Summary
- PREY-0058 targets senior employees through calls impersonating internal IT or help-desk staff.
- Attackers capture authenticated Microsoft 365 sessions and replay them through residential proxy infrastructure.
- The campaign can move from identity compromise into SaaS data collection and extortion without deploying conventional endpoint malware.
A data-theft and extortion campaign is using phone calls and stolen cloud sessions to reach Microsoft 365 and other SaaS data without relying on a conventional malware-led intrusion.
Arctic Wolf tracks the activity as PREY-0058. Researchers describe attackers calling directors, vice-presidents, and other senior employees while impersonating internal IT or help-desk personnel.
Targets are directed through an adversary-in-the-middle authentication flow designed to capture credentials, multi-factor authentication interaction, and the resulting Microsoft 365 session material. The attacker can then replay the authenticated session rather than attempting to log in again with a password alone.
Residential proxy infrastructure is used to make subsequent access appear closer to ordinary consumer traffic. Once inside an account, the operators enumerate applications and collect information from Microsoft 365 and other SaaS repositories including SharePoint, OneDrive, Exchange, and Box before moving towards extortion.
Arctic Wolf’s observed victim set has been concentrated in the United States and includes senior staff across construction, engineering, healthcare, pharmaceuticals, real estate, finance, and professional services. The underlying technique is not geographically constrained and relies on cloud services widely used by UK and European organisations.
The campaign shifts the useful detection surface away from a malicious executable. An endpoint may never receive ransomware, a remote-access trojan, or a bespoke payload. The attacker instead operates through an authenticated cloud identity and applications the user is already permitted to access.
That changes the evidence left behind. Identity telemetry, session behaviour, proxy characteristics, application access, unusual mailbox or document activity, and large-scale data collection can be more informative than endpoint malware alerts.
Cyber Insider reported this week on BigBear 2.0, another campaign targeting authenticated Microsoft 365 sessions. PREY-0058 differs in its reliance on live voice contact and the manipulation of senior employees during the authentication process.
Multi-factor authentication still blocks large volumes of credential-only compromise, but the control has different limitations where the legitimate user is persuaded to complete the authentication flow while an attacker sits in the middle. The target is not simply the password; it is the valid session created after the stronger authentication step succeeds.
Residential proxies make contextual detection harder. A sign-in originating from a consumer connection in a plausible location can create fewer obvious geographical indicators than access from a known hosting provider or overseas datacentre.
The research also identifies overlap in tradecraft with activity tracked elsewhere as UNC6671, while relationships between several extortion brands remain uncertain. Those similarities should not be converted into a firm attribution without stronger evidence.
From an operational perspective, the actor label is less important than the access path. The campaign demonstrates how an attacker can move from social engineering to an authorised cloud session and then directly into business data without first establishing a traditional foothold across the corporate network.
That compresses several stages normally associated with an intrusion. Once the session is compromised, the attacker may already have access to mail, shared files, and business applications through the same identity that the organisation trusts.
The resulting extortion model depends on cloud identity rather than ransomware deployment. Its success is measured by whether a stolen session can reach valuable data before identity controls, behavioural detections, or application monitoring recognise that the legitimate account is no longer being operated by its legitimate user.




