TechNewsReel
Live

Vishing and Residential Proxies Used to Bypass MFA in M365 Data Theft Campaign

Threat cluster PREY-0058 targets U.S. executives using identity-centric attacks to exfiltrate cloud data for extortion.

TechNewsReel Newsroom · September 7, 2026

A sophisticated threat cluster is targeting high-level U.S. executives through a combination of social engineering and identity theft to steal corporate data. The campaign, tracked by Arctic Wolf as PREY-0058, bypasses multi-factor authentication (MFA) to exfiltrate sensitive information from cloud environments for extortion.

The attack begins with "vishing"—voice phishing—where attackers impersonate IT help desk staff to target Directors and Vice Presidents. Once the victim is engaged, the adversaries deploy adversary-in-the-middle (AitM) phishing pages to capture session tokens. This method allows the attackers to bypass MFA entirely, granting them direct access to the victim's account without needing a password or a secondary code.

Once inside, the group exfiltrates data from SaaS platforms, including SharePoint, OneDrive, and Okta. This activity often begins with accessing applications such as 'My Signins,' 'My Profile,' and 'My Apps,' which allow the attackers to map out the victim's account details and identify which corporate applications are available for exploitation.

The Shift to Identity-Centric Attacks

This campaign reflects a broader industry trend where adversaries are moving away from traditional malware and network lateral movement. The PREY-0058 attack chain relies exclusively on SaaS identity theft, meaning no malicious software is ever deployed to the victim's endpoint. This makes the intrusion significantly harder to detect using traditional antivirus or endpoint detection and response (EDR) tools.

Arctic Wolf notes that the cluster shares tradecraft with Mandiant's UNC6671. The group has cast a wide net across several U.S. sectors, specifically targeting the healthcare, pharmaceuticals, finance, real estate, engineering, construction, and professional services industries.

Bypassing Geographic Security

One of the most critical aspects of this campaign is the use of residential proxies, specifically NodeMaven. By routing their traffic through these proxies, attackers can replay stolen session tokens from IP addresses that match the victim's own geography and Autonomous System Number (ASN).

This technique effectively neutralizes common security triggers, such as "impossible travel" alerts or geo-fencing, which typically flag logins coming from unexpected countries or data centers. By mimicking the victim's digital footprint, the attackers can exfiltrate massive amounts of sensitive data from cloud environments while remaining undetected by security operations centers.

What to Watch

As identity-centric attacks evolve, the reliance on standard MFA is becoming a known vulnerability. Organizations are now encouraged to evaluate phishing-resistant authentication methods, such as FIDO2-based security keys, to prevent AitM token theft. Security teams should remain vigilant for unusual access patterns within SaaS logs, even when the originating IP address appears legitimate.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.