"Initial sign-in activity involves applications such as 'My Signins,' 'My Profile,' 'My Apps,' which reveal account details and the applications available to the victim," researchers Steven Campbell, Trevor Daher, Stefan Hostetler, and Joshua Riccio said in an analysis.
The vishing call that opens the door
Threat hunters at Arctic Wolf have detailed a coordinated campaign — tracked as PREY-0058 — that begins with a phone call impersonating internal IT or help desk staff. Targets are typically directors, vice presidents and other executive staff. The caller directs the target to an authentication-themed URL constructed in a predictable way: <victim organization>.<lure domain>.
Once a target follows the link, they are routed into an operator-controlled adversary-in-the-middle (AitM) Microsoft 365 login flow designed to capture credentials and multi-factor authentication (MFA) approvals. The explicit goal is to harvest authenticated session tokens rather than to install malware on the victim's endpoint.
The lure domains and impersonation infrastructure
Arctic Wolf identified hundreds of lure subdomains impersonating real companies. Examples of the lure domains flagged include:
- assignpasskey[.]com
- mfaregister[.]com
- nowsso[.]com
- oskeysetup[.]com
- oursso[.]com
- passkey-mfa[.]com
- passkeydeploy[.]com
- registermymfa[.]com
- setpasskey[.]com
Those domains feed the AitM flow and present what appear to be legitimate authentication pages to the victim. Arctic Wolf's reviewers emphasize the volume and variety of these entries, noting "hundreds of entries impersonating real companies." Google, the source noted, said early last month that the evolving labels used to track this activity do not map to a single, proven actor identity — instead reflecting an amorphous set of affiliates or splinter crews using shared phishing infrastructure.

This site is the portfolio.
OSINTSights runs on Cloudflare Workers, D1, R2, and Vectorize, with an AI pipeline on Hetzner ARM. Nubivance designed, built, and operates it. We do the same for clients.
See what we buildHow stolen tokens are replayed from residential proxies
After capturing session tokens, attackers do not rely on traditional lateral movement or endpoint malware. Instead they perform session replay attacks from proxy infrastructure, such as NodeMaven, and from IP addresses that resolve to the same geographical location and autonomous system number (ASN) as the victim.
Arctic Wolf's analysts observed initial sign-ins that surface account details and application lists, then a discovery stage focused on SharePoint and Entra ID. SharePoint discovery recorded SearchQueryPerformed events targeting contentclass:STS_Site, contentclass:STS_Web, and wildcard searches using indexdocid for pagination. The threat actors then carry out bulk collection and exfiltration from SharePoint, OneDrive, Exchange, and Box, followed by extortion demands to victims.
Notably, the cluster avoids endpoint implants and network-based lateral movement; the entire chain is built around social engineering, authentication interception, and remote token replay.
Connections to other tracked groups: PREY-0058, UNC6671, Cinder, Pink
Arctic Wolf tracks the activity as PREY-0058 and highlights significant tradecraft overlap with a group Google-owned Mandiant has called UNC6671. The analysis also flags the data-extortion actor known as Cinder as likely a rebrand or continuation of operations linked to a group named Pink, citing overlaps between organizations listed on the Cinder leak site and those connected to Pink.
The reporting stresses that these names are labels for activity clusters and infrastructure patterns rather than proof of a single actor operating under multiple aliases.
What this means for technologists, affected enterprises, and end users
- Technologists and security teams: Arctic Wolf advises implementing Conditional Access policies and deploying phishing‑resistant MFA to reduce the success of authentication interception. Defenders are urged to detect anomalous residential‑proxy token replay, SharePoint discovery and bulk access, mailbox harvesting, and newly registered authentication-themed lure infrastructure.
- Affected enterprises and procurement leaders: Organizations whose executives and senior staff hold broad access to SharePoint, OneDrive, Exchange, and third‑party storage like Box should restrict the scope of data users can reach and audit discovery activity that precedes large‑scale downloads.
- End users and help desk staff: Training should cover vishing risks and the specific pattern of being asked to visit an authentication URL that mimics an internal domain. Arctic Wolf explicitly recommends educating employees and help desk personnel about these social‑engineering techniques.
PREY-0058 underscores a hard truth: modern intrusions increasingly aim to abuse authentication rather than to beat down network defenses with malware. With operators harvesting MFA approvals and replaying tokens from proxies that mimic legitimate geolocation and ASN characteristics, defenders must treat anomalous sign‑in telemetry, rapid SharePoint discovery, and sudden mass downloads as high‑priority alerts. Arctic Wolf and other observers show that blocking the next call or domain will help, but the broader challenge is reducing the value of intercepted tokens through stronger, phishing‑resistant authentication and tighter access controls.




