A widespread data theft and extortion threat cluster targeting Microsoft 365 and other software-as-a-service (SaaS) offerings through information technology (IT) help desk vishing, adversary-in-the-middle (AitM) token theft, and residential-proxy sign-ins. The activity mainly singles out directors, vice presidents, and other executive staff. It's being tracked by Arctic Wolf under the moniker PREY-0058 and shares significant tradecraft similarities with a data extortion group called UNC6671. The attack chains begin with threat actors impersonating internal IT or help desk personnel in phone calls and directing prospective targets to an authentication-themed URL that follows the pattern: <victim organization>.<lure domain>.
The captured tokens are subsequently leveraged in session replay attacks originating from proxy infrastructure, such as NodeMaven. After initial access, the threat actors perform discovery techniques against SharePoint and Entra ID, including SearchQueryPerformed events with contentclass:STS_Site, contentclass:STS_Web, and wildcard searches using indexdocid for pagination. The final step involves en masse collection and exfiltration from SharePoint, OneDrive, Exchange, and Box.[/subscribe_to_unlock_form]
A widespread data theft and extortion threat cluster targeting Microsoft 365 and other software-as-a-service (SaaS) offerings through information technology (IT) help desk vishing, adversary-in-the-middle (AitM) token theft, and residential-proxy sign-ins. The activity mainly singles out directors, vice presidents, and other executive staff. It's being tracked by Arctic Wolf under the moniker PREY-0058 and shares significant tradecraft similarities with a data extortion group called UNC6671. The attack chains begin with threat actors impersonating internal IT or help desk personnel in phone calls and directing prospective targets to an authentication-themed URL that follows the pattern: <victim organization>.<lure domain>.
The captured tokens are subsequently leveraged in session replay attacks originating from proxy infrastructure, such as NodeMaven. After initial access, the threat actors perform discovery techniques against SharePoint and Entra ID, including SearchQueryPerformed events with contentclass:STS_Site, contentclass:STS_Web, and wildcard searches using indexdocid for pagination. The final step involves en masse collection and exfiltration from SharePoint, OneDrive, Exchange, and Box.[emaillocker id="1283"]
The targets are spread across the U.S., primarily in construction and engineering, healthcare and pharmaceuticals, real estate and property management, finance, and professional services. To counter the threat, organizations are advised to implement Conditional Access policies, deploy phishing-resistant MFA, restrict the scope of data that users have access to in SharePoint, and educate employees and help desk staff about vishing risks.
| Tactic | Technique Id | Technique | Sub-technique |
|---|---|---|---|
| Initial access | T1566.002 | Phishing | Spearphishing Link |
| Credential access | T1555.003 | Credentials from Password Stores | Credentials from Web Browsers |
| Discovery | T1083 | File and Directory Discovery | - |
| Collection | T1005 | Data from Local System | - |
| Exfiltration | T1567.002 | Exfiltration Over Web Service | Exfiltration to Cloud Storage |
The following reports contain further technical details:
[/emaillocker]