Threat Actor
PEAR
- First Reported
- Sep 24, 2026
- Latest Reported
- Sep 24, 2026
Reported Context (1)
- Named as an example of a threat actor group using phishing and vishing to gain M365 account access, followed by identity and token abuse for large-scale file exfiltration and extortion. Microsoft 365 File Retrieval May Appear as “FileAccessed,” Not “FileDownloaded”
Threat Actors (2)
MITRE ATT&CK (4)
Vendors (1)
Products (6)
Note: Related entities, including threat actors, malware, CVEs, MITRE ATT&CK techniques, vendors, products, tools, countries, and industries, are shown when they appear in the same reporting. Their presence does not necessarily mean they were targeted, compromised, vulnerable, responsible for the activity, or directly involved in the incident.