Cybersecurity Threat Group PREY-0058 Targets U.S. Executives with Fake IT Calls for Data Theft and Extortion
A widespread data theft and extortion campaign, tracked as PREY-0058 by Arctic Wolf, is targeting executives in the U.S. across various sectors, including construction, engineering, healthcare, pharmaceuticals, real estate, property management, finance, and professional services. This threat cluster exploits Microsoft 365 and other software-as-a-service (SaaS) offerings through sophisticated vishing attacks. The attackers impersonate internal IT or help desk personnel, directing targets to fraudulent authentication URLs. These URLs facilitate adversary-in-the-middle (AitM) token theft, harvesting credentials and multi-factor authentication (MFA) approvals. The stolen authenticated session tokens are then used in session replay attacks, often originating from proxy infrastructure like NodeMaven, to gain unauthorized access. Once inside, the threat actors perform discovery techniques against SharePoint and Entra ID, followed by mass collection and exfiltration of data from SharePoint, OneDrive, Exchange, and...