Microsoft 365 Executives Targeted in Sophisticated Help Desk Vishing Extortion Campaign

Senior executives at companies using Microsoft 365 and other SaaS platforms are now facing elaborate data theft and extortion schemes leveraging help desk vishing, adversary-in-the-middle token attacks, and proxy-based session hijacking. Research conducted by Arctic Wolf has identified this active threat cluster as PREY-0058, which bears striking resemblance to the UNC6671 group previously profiled by Mandiant.

Attack Flow: From Fake IT Call to Corporate Blackmail

The operation typically kicks off with a phone call in which attackers pose as internal IT or help desk representatives. They instruct the target—commonly directors, vice presidents, and other high-level staff—to visit a phishing page with a URL structured like “.”, where domains include names like passkey-mfa[.]com, setpasskey[.]com, oursso[.]com, and others designed to mimic legitimate authentication portals.

Once the victim interacts with the phishing page, the threat actors execute an adversary-in-the-middle (AitM) attack during the Microsoft 365 login process. Their goal: capture credentials and multi-factor authentication (MFA) approvals, then steal session tokens. These tokens are later reused in session replay attacks from proxy IPs, often located in the same geographic region and network range as the victim, to avoid detection.

Inside the Breach: No Malware, But Deep Access

After securing access, attackers perform reconnaissance within SharePoint and Entra ID, using features like SearchQueryPerformed events and wildcard site-web queries. Once sufficient access is confirmed, large volumes of data are exfiltrated from SharePoint, OneDrive, Exchange, or Box. Victims are then approached with extortion demands.

Interestingly, these campaigns don’t rely on deploying endpoint malware or conducting lateral network movement. The attackers instead leverage impersonated lure infrastructure—hundreds of subdomains mimicking real companies—and tools for session replay using residential proxies to bypass conventional defenses.

Who’s Being Targeted & How to Fight Back

Sectors under attack span construction & engineering, healthcare & pharmaceuticals, finance, real estate & property management, and professional services. The primary targets are high-ranking executives with privileged access to sensitive systems and data.

Mitigation strategies include instituting conditional access policies, using phishing-resistant MFA, limiting user permissions on data platforms like SharePoint, and training employees and help desk teams to recognize vishing and phishing tactics. Detection efforts should focus on activity like anomalous token replays from residential proxies, mass access to mailbox data, discovery queries in SharePoint, and newly registered authentication-styled domains being deployed in the attack infrastructure.

This emerging extortion method underscores a shift in threat actor strategy: moving away from malware-centric breaches to social engineering, token theft, and session replay. As these tools evolve, defenders must adjust with robust identity security controls and monitoring. Watch carefully for novel lure infrastructures, improvements in MFA bypass techniques, and ever more sophisticated impersonation tactics—these will define the next phase of enterprise risk.