Fake Passkey Lures Steal Microsoft 365 Access

31267256481?profile=RESIZE_400xA new social engineering campaign has been discovered in which attackers are using fake passkeys and IT support requests to gain access to Microsoft 365 accounts. Microsoft Threat Intelligence has tracked the activity since May 2026 and says several threat actors, including Storm-3121 and Storm-3032, use these initial-access methods.  The company links Storm-3121 activity to ShinyHunters and Falcon extortion, while Storm-3032 represents actors that split from BlackFile and now operate under the Helix extortion banner.[1]

Passkey Lures Target Corporate Employees - The attackers begin by researching potential targets through social media and professional networking sites.  They contact employees by phone, text, or Microsoft Teams.  In some cases, the messages come from compromised accounts, making them appear to be from a familiar contact. Posing as IT support, the attackers say the employee needs to update a passkey, single sign-on (SSO), or multi-factor authentication (MFA).

The victims are then sent to fake Microsoft sign-in pages. Microsoft found domains including passkeyhelpdesk.com, integratedsso.com, and oktasession.com, along with URLs that include the target company’s name, such as contoso.add-passkey.com.  Some domains were registered through Nicenic, although Microsoft cautions that registration alone does not indicate registrar involvement.

The passkey theme is primarily a social engineering pretext rather than an attack on passkey cryptography.  Microsoft found that victims were instead directed through adversary-in-the-middle (AiTM) phishing or device-code authentication flows.

In AiTM attacks, attackers can capture credentials and session tokens.  With device-code phishing, victims enter a code on Microsoft’s legitimate authentication page and unknowingly authorize an attacker-controlled client to obtain access.

Persistence and Cloud Data Collection - After compromising an account, the attackers register additional authentication methods under their control, such as an authenticator app, phone number, or software-based OTP token.  This gives them another route back into the account even if the original access method is disrupted.

The attackers also use Node.js-based tooling and Microsoft Graph APIs to enumerate users, groups, permissions, applications, and other organizational resources before accessing SharePoint Online, OneDrive for Business, and, in some cases, Exchange Online for files, emails, and attachments.

Microsoft also saw large volumes of activity against SharePoint and OneDrive linked to the python-httpx user agent.  The user agent alone is not evidence of malicious activity, but the activity becomes more suspicious when combined with unusual sign-ins, authentication-method changes, reconnaissance, and large-scale data access.

The collection was generally measured rather than a rapid “smash-and-grab,” with observed cases accessing fewer than 1,000 files or emails within an hour.  Microsoft said this pace could help the activity blend with normal enterprise usage while enabling sustained collection.

Attack Sequence (Source: Microsoft)

Protection Strategies - Microsoft recommends investigating unusual sign-ins together with newly registered authentication methods, Microsoft Graph reconnaissance, token activity, abnormal SharePoint or OneDrive downloads, and suspicious mailbox access.  For confirmed compromises, organizations should revoke active sessions and remove unauthorized authentication methods.

Organizations can reduce the risk by using phishing-resistant MFA, including FIDO2 passkeys or hardware-backed security keys, blocking device-code authentication where it is not required, and limiting access from unmanaged devices.

Security Products & Services - Microsoft recommends phishing-resistant authentication such as passkeys as part of the defense against these attacks.  The campaign does not show a weakness in passkey cryptography itself; attackers use passkey enrollment as a convincing reason to steer employees into other authentication flows.

 

This AI-created article is shared at no charge for educational and informational purposes only.

Red Sky Alliance is a Cyber Threat Analysis and Intelligence Service organization.  We provide indicators of compromise information (CTI) via a notification/Tier I analysis service (RedXray) or an analysis service (CTAC).  For questions, comments, or assistance, please contact the office directly at 1-844-492-7225 or feedback@redskyalliance.com    

Weekly Cyber Intelligence Briefings:
REDSHORTS - Weekly Cyber Intelligence Briefings
https://attendee.gotowebinar.com/register/7855487668891299929

 

[1] https://hackread.com/hackers-it-support-fake-passkey-microsoft-365-access/

E-mail me when people leave their comments –

You need to be a member of Red Sky Alliance to add comments!