The PREY-0058 threat cluster is targeting executives with voice-phishing calls impersonating internal IT help-desk staff. Operators direct victims to fraudulent Microsoft 365 authentication pages using adversary-in-the-middle phishing, capturing credentials, MFA approvals, and authenticated session tokens. They replay those tokens through residential proxies—frequently NodeMaven addresses selected to match the victim’s apparent geography and network profile—to bypass normal MFA protections.
After gaining access, the attackers enumerate Microsoft Entra ID and SharePoint and bulk-exfiltrate information from SharePoint, OneDrive, Exchange, and Box before issuing extortion demands. The activity overlaps with tradecraft attributed to UNC6671 and potentially Cinder or Pink-linked operations. Organizations should verify unexpected IT calls through trusted channels, require managed devices and phishing-resistant MFA such as FIDO2 keys or device-bound passkeys, restrict proxy-originated access, enable Continuous Access Evaluation, and monitor for token replay and anomalous bulk SaaS-data collection.

Get the infrastructure and lures behind it.
3 events from the most recent confirmed update back to the earliest known activity.
Arctic Wolf assessed that the PREY-0058 SaaS data-theft and extortion cluster has significant tradecraft similarities with the group Google Threat Intelligence Group tracks as UNC6671.
Arctic Wolf assessed with moderate confidence that the Cinder extortion brand is a rebrand or possible continuation of Pink operations, citing overlap between organizations listed on Cinder's leak site and victims linked to Pink-attributed phishing infrastructure. The report also associated PREY-0058 activity with BlackFile, Pink, Helix, Cinder, and Redact while cautioning that the labels do not prove a single actor identity.
Arctic Wolf reported that the PREY-0058 threat cluster impersonates IT help-desk staff in vishing calls, uses adversary-in-the-middle Microsoft 365 phishing to steal session tokens, and replays them through residential proxies. The cluster targets executives, collects data from Microsoft 365 services and Box, and issues extortion demands; Arctic Wolf also released indicators of compromise.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 14 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
6 references tracked. Mallory keeps watching after this page renders.
rhisac.org
Open sourcehelpnetsecurity.com
Open sourcesecurityaffairs.com
Open sourcethehackernews.com
Open sourcearcticwolf.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.