Executive Summary
Arctic Wolf is tracking a widespread threat cluster designated PREY-0058, which shows significant tradecraft overlap with Mandiant's UNC6671. The activity involves a group of associated extortion brands—including Cinder, BlackFile, Helix, and Redact—targeting executive staff at US-based organizations. Cinder is specifically assessed to be a rebrand or continuation of the earlier Pink operations.
The attack chain begins with vishing calls impersonating IT help-desk personnel, directing victims to organization-specific AiTM phishing pages to capture credentials and MFA-backed session tokens. Once access is obtained, the actors utilize residential proxy networks like NodeMaven to replay tokens from IP addresses matching the victim's geolocation. They perform automated discovery and bulk exfiltration of SharePoint, OneDrive, and Exchange data without deploying endpoint malware or performing lateral movement.
This campaign primarily affects US sectors including construction, healthcare, finance, and real estate. The business impact is high, focusing on data extortion where attackers demand payment to prevent the leak of stolen corporate documents.
