PREY-0058: Vishing-Driven Credential Theft Campaign Bypasses MFA to Exfiltrate Microsoft 365 Data for Extortion

❓What:
Arctic Wolf is tracking an active cluster (PREY-0058) using voice phishing to compromise Microsoft 365 and connected SaaS platforms — no software vulnerability involved
Actors impersonate IT/Helpdesk staff via phone calls or texts, directing victims — primarily Directors, VPs, and executives — to Adversary-in-the-Middle (AiTM) phishing pages
AiTM pages capture credentials and MFA tokens in real time, defeating standard MFA
Static residential proxy infrastructure (NodeMaven, seen in the majority of cases) is used to mimic legitimate login behavior and evade detection
Post-access, actors harvest Exchange mail via an abnormal API path, enumerate SharePoint/OneDrive with wildcard queries, then bulk-download files
Data is not encrypted or destroyed — the objective is theft and extortion, not disruption
Extortion demands are sent via TOX messaging within hours, with a 72-hour deadline and threats of public data exposure
Tradecraft overlaps with public reporting on UNC6671; multiple extortion "brand" names (BlackFile, Redact, Pink, Helix) are associated with the activity — the relationship between these brands and any single actor group is not confirmed
⚠️Impact:
Executive and IT-staff accounts can be fully compromised without triggering vulnerability-based detections, since MFA is bypassed via social engineering rather than exploit
Full-scope data exposure across Exchange Online, SharePoint, OneDrive, and Box is possible before security teams detect initial access
The intrusion-to-extortion timeline is compressed to hours, sharply narrowing the response window
Organizations face reputational and regulatory exposure from threatened public leaks of stolen data
💡Recommendations:
Roll out vishing-awareness training for executives, VPs, and IT staff — the groups this campaign specifically targets
Notify all employees that IT/Helpdesk will never cold-call or text asking to register passkeys or change authentication methods; establish a verified callback channel for any such request
Move high-risk and executive accounts to FIDO2 hardware keys or certificate-based auth to eliminate AiTM phishing risk entirely
Require sign-ins from managed/compliant devices via Conditional Access
Block sign-ins from known residential/anonymization proxy networks (e.g., NodeMaven) at the identity provider level
Apply least-privilege RBAC on SharePoint sites and libraries
Configure Purview DLP thresholds to flag or block high-volume single-session downloads
Full Bulletin:
