PREY-0058: Sophisticated Vishing and AiTM Attacks Target Microsoft 365 Executives
A new threat cluster, dubbed **PREY-0058** by **Arctic Wolf**, is executing widespread data theft and extortion campaigns against **Microsoft 365** and other SaaS platforms. These attacks leverage a sophisticated combination of vishing, adversary-in-the-middle (AiTM) token theft, and residential-proxy sign-ins, primarily targeting executive-level personnel.
Threat hunters have uncovered details of a pervasive data theft and extortion threat cluster that is actively targeting **Microsoft 365** and other software-as-a-service (SaaS) offerings. The sophisticated campaign employs IT help desk vishing, adversary-in-the-middle (AiTM) token theft, and residential-proxy sign-ins to compromise victim accounts.
### Executive-Level Targets and Evolving Threat Actors
The activity, which predominantly singles out directors, vice presidents, and other executive staff, is being tracked by **Arctic Wolf** under the moniker **PREY-0058**. Researchers note significant tradecraft similarities with a data extortion group that **Google**-owned **Mandiant** calls **UNC6671**.
Further analysis suggests that the data extortion threat actor known as **Cinder** might represent another rebrand or a continuation of **Pink** operations, citing overlaps between organizations listed on the **Cinder** leak site and those connected to **Pink**. It's important to understand that these evolving labels do not necessarily correspond to a single, proven actor identity, but rather an amorphous set of affiliates, splinter crews, or groups utilizing the same underlying phishing infrastructure.
### Anatomy of the Attack Chain
Attack chains typically commence with threat actors impersonating internal IT or help desk personnel in phone calls. They direct prospective targets to an authentication-themed URL following the pattern: `<victim organization>.<lure domain>`. Some of the lure domains flagged by **Arctic Wolf** include:
* assignpasskey[.]com
* mfaregister[.]com
* nowsso[.]com
* oskeysetup[.]com
* oursso[.]com
* passkey-mfa[.]com
* passkeydeploy[.]com
* registermymfa[.]com
* setpasskey[.]com
These deceptive URLs lead to an operator-controlled AiTM **Microsoft 365** login flow, meticulously designed to harvest credentials and multi-factor authentication (MFA) approvals. This process allows the attackers to obtain authenticated session tokens. The captured tokens are subsequently leveraged in session replay attacks, originating from proxy infrastructure such as **NodeMaven**, and from IP addresses that resolve to the same geographical location and ASN as the victim.
### Post-Compromise Activities and Data Exfiltration
As researchers Steven Campbell, Trevor Daher, Stefan Hostetler, and Joshua Riccio detailed in their analysis, "Initial sign-in activity involves applications such as 'My Signins,' 'My Profile,' 'My Apps,' which reveal account details and the applications available to the victim." Following initial access, the threat actors perform discovery techniques against **SharePoint** and **Entra ID**. **SharePoint** discovery often includes `SearchQueryPerformed` events with `contentclass:STS_Site`, `contentclass:STS_Web`, and wildcard searches using `indexdocid` for pagination.
The final stage involves en masse collection and exfiltration of data from **SharePoint**, **OneDrive**, **Exchange**, and **Box**. Once data is stolen, extortion demands are sent to the victims.
### Distinctive Tradecraft and Geographic Reach
Notably, **PREY-0058** distinguishes itself by the absence of endpoint malware deployment or network-based lateral movement. Further analysis of subdomains across the lure infrastructure has revealed hundreds of entries impersonating legitimate companies.
The targets are primarily located across the U.S., spanning various sectors including construction and engineering, healthcare and pharmaceuticals, real estate and property management, finance, and professional services.
### Mitigating the Threat
To effectively counter this sophisticated threat, organizations are strongly advised to:
* Implement robust Conditional Access policies.
* Deploy phishing-resistant MFA solutions.
* Restrict the scope of data access for users within **SharePoint**.
* Educate employees and help desk staff comprehensively about the risks associated with vishing attacks.
**Arctic Wolf** emphasizes that "Defenders can disrupt this activity by detecting anomalous residential-proxy token replay, **SharePoint** discovery and bulk access, mailbox harvesting, and newly registered authentication-themed lure infrastructure."