PREY-0058 Vishing and Cloud Data Extortion
Score: 8/10

PREY-0058 Vishing and Cloud Data Extortion

PREY-0058 (UNC6671) uses help-desk vishing and AiTM phishing to steal Microsoft 365 session tokens for bulk data exfiltration from SharePoint and Exchange via residential proxies.

Executive Summary

Arctic Wolf is tracking a widespread threat cluster designated PREY-0058, which shows significant tradecraft overlap with Mandiant's UNC6671. The activity involves a group of associated extortion brands—including Cinder, BlackFile, Helix, and Redact—targeting executive staff at US-based organizations. Cinder is specifically assessed to be a rebrand or continuation of the earlier Pink operations.

The attack chain begins with vishing calls impersonating IT help-desk personnel, directing victims to organization-specific AiTM phishing pages to capture credentials and MFA-backed session tokens. Once access is obtained, the actors utilize residential proxy networks like NodeMaven to replay tokens from IP addresses matching the victim's geolocation. They perform automated discovery and bulk exfiltration of SharePoint, OneDrive, and Exchange data without deploying endpoint malware or performing lateral movement.

This campaign primarily affects US sectors including construction, healthcare, finance, and real estate. The business impact is high, focusing on data extortion where attackers demand payment to prevent the leak of stolen corporate documents.

Key Details

Threat Name

UNC6671 (PREY-0058)

Affects

—

Adversary

PREY-0058 Other Adversaries and Aliases: Cinder; BlackFile; Helix; Redact; UNC6671

Malware/Tools

BlackFile, Pink, Helix, Cinder, Redact

Report Score

8out of 10
Quality Score
Good
IOC Quality8
TTP Details9
Detection Guidance7
Enterprise Relevance10
Clarity & Structure9
Technical Depth7

Sources