강탈 공격에 대한 경고가 나왔다.

위협 사냥꾼들이 Microsoft 365와 기타 SaaS 제품을 노리는 광범위한 데이터 도난 및 extortion 공격 클러스터에 대한 정보를 공개했다. 공격에는 IT 헬프 데스크 vishing, 중간자 공격(AitM)으로 인한 토큰 도 theft, 주거용 프록시 로그인 등이 포함된다. 이 활동은 주로 이사, 부사장 및 기타 임원 직원을 목표로 한다.


── EN ──────────────────

Warning issued about data theft and extortion attacks targeting Microsoft 365.

Threat hunters have disclosed information about a widespread data theft and extortion attack cluster targeting Microsoft 365 and other SaaS products. The attacks involve IT help desk vishing, adversary-in-the-middle (AitM) token theft, and residential-proxy sign-ins. This activity primarily targets directors, vice presidents, and other executive staff.

원문 보기 →목록으로