Arctic Wolf is tracking a widespread IT impersonation and voice-phishing cluster, PREY-0058. Threat actors target senior users through highly targeted social engineering by calling or texting victims to bypass MFA controls. If successful, attackers gain unauthorized access to Microsoft 365 and associated SaaS platforms without exploiting any software vulnerability. They then conduct rapid data exfiltration across email, file storage, and cloud document repositories. The threat actors use static residential proxy infrastructure, specifically NodeMaven Proxy, to blend into legitimate user activity and evade detection.
Once inside, they use the One Outlook Web Client App (AppID info 9199bf20-a13f-4107-85dc-02114787ef48) to retrieve mail from an abnormal API path (API ID c999ed3e-27ae-4cb3-b3a2-46b056af63d3). They then access SharePoint Online and execute broad queries via API to map accessible sites and subsites. This activity generates SearchQueryPerformed event logs. The actors also execute a wildcard query (*) to list all documents available in SharePoint and then paginate through the results.[/subscribe_to_unlock_form]
Arctic Wolf is tracking a widespread IT impersonation and voice-phishing cluster, PREY-0058. Threat actors target senior users through highly targeted social engineering by calling or texting victims to bypass MFA controls. If successful, attackers gain unauthorized access to Microsoft 365 and associated SaaS platforms without exploiting any software vulnerability. They then conduct rapid data exfiltration across email, file storage, and cloud document repositories. The threat actors use static residential proxy infrastructure, specifically NodeMaven Proxy, to blend into legitimate user activity and evade detection.
Once inside, they use the One Outlook Web Client App (AppID info 9199bf20-a13f-4107-85dc-02114787ef48) to retrieve mail from an abnormal API path (API ID c999ed3e-27ae-4cb3-b3a2-46b056af63d3). They then access SharePoint Online and execute broad queries via API to map accessible sites and subsites. This activity generates SearchQueryPerformed event logs. The actors also execute a wildcard query (*) to list all documents available in SharePoint and then paginate through the results.[emaillocker id="1283"]
The consistent use of static residential proxy infrastructure is intended to blend into legitimate user activity and evade detection. Arctic Wolf MDR Protection has detections in place that apply to multiple stages of this attack, including suspicious identity activity, cloud reconnaissance, and bulk data access and exfiltration. The threat actors do not encrypt or destroy data; their objective is purely data theft followed by financial extortion.
| Tactic | Technique Id | Technique | Sub-technique |
|---|---|---|---|
| Initial access | T1566.002 | Phishing | Spearphishing Link |
| Defence Evasion | T1036.005 | Masquerading | Match Legitimate Resource Name or Location |
| Credential access | T1555.003 | Credentials from Password Stores | Credentials from Web Browsers |
| Collection | T1005 | Data from Local System | - |
| Command and control | T1071.001 | Application Layer Protocol | Web Protocols |
| Exfiltration | T1041 | Exfiltration Over C2 Channel | - |
The following reports contain further technical details:
[/emaillocker]