Executive Summary
Arctic Wolf is tracking a widespread data theft and extortion threat cluster designated as PREY-0058, also known as Cordial Spider and the previously-mentioned UNC667, above. This activity, detailed in a GitHub blog post published on 4 September 2026, targets Microsoft 365 and other SaaS services through IT help-desk vishing, adversary-in-the-middle token theft, and residential-proxy sign-ins. Analysis of subdomains across the lure infrastructure revealed hundreds of entries impersonating companies in multiple, critical sectors, with targets primarily US-based. Arctic Wolf observed no endpoint malware deployment or network-based lateral movement in this cluster, as actors exfiltrated data from SharePoint, OneDrive, Exchange, and Box, then sent extortion demands to victims. Arctic Wolf has provided a collection of Initiators of Compromise, which are included below for RH-ISAC Core Member awareness.
The RH-ISAC Intelligence Team will continue to monitor the situation for relevant updates.
Key Takeaways
- The threat actors impersonate internal IT or helpdesk personnel by phone and direct them to an authentication-themed URL, where an operator-controlled AiTM panel is manually gated for each victim to advance through the credential gathering process. This panel stages a Microsoft 365 login flow that captures credentials and MFA approvals to obtain access to authenticated session tokens.
- Stolen sessions are replayed from residential proxy infrastructure, most notably NodeMaven, often from IP addresses that resolve to the same geo-location and network as the victim. Initial sign-in activity involves applications such as My Signins, My Profile, and My Apps, which reveal account details and the applications available to the victim.
- After initial access, the threat actors perform discovery techniques against SharePoint and Entra ID, including SearchQueryPerformed events with contentclass:STS_Site, contentclass:STS_Web, and wildcard searches using indexdocid for pagination. These queries are being executed consistently across cases to map and enumerate SharePoint data.
- The threat actors then perform bulk collection and exfiltration from SharePoint, OneDrive, Exchange, and other SaaS providers such as Box. Observed Exchange collection generates MailItemsAccessed events, while SharePoint and OneDrive collection produces high volumes of FileAccessed and FileDownloaded events.
- Defenders can disrupt this activity by detecting anomalous residential-proxy token replay, SharePoint discovery and bulk access, mailbox harvesting, and newly registered authentication-themed lure infrastructure. Conditional Access policies that enforce device trust and compliance can prevent replay of stolen sessions from attacker-controlled infrastructure.
Indicators of Compromise
Arctic Wolf has provided Indicators of Compromise included with this campaign, which are included below in their entirety.
Lure Domains
assignpasskey[.]com
mfaregister[.]com
nowsso[.]com
oskeysetup[.]com
oursso[.]com
passkey-mfa[.]com
passkeydeploy[.]com
registermymfa[.]com
setpasskey[.]com
Panel Infrastructure
31[.]42[.]184[.]213
Exfiltration Autonomous System Numbers
AS51582 – PrivateLayer Inc
AS23470 – ReliableSite.Net LLC
AS399629 – Bl Networks
Exfiltration User Agents
Microsoft.Graph.Client/6.0.3
python-httpx/0.28.1
python-requests/2.28.1
Sign-In User Agents
python-requests/2.33.1
python-requests/2.34.2
Residential Proxy Providers (Sign-In)
DATAIMPULSE
LUMINATI
MASSIVE
NODEMAVEN
PROXYRACK
SHIFTER
SOAX
YILU
Mailitemsaccessed Identifier Pair
ClientAppId: 9199bf20-a13f-4107-85dc-02114787ef48
API ID: c999ed3e-27ae-4cb3-b3a2-46b056af63d3
Sharepoint Search Patterns
contentclass:STS_Site
contentclass:STS_Web
indexdocid>{integer}
Entra ID Directory-Enumeration Activity
Get user flows
Get API connectors
Get identity providers
Get user attributes