UNC6671 Associated DLS Listings by Site | Image: Google Threat Intelligence Group
Threat actors are actively compromising executive accounts using highly targeted Microsoft 365 vishing attacks. The PREY-0058 extortion campaign bypasses traditional multi-factor authentication to steal sensitive cloud data.
At a Glance
| Category | Details |
|---|---|
| Actor/Group | PREY-0058 (Overlaps with UNC6671 / BlackFile) |
| Activity Type | IT impersonation (vishing), AiTM phishing, data extortion |
| Targets | Directors, executives, and IT staff |
| Scale | Rapid intrusion-to-extortion cycle, no data encryption |
| Jurisdiction | Tracked by private security intelligence firms |
| Source | Arctic Wolf Threat Intelligence |
Executive Summary
Hackers use phone calls to impersonate internal IT helpdesks. They trick executives into visiting fake login portals to capture their session tokens. Afterwards, the attackers exfiltrate massive volumes of cloud data before demanding financial ransoms.
How the Attacks Unfold
The intruders phone company executives directly. They claim an urgent security update requires a new passkey. The caller then directs the victim to an Adversary-in-the-Middle (AiTM) phishing site. These portals mimic legitimate internal domains.
According to the Arctic Wolf report, “If the target falls for the ploy, the attacker gains unauthorized access to Microsoft 365 and associated SaaS platforms without exploiting any software vulnerability.” The attackers then route their stolen sessions through static residential networks. Specifically, they utilize NodeMaven Proxy to mask their physical locations and bypass impossible-travel alerts.
Who Is Behind the Campaign
Arctic Wolf tracks this activity cluster as PREY-0058. Google Mandiant tracks a highly overlapping group known as UNC6671. Security analysts link these operations to multiple extortion brands, including BlackFile, Redact, Pink, and Helix.
The Impact of the Breaches
These hackers do not deploy malware or encrypt files. Instead, they focus entirely on data theft. Once inside, they harvest emails using the One Outlook Web Client application. Next, they execute wildcard searches across SharePoint and OneDrive repositories to download sensitive documents in bulk. Following the theft, the attackers email the victimized executives. They demand a ransom payment via TOX messaging and enforce a strict 72-hour deadline.
Defending Against Vishing
Organizations must close the gaps that enable these Microsoft 365 vishing attacks. Security teams should deploy phishing-resistant authentication, such as FIDO2 hardware keys. Furthermore, companies must implement strict helpdesk verification procedures. Employees should always hang up and dial a known internal number to verify IT requests.
Support Our Threat Intelligence
Find our threat intelligence and malware analysis helpful? Support our work today and unlock a 100% ad-free reading experience!