The threat cluster PREY-0058 is bypassing endpoint security by using social engineering and phone-based impersonation to steal Microsoft 365 credentials and session tokens from corporate executives.
Key Points
- Attackers pose as internal IT help desk staff to direct victims toward rogue authentication portals designed to intercept multi-factor authentication.
- The group uses residential proxy networks like NodeMaven to replay stolen session tokens from the victim's geographic location, effectively bypassing impossible travel alerts.
- Once inside, intruders perform discovery on SharePoint and Entra ID to map sensitive repositories and exfiltrate data from OneDrive, Exchange, and Box.
- Arctic Wolf researchers identified that these attacks specifically target high-level personnel, including Directors and Vice Presidents.
- Security teams are advised to monitor for unusual SearchQueryPerformed events and block access from known proxy or hosting networks.