Arctic Wolf Releases Cordial Spider/PREY-0058 Report of IT Help Desk Vishing for Cloud Data Theft and Extortion

Executive Summary

Arctic Wolf is tracking a widespread data theft and extortion threat cluster designated as PREY-0058, also known as Cordial Spider and the previously-mentioned UNC667, above. This activity, detailed in a GitHub blog post published on 4 September 2026, targets Microsoft 365 and other SaaS services through IT help-desk vishing, adversary-in-the-middle token theft, and residential-proxy sign-ins. Analysis of subdomains across the lure infrastructure revealed hundreds of entries impersonating companies in multiple, critical sectors, with targets primarily US-based. Arctic Wolf observed no endpoint malware deployment or network-based lateral movement in this cluster, as actors exfiltrated data from SharePoint, OneDrive, Exchange, and Box, then sent extortion demands to victims. Arctic Wolf has provided a collection of Initiators of Compromise, which are included below for RH-ISAC Core Member awareness.

The RH-ISAC Intelligence Team will continue to monitor the situation for relevant updates.

Key Takeaways

  • The threat actors impersonate internal IT or helpdesk personnel by phone and direct them to an authentication-themed URL, where an operator-controlled AiTM panel is manually gated for each victim to advance through the credential gathering process. This panel stages a Microsoft 365 login flow that captures credentials and MFA approvals to obtain access to authenticated session tokens.
  • Stolen sessions are replayed from residential proxy infrastructure, most notably NodeMaven, often from IP addresses that resolve to the same geo-location and network as the victim. Initial sign-in activity involves applications such as My Signins, My Profile, and My Apps, which reveal account details and the applications available to the victim.
  • After initial access, the threat actors perform discovery techniques against SharePoint and Entra ID, including SearchQueryPerformed events with contentclass:STS_Site, contentclass:STS_Web, and wildcard searches using indexdocid for pagination. These queries are being executed consistently across cases to map and enumerate SharePoint data.
  • The threat actors then perform bulk collection and exfiltration from SharePoint, OneDrive, Exchange, and other SaaS providers such as Box. Observed Exchange collection generates MailItemsAccessed events, while SharePoint and OneDrive collection produces high volumes of FileAccessed and FileDownloaded events.
  • Defenders can disrupt this activity by detecting anomalous residential-proxy token replay, SharePoint discovery and bulk access, mailbox harvesting, and newly registered authentication-themed lure infrastructure. Conditional Access policies that enforce device trust and compliance can prevent replay of stolen sessions from attacker-controlled infrastructure.

Indicators of Compromise

Arctic Wolf has provided Indicators of Compromise included with this campaign, which are included below in their entirety.

Lure Domains

assignpasskey[.]com

mfaregister[.]com

nowsso[.]com

oskeysetup[.]com

oursso[.]com

passkey-mfa[.]com

passkeydeploy[.]com

registermymfa[.]com

setpasskey[.]com

Panel Infrastructure

31[.]42[.]184[.]213

Exfiltration Autonomous System Numbers

AS51582 – PrivateLayer Inc

AS23470 – ReliableSite.Net LLC

AS399629 – Bl Networks

Exfiltration User Agents

Microsoft.Graph.Client/6.0.3

python-httpx/0.28.1

python-requests/2.28.1

Sign-In User Agents

python-requests/2.33.1

python-requests/2.34.2

Residential Proxy Providers (Sign-In)

DATAIMPULSE

LUMINATI

MASSIVE

NODEMAVEN

PROXYRACK

SHIFTER

SOAX

YILU

Mailitemsaccessed Identifier Pair

ClientAppId: 9199bf20-a13f-4107-85dc-02114787ef48

API ID: c999ed3e-27ae-4cb3-b3a2-46b056af63d3

Sharepoint Search Patterns

contentclass:STS_Site

contentclass:STS_Web

indexdocid>{integer}

Entra ID Directory-Enumeration Activity

Get user flows

Get API connectors

Get identity providers

Get user attributes

More Recent Blog Posts

Executive Summary A dark web marketplace is selling 153,000,000 American and Canadian driver’s licenses, reportedly siphoned from idscan[.]net, according to multiple social media...

Executive Summary On 28 August 2026, Microsoft Threat intelligence reported details of what they have dubbed a TerminalFix campaign, a variant of ClickFix,...

Executive Summary Researchers from Lab539 on 12 August 2026 observed a widespread campaign utilizing compromised WordPress sites to deliver a ClickFix verification flow...