Ask most security leaders whether their organization is protected against credential phishing, and they will point to the multi-factor authentication rollout they finished two years ago. Arctic Wolf’s newest research should make them ask a harder question: what happens when the attacker does not bother phishing the login page at all, and calls the help desk instead?
Arctic Wolf is tracking a campaign it calls PREY-0058, and the mechanics are worth sitting with. The threat actors impersonate internal IT or help desk personnel by phone and direct their targets, mostly directors and vice presidents at US construction, healthcare, real estate, finance, and professional services firms, to an authentication-themed URL. That URL leads to an operator-controlled, adversary-in-the-middle Microsoft 365 login flow that captures credentials and MFA approvals in real time and obtains a live, authenticated session token. Stolen sessions are then replayed from residential proxy infrastructure, most notably a provider called NodeMaven, often from IP addresses that resolve to the same geography and network as the victim, so the sign-in looks legitimate to any location-based conditional access rule. From there, actors pull data out of SharePoint, OneDrive, Exchange, and Box, and send an extortion demand.
The counter-argument, and why it does not hold
The obvious response is that this is old news dressed up: phishing-resistant MFA, FIDO2 keys, passkeys, was supposed to close exactly this gap by making credentials unphishable. That is true as far as it goes, and every organization that has not made that move should still make it. But PREY-0058 is not phishing the login page. It is phishing the person who decides whether a login attempt is legitimate in the first place, by having them believe they are on the phone with their own IT department. A hardware key does not help an executive who has just been talked into approving an MFA prompt they believe their own help desk requested. The vulnerability here is not cryptographic. It is procedural, and it sits in exactly the place most security programs have spent the least attention: the moment a human on staff decides who they are actually talking to.
That is not a new observation in the abstract. It is the same failure mode behind the 2023 casino-industry breaches and years of Scattered Spider reporting: attackers target the help desk because it is often the one privileged access point in the enterprise with no hardware-bound verification and no callback protocol, just a person under time pressure trying to be helpful. What PREY-0058 shows is that three years on, that gap is still wide open, and it has industrialized. Arctic Wolf’s indicators tie the campaign to a cluster of extortion brands, among them BlackFile, Pink, Helix, Cinder, and Redact, that the firm says “may represent affiliates, changing brands, or other relationships rather than a single proven actor identity.” The tradecraft, not the label, is the constant. It shares significant overlap with what Google-owned Mandiant tracks as UNC6671, which tells you this is not one crew’s specialty. It is a technique now available across an extortion ecosystem that rebrands faster than most SOCs can update their threat intel feeds.
Chasing brand names is the wrong fight
That naming churn is itself worth calling out, because it is where a lot of security teams misspend their attention. Every time a new brand shows up in a leak-site tracker, there is a temptation to treat it as a new threat requiring new detections. PREY-0058 argues the opposite: defenders should stop trying to keep a scorecard of extortion brand names and instead fix the one process gap that keeps letting all of them in. A rebrand does not require a new defense if the entry point never changed.
What actually closes the gap
Arctic Wolf’s own guidance is the right starting point, and it is notably not about buying a new tool. Tighten Conditional Access so that proxy and hosting-provider traffic gets blocked or challenged rather than trusted by default. Move to phishing-resistant MFA that cannot be relayed through a fake login page, which still matters even though it is not the whole fix. Limit how much a single SharePoint or OneDrive account can reach, so a compromised session cannot walk the entire tenant. And, critically, train help desk staff on a real verification protocol, a callback to a known number, a manager confirmation, anything other than trusting the caller’s word, for any request that touches credentials or MFA.
None of that is exotic. All of it has been recommended before, in the aftermath of every high-profile vishing breach going back years, including in this publication’s own coverage of the growing gap between how fast identity infrastructure moves and how slowly organizations verify who is actually using it. The uncomfortable finding in PREY-0058 is not a new technique. It is that the old advice still has not been implemented widely enough to stop a campaign built entirely around it, three years and multiple extortion brands later. Security programs that have checked the MFA box and moved on are not done. The help desk is still the door nobody locked, and until organizations treat caller verification with the same rigor as the identity governance failures already documented across enterprise AI access, campaigns like this one will keep working exactly as designed.
Source: Arctic Wolf
