Executive Summary

Arctic Wolf identified PREY-0058, a widespread data theft and extortion campaign targeting Microsoft 365 and SaaS platforms through sophisticated vishing attacks. The threat actors impersonate IT help desk personnel, directing executives to fraudulent authentication pages that harvest credentials and MFA tokens via adversary-in-the-middle techniques. Using residential proxy infrastructure like NodeMaven, attackers perform session replay attacks to access SharePoint, OneDrive, Exchange, and Box for mass data exfiltration before issuing extortion demands. The campaign primarily targets directors and executives across construction, healthcare, finance, and professional services sectors.

This incident highlights the growing sophistication of identity-based attacks that bypass traditional security controls. As organizations increasingly rely on cloud services and remote access, vishing campaigns exploiting human factors and legitimate authentication flows represent a critical threat vector requiring enhanced user education and phishing-resistant authentication measures.

Why This Matters Now

The PREY-0058 campaign demonstrates how threat actors are evolving beyond malware to exploit human psychology and cloud authentication systems, making traditional endpoint security insufficient against modern identity-focused attacks targeting executive leadership.

Attack Path Analysis

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

The attackers use adversary-in-the-middle techniques to intercept and replay legitimate MFA tokens in real-time, allowing them to maintain authenticated sessions even with MFA enabled.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.

Aviatrix Zero Trust CNSF would likely constrain this Microsoft 365 compromise by limiting lateral movement and reducing the blast radius of authenticated session abuse through workload segmentation and controlled egress enforcement.

Initial Compromise

Control: Cloud Native Security Fabric (CNSF)

Mitigation: Zero trust network controls would likely limit unauthorized session establishment and reduce the scope of initial authenticated access to Microsoft 365 services through identity-aware routing policies

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: Segmentation policies would likely constrain session replay effectiveness by limiting cross-service access and reducing the privilege scope available to replayed authentication tokens across Microsoft 365 workloads

Lateral Movement

Control: East-West Traffic Security

Mitigation: East-west traffic controls would likely restrict cross-application enumeration and limit the attacker's ability to discover available services and expand access across the Microsoft 365 tenant environment

Command & Control

Control: Multicloud Visibility & Control

Mitigation: Visibility and control mechanisms would likely detect and constrain systematic enumeration activities across SharePoint and Entra ID, reducing the scope of data discovery through monitoring and policy enforcement

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Egress controls would likely constrain mass data extraction by limiting outbound data flows and reducing the volume of information that could be transferred from Microsoft 365 services through policy-based restrictions

Impact (Mitigations)

While extortion demands would likely still occur, the constrained data access and reduced exfiltration scope from prior CNSF controls would limit the volume and sensitivity of compromised information available for leverage

Impact at a Glance

Affected Business Functions

  • Email Communication Systems
  • Document Management and Collaboration
  • Executive Decision Making
  • Confidential Business Operations
Operational Disruption

Estimated downtime: N/A

Financial Impact

Estimated loss: N/A

Data Exposure

Comprehensive data theft from Microsoft 365 environments including SharePoint documents, OneDrive files, Exchange emails, and Box storage. Primary targets are executives and senior staff across construction, healthcare, pharmaceuticals, real estate, finance, and professional services sectors. Stolen data is used for extortion demands.

Recommended Actions

  • Deploy Zero Trust Segmentation with identity-based policies to limit SharePoint and Exchange access scope, preventing mass data enumeration even with compromised credentials
  • Implement Egress Security & Policy Enforcement to detect and block bulk data transfers from Microsoft 365 services to unauthorized external destinations
  • Enable Multicloud Visibility & Control to identify anomalous residential proxy authentication patterns and repeated bulk access to cloud resources
  • Deploy Threat Detection & Anomaly Response capabilities to baseline normal user behavior and alert on suspicious bulk SharePoint discovery and mailbox harvesting activities
  • Strengthen Encrypted Traffic controls and session monitoring to detect token replay attacks and enforce geographic and behavioral authentication policies

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image