Threat hunters describe a campaign that targets executives with fake “IT help desk” calls to obtain Microsoft 365 access, leading to data theft and extortion. The reporting says attackers use vishing, adversary-in-the-middle (AitM) techniques to steal session tokens, and sign-ins that appear to originate from residential proxies.

Researchers say the activity is being tracked under the name PREY-0058 and is associated with tradecraft similarities to a data extortion group that Google Threat Intelligence Group has identified as UNC6671. Across the outlets, the targets are described as senior corporate staff, including directors and vice presidents, rather than general users. Help Net Security and The Hacker News both frame the incident as part of a coordinated cluster aimed at Microsoft 365 and other SaaS accounts, with access obtained through social engineering followed by technical session compromise. The outlets focus on different elements of the same attack chain—one emphasizing the help-desk vishing premise and the other describing the broader token theft and proxy-based sign-in behavior—while remaining consistent that stolen access is used for theft and extortion.