Arctic Wolf has linked PREY-0058 to a widespread data theft and extortion campaign that targets Microsoft 365 and other SaaS platforms using help desk vishing, AitM token theft, and residential-proxy sign-ins. The attackers focus on executives, then harvest data from SharePoint, OneDrive, Exchange, and Box before sending extortion demands, with overlaps suggesting ties to UNC6671 and possibly Cinder/Pink. #PREY0058 #UNC6671 #Cinder #Pink #Microsoft365 #SharePoint #OneDrive #Exchange #Box
Keypoints
- PREY-0058 targets Microsoft 365 and other SaaS services through vishing and AitM token theft.
- The campaign mainly singles out executives such as directors and vice presidents.
- Attackers use authentication-themed lure domains to steal credentials and MFA approvals.
- Captured session tokens are replayed through residential proxies to access victim accounts.
- Data is collected from SharePoint, OneDrive, Exchange, and Box before extortion demands are issued.
Read More: https://thehackernews.com/2026/09/microsoft-365-attackers-use-help-desk.html