Active Cloud Data Theft and Extortion Campaign Targeting Microsoft 365 and SaaS Platforms
A widespread IT impersonation and voice-phishing campaign designated PREY-0058 is actively targeting Microsoft 365 and SaaS platforms. Threat actors impersonate IT helpdesk staff via phone or text to trick executives and senior personnel into divulging credentials through adversary-in-the-middle phishing portals. After bypassing multi-factor authentication, attackers conduct rapid automated data exfiltration across email, file storage, and cloud repositories without deploying ransomware. The operation relies heavily on NodeMaven residential proxy infrastructure to blend with legitimate traffic. Extortion demands are delivered via TOX messaging within hours of compromise, typically with 72-hour deadlines and threats of public data exposure. The campaign exhibits tradecraft overlapping with UNC6671 and involves multiple extortionware brands including BlackFile, Redact, Pink, and Helix.
AI Analysis
Technical Summary
PREY-0058 is a widespread social engineering and extortion campaign targeting Microsoft 365 and SaaS platforms. It employs IT helpdesk impersonation via phone and text (vishing) to deceive high-level personnel into divulging credentials through adversary-in-the-middle phishing portals. This enables attackers to bypass multi-factor authentication controls. Following credential compromise, the threat actors perform rapid automated data exfiltration across cloud email, file storage, and other repositories without deploying ransomware payloads. The campaign leverages NodeMaven residential proxy infrastructure to evade detection by blending with legitimate traffic. Extortion demands are delivered via TOX messaging within hours, typically imposing 72-hour deadlines and threatening public data exposure. The campaign's tactics overlap with those of UNC6671 and utilize multiple extortionware brands including BlackFile, Redact, Pink, and Helix.
Potential Impact
Successful attacks result in credential theft including bypass of multi-factor authentication, leading to rapid exfiltration of sensitive data from Microsoft 365 and SaaS cloud environments. The campaign does not deploy ransomware but instead uses stolen data for extortion, threatening public exposure. The use of residential proxies complicates detection and attribution. The impact includes potential significant data loss, reputational damage, and financial extortion pressure on targeted organizations.
Mitigation Recommendations
No official patch or fix applies as this is a social engineering and credential theft campaign rather than a software vulnerability. Organizations should enhance user awareness training focused on vishing and IT impersonation tactics, implement strong verification procedures for helpdesk communications, and monitor for suspicious login activity. Multi-factor authentication should be complemented with additional controls resistant to phishing and adversary-in-the-middle attacks. Review and restrict use of residential proxy traffic where possible. Incident response plans should include rapid containment and communication strategies for extortion attempts. Check vendor advisories and threat intelligence sources for updates on detection and mitigation techniques.
Indicators of Compromise
- domain: setpasskey.com
- domain: assignpasskey.com
- domain: oskeysetup.com
- domain: oskeyconnect.com
- domain: secure-passkey.com
- domain: mfaregister.com
- domain: passkey-mfa.com
- domain: registermymfa.com
- domain: oskey.com
Active Cloud Data Theft and Extortion Campaign Targeting Microsoft 365 and SaaS Platforms
Description
A widespread IT impersonation and voice-phishing campaign designated PREY-0058 is actively targeting Microsoft 365 and SaaS platforms. Threat actors impersonate IT helpdesk staff via phone or text to trick executives and senior personnel into divulging credentials through adversary-in-the-middle phishing portals. After bypassing multi-factor authentication, attackers conduct rapid automated data exfiltration across email, file storage, and cloud repositories without deploying ransomware. The operation relies heavily on NodeMaven residential proxy infrastructure to blend with legitimate traffic. Extortion demands are delivered via TOX messaging within hours of compromise, typically with 72-hour deadlines and threats of public data exposure. The campaign exhibits tradecraft overlapping with UNC6671 and involves multiple extortionware brands including BlackFile, Redact, Pink, and Helix.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
PREY-0058 is a widespread social engineering and extortion campaign targeting Microsoft 365 and SaaS platforms. It employs IT helpdesk impersonation via phone and text (vishing) to deceive high-level personnel into divulging credentials through adversary-in-the-middle phishing portals. This enables attackers to bypass multi-factor authentication controls. Following credential compromise, the threat actors perform rapid automated data exfiltration across cloud email, file storage, and other repositories without deploying ransomware payloads. The campaign leverages NodeMaven residential proxy infrastructure to evade detection by blending with legitimate traffic. Extortion demands are delivered via TOX messaging within hours, typically imposing 72-hour deadlines and threatening public data exposure. The campaign's tactics overlap with those of UNC6671 and utilize multiple extortionware brands including BlackFile, Redact, Pink, and Helix.
Potential Impact
Successful attacks result in credential theft including bypass of multi-factor authentication, leading to rapid exfiltration of sensitive data from Microsoft 365 and SaaS cloud environments. The campaign does not deploy ransomware but instead uses stolen data for extortion, threatening public exposure. The use of residential proxies complicates detection and attribution. The impact includes potential significant data loss, reputational damage, and financial extortion pressure on targeted organizations.
Defensive Guidance
No official patch or fix applies as this is a social engineering and credential theft campaign rather than a software vulnerability. Organizations should enhance user awareness training focused on vishing and IT impersonation tactics, implement strong verification procedures for helpdesk communications, and monitor for suspicious login activity. Multi-factor authentication should be complemented with additional controls resistant to phishing and adversary-in-the-middle attacks. Review and restrict use of residential proxy traffic where possible. Incident response plans should include rapid containment and communication strategies for extortion attempts. Check vendor advisories and threat intelligence sources for updates on detection and mitigation techniques.
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://arcticwolf.com/resources/blog/security-bulletin-active-cloud-data-theft-and-extortion-campaign-targeting-microsoft-365-and-saas-platforms/"]
- Adversary
- PREY-0058
- Pulse Id
- 6aa2affe4ab7ba9012836da5
- Threat Score
- null
Indicators of Compromise
Domain
| Value | Description | Copy |
|---|---|---|
domainsetpasskey.com | — | |
domainassignpasskey.com | — | |
domainoskeysetup.com | — | |
domainoskeyconnect.com | — | |
domainsecure-passkey.com | — | |
domainmfaregister.com | — | |
domainpasskey-mfa.com | — | |
domainregistermymfa.com | — | |
domainoskey.com | — |
Threat ID: 6aa2b994acd9273b4931ac44
Added to database: 09/10/2026, 14:07:16 UTC
Last enriched: 09/10/2026, 14:23:39 UTC
Last updated: 09/10/2026, 16:59:13 UTC
Views: 7
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.