Security1 publisher2 min readPublished
Arctic Wolf says the cluster it tracks as PREY-0058 deploys no malware at all. A call from fake IT leads to a proxied login page, and the stolen session token comes back from inside the victim's own ASN.
The Watch · Security desk
Compiled by The WatchSomething wrong?How this is made
The lure domains name the remedy. Four of the nine Arctic Wolf published contain the string passkey, three contain mfa, and two contain sso [7][8]. The pretext follows from that vocabulary: IT is enrolling your passkey, sign in here to register it. What the proxied login actually takes is the password and the MFA approval, which together yield an authenticated session token [9]. Phishing-resistant enrolment is the control that empties that pocket [17], and the rollout delivering it is the same errand the caller claims to be running [6].
Direction matters when picking the countermeasure. In Arctic Wolf's account the calls run outward, with operators posing as internal IT to directors and vice presidents [6][2], and nothing in that account describes operators phoning a service desk to get an account reset [20]. A callback rule at the help desk, verifying that whoever requests a reset is who they say, therefore does not sit in this chain. The verification that does is the reverse one: the executive confirming the IT caller is real before any authentication step begins. Arctic Wolf's guidance covers training for both populations [17].
The artefacts are audit events. Early access shows up in My Signins, My Profile and My Apps, which expose account details and the applications available to the victim [11]. Discovery then moves against SharePoint and Entra ID, with SearchQueryPerformed events carrying contentclass:STS_Site and contentclass:STS_Web plus wildcard searches using indexdocid to page through results [12]. Arctic Wolf's detection advice points at the same layer: residential-proxy token replay, SharePoint discovery and bulk access, mailbox harvesting, and newly registered authentication-themed lure infrastructure [18].
What the account does not carry is a first-observed date, a victim count, or an extortion figure [19]. Scoping stops at sector and geography, meaning US organizations concentrated in construction and engineering, healthcare and pharmaceuticals, real estate and property management, finance, and professional services [16]. The one quantity offered is infrastructure: hundreds of subdomains impersonating real companies [15]. Those subdomains measure preparation rather than confirmed victims, and that is the ceiling on what this report can tell a defender about scale.
Ranked by verification strength, evidence, and original report placement.
Arctic Wolf tracks a data theft and extortion threat cluster as PREY-0058 that targets Microsoft 365 and other SaaS offerings through IT help desk vishing, adversary-in-the-middle token theft, and residential-proxy sign-ins.
The activity mainly singles out directors, vice presidents, and other executive staff.
Google said early last month that the evolving labels do not correspond to a single proven actor identity, but to an amorphous set of affiliates, splinter crews, or groups using the same underlying phishing infrastructure.
Attack chains begin with the threat actors impersonating internal IT or help desk personnel in phone calls and directing targets to an authentication-themed URL following the pattern <victim organization>.<lure domain>.
Arctic Wolf listed these lure domains: assignpasskey[.]com, mfaregister[.]com, nowsso[.]com, oskeysetup[.]com, oursso[.]com, passkey-mfa[.]com, passkeydeploy[.]com, registermymfa[.]com, setpasskey[.]com.
The attacks lead to an operator-controlled adversary-in-the-middle Microsoft 365 login flow designed to harvest credentials and MFA approvals in order to obtain authenticated session tokens.
Follow any of these and your For You feed starts watching them — no settings page required.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
One vendor write-up, relayed once
Everything checkable traces to Arctic Wolf's analysis, which The Hacker News reproduces closely. The saving grace is how specific that analysis is: nine named domains, a named proxy provider, and audit-log events precise enough that any Microsoft 365 tenant can confirm or fail to confirm them. No second party has done so yet, and Microsoft is absent from the account.
Scale shown in infrastructure, not victims
The size of this campaign is measured by what the operators built rather than what they hit: hundreds of subdomains impersonating real companies, nine registered lure domains, targets across five US sectors. Missing is any figure for compromised tenants, any date range, and any sense of how often a call converted into a live session token.
Mechanics tighter than lineage
The intrusion chain is described more carefully than the family tree around it. Domains, audit events and a proxy provider can be checked; likely a rebrand of Pink rests on overlapping names on a leak site, and Google's own reading is that these labels do not resolve to one operator. The word carrying the most weight with the least behind it is widespread, in the opening line.
Naming rights and a matching service
Arctic Wolf named the activity and closes with four measures plus four detection opportunities that describe the managed detection work it sells. That is ordinary for vendor research, and it cuts both ways here: a purely promotional write-up would not hand out nine domains and specific SharePoint queries that customers and non-customers can use unaided.
Firm on how, thin on how much
The chain from phone call to exfiltration is coherent and specific enough to be wrong in public, which is why I would rely on it for hunting. Scope, timing and the Cinder-to-Pink lineage are where I would not lean, and one publisher relaying one vendor keeps the ceiling where it is.
build
NovaCookies turns an MFA approval into a live Microsoft 365 session for $3201 publisher
security
Apollo's California filing puts Social Security numbers into the private equity attack wave2 publishers
security
NovaCookies: $320 a month buys a session-theft rig that rides real Docusign mail2 publishers
security
BigBear's phishing panel disables WebAuthn in the browser to beat MFA at 258 organizations1 publisher
Publishers with included, body-backed reporting in this cluster.
1 article · September 7, 2026