This post is from a suggested group
PREY-0058: Vishing-Driven Credential Theft Campaign Bypasses MFA to Exfiltrate Microsoft 365 Data for Extortion

❓What:
Arctic Wolf is tracking an active cluster (PREY-0058) using voice phishing to compromise Microsoft 365 and connected SaaS platforms — no software vulnerability involved
Actors impersonate IT/Helpdesk staff via phone calls or texts, directing victims — primarily Directors, VPs, and executives — to Adversary-in-the-Middle (AiTM) phishing pages
AiTM pages capture credentials and MFA tokens in real time, defeating standard MFA
Static residential proxy infrastructure (NodeMaven, seen in the majority of cases) is used to mimic legitimate login behavior and evade detection







