Every campaign in this series so far has started with a message landing in an inbox. PREY-0058 does not. Arctic Wolf is tracking a widespread cluster of intrusions that begins with a phone call or a text message, and by the time it ends, the attacker has walked out with a company’s SharePoint sites, OneDrive files, Exchange mail, and Box folders, all without a single line of malware touching an endpoint.
The Call Comes First
The operators behind PREY-0058 call or text targeted employees, most often directors, vice presidents, and other executives, along with IT staff who might have elevated access. They pose as the company’s own IT help desk, usually with a plausible pretext: a required security update, a passkey enrollment, a login problem that needs fixing right now. The victim is walked, live, on the phone, to a login page.
That page is not generic. Arctic Wolf found that the adversary-in-the-middle infrastructure behind PREY-0058 is built per victim organization, hosted on subdomains that fold in the target company’s own name alongside keywords like passkey, oskey, passkeydeploy, setpasskey, oskeyconnect, or secure-passkey. The naming is deliberate: it is built to look like the exact kind of passkey or hardware-key enrollment step a security-conscious company would actually roll out, at the exact moment the caller has told the victim to expect it.
A Real Session, Stolen Live
The page sits in the middle of a real Microsoft 365 or Okta and Duo SSO login flow. The victim types their password and completes their MFA prompt, believing they are enrolling a passkey or resolving a help desk ticket, and the adversary-in-the-middle panel captures both the credential and the resulting session token as they pass through. That token is then replayed from residential proxy infrastructure, which lets the sign-in appear to originate from an IP address in the victim’s own region rather than from wherever the operator actually sits, defeating the impossible-travel and IP-reputation checks that would otherwise flag it.
Nothing about this stage requires a software vulnerability. It is a working login, completed by the real user, on infrastructure built to look exactly like what they were told to expect.
Mass Collection, Not a Foothold
Once the session is live, PREY-0058’s operators do not install malware or move laterally across the internal network. There is no ransomware payload and no encryption. Instead, they query Microsoft’s own APIs to map every SharePoint site and subsite the compromised account can reach, then run bulk collection and exfiltration across SharePoint, OneDrive, Exchange, and Box. It is a cloud-native data grab, built entirely on legitimate API access to services the victim organization already trusts.
The tradecraft overlaps closely with UNC6671, the vishing-driven data-extortion cluster Mandiant has tracked targeting SaaS platforms through personal-phone social engineering. Once the exfiltration is complete, the victim organization receives an extortion demand, branded under one of several rotating names Arctic Wolf has observed, including BlackFile, Redact, Pink, and Helix. Reported targets so far cluster in the United States, concentrated in construction and engineering, healthcare and pharmaceuticals, real estate and property management, finance, and professional services.
Why This Is a DMARC Story, Even Without an Email
DMARC, SPF, and DKIM exist to answer one question: was this email actually authorized by the domain it claims to come from. PREY-0058’s entry point is a phone call. There is no message to authenticate, no envelope sender to check, no DKIM signature to verify, because the initial approach never touches email at all. That is not a gap in DMARC’s design. It is simply outside the boundary of what the protocol was ever built to see.
The DMARC-relevant part comes after the break-in. Exchange sits on the list of services PREY-0058 harvests, and a compromised mailbox is a live, authenticated sending identity. Any message the operator chooses to send from it, whether to widen the intrusion, pressure a colleague, or simply blend in while collecting more data, goes out through Microsoft’s real infrastructure with a valid DKIM signature and passes DMARC cleanly, because the account genuinely is authorized to send as that domain. The protocol answers its one question correctly. It was simply never asked the question that mattered here.
What This Means for Your Program
A phishing-resistant channel does not help if the attacker never uses it. Vishing routes around email filtering, link scanning, and DMARC alike by targeting the human on a phone line instead of the inbox. Awareness training that only covers suspicious emails leaves this entire attack surface uncovered.
Help desk verification procedures are now an identity control, not an IT convenience. If a caller claiming to be IT support can talk an executive through an MFA approval, the organization’s actual weak point is the process for verifying who is on the other end of that call, not the strength of the MFA method itself.
Passkey and hardware-key rollouts need a verification step that cannot be spoofed by a phone call. PREY-0058 works specifically because it mimics the legitimate passkey enrollment flow companies are now deploying. Any enrollment process introduced as a security upgrade needs an out-of-band way for the user to confirm it is genuine before they act on it.
Least-privilege access to SharePoint and OneDrive limits the damage a single stolen session can do. The bulk collection stage depends entirely on how much a single compromised account can see. Scoping access tightly turns a full tenant compromise into a contained incident.
The Takeaway
PREY-0058 did not need to beat DMARC, SPF, or DKIM, because it never had to face them. It walked around email authentication entirely by picking up the phone, and only touched authenticated infrastructure after the damage was already done. As vishing-driven, malware-free data extortion keeps proving it can move faster than a security team notices, the accounts your domain already trusts deserve the same scrutiny as the messages trying to impersonate you.
DMARC confirms that an email was authorized to send as your domain. It has nothing to say about a phone call that never touched email at all, or the authenticated mail a hijacked mailbox sends afterward. Excello Mail gives you continuous visibility into everything sending as your domain, so activity from a compromised account stands out instead of disappearing into a passing DMARC report. Sign up for free to Excello Mail and get that visibility in place before a stolen session turns into a data breach.