Arctic Wolf Exposes Microsoft 365 Data Theft Campaign
A threat cluster tracked as PREY-0058 is using fake IT calls and proxy sign-ins to steal data from executives for extortion, according to Arctic Wolf.

Threat hunters at Arctic Wolf have detailed a widespread data theft and extortion campaign targeting Microsoft 365 and other SaaS platforms. The activity, tracked as PREY-0058, uses IT help desk vishing calls, adversary-in-the-middle token theft, and residential-proxy sign-ins to compromise executive accounts.
Arctic Wolf states the campaign shares significant tradecraft similarities with a data extortion group that Google-owned Mandiant calls UNC6671. The researchers also note that another data extortion actor known as Cinder likely represents a rebrand or continuation of the Pink group, citing overlaps in victim organizations listed on leak sites. Google has previously indicated that such evolving labels often correspond to an amorphous set of affiliates or groups using shared phishing infrastructure rather than a single proven actor.
Attack Chain Relies on Vishing
The attack chain begins with threat actors impersonating internal IT or help desk personnel in phone calls to directors, vice presidents, and other executives. The callers direct targets to an authentication-themed URL following a specific pattern: <victim organization>.<lure domain>. Arctic Wolf has flagged several of these lure domains.
These URLs lead to an operator-controlled adversary-in-the-middle Microsoft 365 login flow designed to harvest credentials and multi-factor authentication approvals. The goal is to obtain authenticated session tokens.
Token Replay and Discovery
The captured tokens are then used in session replay attacks originating from proxy infrastructure, such as NodeMaven, and from IP addresses that geographically match the victim's location. Researchers Steven Campbell, Trevor Daher, Stefan Hostetler, and Joshua Riccio said in their analysis, "Initial sign-in activity involves applications such as 'My Signins,' 'My Profile,' 'My Apps,' which reveal account details and the applications available to the victim."
After gaining initial access, the actors perform discovery techniques against SharePoint and Entra ID. SharePoint discovery includes SearchQueryPerformed events with queries for contentclass:STS_Site and contentclass:STS_Web, along with wildcard searches using indexdocid for pagination.
Data Exfiltration and Extortion
In the final step, the threat actors perform en masse collection and exfiltration from SharePoint, OneDrive, Exchange, and Box. Following data theft, extortion demands are sent to the victims. A notable aspect of PREY-0058 is the absence of endpoint malware deployment or traditional network-based lateral movement. Further analysis of the lure infrastructure has uncovered hundreds of subdomains impersonating real companies.
The campaign's targets are spread across the United States, primarily in sectors including construction and engineering, healthcare and pharmaceuticals, real estate and property management, finance, and professional services.
Recommended Defensive Controls
To counter this threat, Arctic Wolf advises organizations to implement several defensive measures. These include deploying Conditional Access policies and phishing-resistant multi-factor authentication. Organizations should also restrict the scope of data users can access in SharePoint and educate employees and help desk staff about vishing risks.
"Defenders can disrupt this activity by detecting anomalous residential-proxy token replay, SharePoint discovery and bulk access, mailbox harvesting, and newly registered authentication-themed lure infrastructure," the firm stated. The campaign shows the continued risk posed by sophisticated social engineering combined with token theft techniques against cloud services.





