A newly identified threat cluster known as PREY-0058 is targeting corporate Microsoft 365 accounts through a combination of old-fashioned social engineering and modern token theft. According to research covered by The Hacker News, the group uses help desk vishing (voice phishing) calls combined with adversary-in-the-middle (AitM) session token theft to break into Microsoft 365 and other SaaS platforms, then extort victims over the stolen data. The campaign is a reminder that even well-configured multi-factor authentication (MFA) can be defeated when attackers target the humans and processes around it rather than the login screen itself.
What Is PREY-0058 and How the Help Desk Scam Works
PREY-0058 is the designation given to this attack cluster, and its method centers on impersonating IT support. Rather than sending a phishing email and hoping someone clicks a link, the attackers reportedly place phone calls to employees, executives, or IT help desks, posing as legitimate technical support staff. This is vishing: voice-based social engineering designed to build trust quickly and pressure the target into acting before they think to verify who they're actually talking to.
The goal of these calls is typically to convince a target to reset a password, approve a login prompt, or hand over a one-time code. Because the request appears to come from an internal IT resource, it slips past the instinct many employees have developed around suspicious emails. Vishing exploits a gap that email security tools cannot close: a phone call feels personal and urgent in a way that a message in an inbox does not.
How Adversary-in-the-Middle Attacks Bypass MFA
What makes PREY-0058 particularly effective is the second half of its playbook: adversary-in-the-middle token theft. In an AitM attack, the threat actor doesn't just steal a username and password. Instead, they insert themselves between the victim and the real login service, often using a convincing fake authentication page. When the victim logs in and completes their MFA step, the attacker's proxy captures the resulting session token, the piece of data that proves a user is already authenticated.
This matters because a stolen session token lets an attacker skip the login process entirely. They don't need to guess a password or trick someone into approving a push notification a second time. They simply reuse the captured token to access Microsoft 365 as if they were the legitimate user, MFA and all. It's a technique that has been used against Microsoft 365 environments before, but pairing it with a live vishing call to obtain initial access or reset credentials adds a layer of human manipulation that technical defenses alone struggle to catch.
Who Is Being Targeted and What Data Is at Risk
The reporting on PREY-0058 indicates the campaign is focused on stealing data from Microsoft 365 and other SaaS services, with the end goal of extortion rather than simple account takeover for spam or fraud. This pattern, gain access, exfiltrate sensitive files or communications, then demand payment to prevent disclosure, mirrors a broader shift in cybercrime toward data theft and extortion rather than traditional ransomware encryption. Executives and other high-value employees appear to be a focus, likely because their mailboxes and cloud storage hold the kind of sensitive financial, legal, or strategic information that makes for effective leverage in an extortion attempt.
This fits into a larger trend documented across the industry: social engineering, increasingly enhanced by convincing impersonation tactics, is outpacing many organizations' existing defenses. A recent survey on AI phishing and deepfakes found that a majority of business leaders feel confident in their security posture even as voice-based and AI-assisted impersonation attacks continue to succeed. PREY-0058 is a real-world example of that gap between confidence and readiness.
What This Means For You
If your organization relies on Microsoft 365, this campaign is a signal to look beyond password strength and MFA enrollment rates. Attackers have adapted to a world where MFA is standard, and they're now targeting the verification processes around it, including help desks, password resets, and phone-based support requests. Employees, especially executives and IT staff, need to know that a phone call claiming to be from internal support is not automatically trustworthy just because it sounds official.
Practical Steps to Protect Corporate Accounts
Organizations can reduce their exposure to attacks like PREY-0058 with a few concrete changes. Help desks should use strict identity verification procedures for any password reset or MFA re-enrollment request, ideally requiring a callback to a known number or verification through a separate, pre-established channel rather than trusting the caller's word. Security teams should also consider phishing-resistant authentication methods, such as hardware security keys, which are far more difficult for AitM proxies to intercept than one-time codes or push approvals. Monitoring for anomalous session token usage, such as logins from unexpected locations immediately following a help desk interaction, can help catch an intrusion before data is exfiltrated. Finally, regular training that specifically covers vishing scenarios, not just email phishing, gives employees a script to follow when a call feels off.
The broader lesson from PREY-0058 is that a Microsoft 365 vishing attack succeeds by exploiting trust and process gaps, not technical vulnerabilities in the platform itself. As attackers keep blending social engineering with technical token theft, layered defenses that account for human behavior are no longer optional. Take a few minutes this week to review your organization's help desk verification policy and confirm your team knows what a legitimate IT request actually looks like.




