top of page

Security Bulletin

Public·5 members

Jake Geier
Jake Geier

PREY-0058: Vishing-Driven Credential Theft Campaign Bypasses MFA to Exfiltrate Microsoft 365 Data for Extortion


❓What:

  • Arctic Wolf is tracking an active cluster (PREY-0058) using voice phishing to compromise Microsoft 365 and connected SaaS platforms — no software vulnerability involved

  • Actors impersonate IT/Helpdesk staff via phone calls or texts, directing victims — primarily Directors, VPs, and executives — to Adversary-in-the-Middle (AiTM) phishing pages

  • AiTM pages capture credentials and MFA tokens in real time, defeating standard MFA

  • Static residential proxy infrastructure (NodeMaven, seen in the majority of cases) is used to mimic legitimate login behavior and evade detection

  • Post-access, actors harvest Exchange mail via an abnormal API path, enumerate SharePoint/OneDrive with wildcard queries, then bulk-download files

  • Data is not encrypted or destroyed — the objective is theft and extortion, not disruption

  • Extortion demands are sent via TOX messaging within hours, with a 72-hour deadline and threats of public data exposure

  • Tradecraft overlaps with public reporting on UNC6671; multiple extortion "brand" names (BlackFile, Redact, Pink, Helix) are associated with the activity — the relationship between these brands and any single actor group is not confirmed


⚠️Impact:

  • Executive and IT-staff accounts can be fully compromised without triggering vulnerability-based detections, since MFA is bypassed via social engineering rather than exploit

  • Full-scope data exposure across Exchange Online, SharePoint, OneDrive, and Box is possible before security teams detect initial access

  • The intrusion-to-extortion timeline is compressed to hours, sharply narrowing the response window

  • Organizations face reputational and regulatory exposure from threatened public leaks of stolen data


💡Recommendations:

  • Roll out vishing-awareness training for executives, VPs, and IT staff — the groups this campaign specifically targets

  • Notify all employees that IT/Helpdesk will never cold-call or text asking to register passkeys or change authentication methods; establish a verified callback channel for any such request

  • Move high-risk and executive accounts to FIDO2 hardware keys or certificate-based auth to eliminate AiTM phishing risk entirely

  • Require sign-ins from managed/compliant devices via Conditional Access

  • Block sign-ins from known residential/anonymization proxy networks (e.g., NodeMaven) at the identity provider level

  • Apply least-privilege RBAC on SharePoint sites and libraries

  • Configure Purview DLP thresholds to flag or block high-volume single-session downloads


Full Bulletin:


bottom of page