PREY-0058 is a widespread financially motivated cloud data-theft and extortion cluster targeting Microsoft 365 and other SaaS environments, predominantly against directors, vice presidents, executives, and IT personnel at US-based organizations. Its operations rely on IT help-desk impersonation by telephone and text-based vishing rather than exploitation of software vulnerabilities. Operators use adversary-in-the-middle authentication portals to capture credentials, MFA approvals, and authenticated session tokens, then replay stolen sessions through residential proxy services selected to resemble the victim's expected geography and network context. Following account takeover, PREY-0058 enumerates account information, associated applications, Microsoft Entra ID, and SharePoint resources. It performs bulk collection from Exchange Online, SharePoint, OneDrive, and other SaaS platforms including Box. The group uses high-volume mailbox access, document search, file access, and download activity to locate and exfiltrate cloud-hosted data. In some intrusions, it resets passwords or registers new authentication information. No endpoint-malware deployment, data encryption, destructive activity, or network-based lateral movement has been observed in this activity. PREY-0058 conducts encryption-less extortion: after stealing data, it contacts victim executives, typically imposes a short payment deadline, and threatens public disclosure. Its tradecraft substantially overlaps activity tracked as UNC6671. It has also been associated with the BlackFile, Pink, Helix, Cinder, and Redact extortion brands, but these labels do not establish a single confirmed actor identity and may represent rebrands, affiliates, splinter groups, or operators sharing infrastructure.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
29 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
14 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A data-theft and extortion activity cluster conducting IT help-desk vishing against Microsoft 365 and other SaaS accounts. It uses adversary-in-the-middle authentication lures to capture credentials, MFA approvals, and session tokens, then systematically discovers and bulk-exfiltrates data from enterprise SaaS services.
Conducts social-engineering and extortion operations against Microsoft 365 and SaaS environments. Operators impersonate internal IT/help-desk personnel by phone, direct executive targets to adversary-in-the-middle authentication portals, intercept credentials and MFA approvals, replay stolen sessions through geographically aligned residential proxies, enumerate SharePoint and Entra ID, and harvest data from OneDrive, Exchange, and Box for extortion.
Data-theft and extortion activity targeting SaaS accounts, particularly Microsoft 365, to collect and exfiltrate data before sending extortion demands. The activity is directed primarily at executive personnel.
Conducts cloud data-theft and rapid financial-extortion operations against Microsoft 365 and associated SaaS environments without deploying ransomware.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.