ZeroHour
Cyber Security Newspublished ()ingested Tushar Subhra Dutta
Part of a story covered by 13 sources: “Passkey-themed vishing by Storm-3121/Storm-3032, N0va phishkit, blob-URL phishing, and M365 Direct Send spoofing headline a week of identity attacks” — merged summary and timeline →

Hackers Use Passkey-Themed Phishing to Hijack Microsoft 365 Accounts and Steal Cloud Data

highPhishing & fraud exploited in the wildimportance 66
AI summary · glm-5.3-flash

Microsoft reports passkey-themed phishing campaigns hijacking Microsoft 365 accounts via AiTM and device-code flows, then exfiltrating cloud data.

Microsoft researchers identified passkey-themed phishing across cloud intrusions observed since May 2026, where callers posing as IT support direct victims to lookalike sign-in pages. The flows include adversary-in-the-middle phishing and device-code authentication, letting attackers capture usable sessions even when MFA succeeds, followed by rogue MFA registration for persistence. Attackers enumerate tenants via Microsoft Graph and collect SharePoint, OneDrive, and Exchange data at rates below 1,000 items per hour; lure domains include passkeyhelpdesk.com and setupmypasskey.com.

  • The passkey narrative is a pretext for AiTM phishing or device-code sign-ins that capture sessions despite MFA.
  • Attackers add their own authenticator apps, phone numbers, or OTP tokens for durable persistence.
  • Graph enumeration and high-volume cloud downloads use python-httpx and rotate infrastructure to blend in.
  • Recommended: phishing-resistant MFA, session and token revocation, and review of newly registered authentication methods.

Indicators of compromiseAll →

TypeIndicatorContext
domainadd-passkey.comy security Domain setupmypasskey[.]com Passkey setup Domain add-passkey[.]com Passkey enrollment Domain integratedsso[.]com SSO Domain
domainintegratedsso.comey setup Domain add-passkey[.]com Passkey enrollment Domain integratedsso[.]com SSO Domain oktasession[.]com Identity-provider session Do
domainkeysyncos.comO Domain oktasession[.]com Identity-provider session Domain keysyncos[.]com Key synchronization Domain oskeysync[.]com Key synchroniz
domainmyconnectkey.comistration Domain syncmykey[.]com Key synchronization Domain myconnectkey[.]com Key connection Domain oskeyconnect[.]com Key connection D
domainoktasession.comom Passkey enrollment Domain integratedsso[.]com SSO Domain oktasession[.]com Identity-provider session Domain keysyncos[.]com Key sync
domainoskeyconnect.comhronization Domain myconnectkey[.]com Key connection Domain oskeyconnect[.]com Key connection Domain validationsetupac[.]com Account val
domainoskeyregister.comey synchronization Domain oskeysetup[.]com Key setup Domain oskeyregister[.]com Key registration Domain syncmykey[.]com Key synchronizati
domainoskeysetup.comonization Domain oskeysync[.]com Key synchronization Domain oskeysetup[.]com Key setup Domain oskeyregister[.]com Key registration Dom
domainoskeysync.comr session Domain keysyncos[.]com Key synchronization Domain oskeysync[.]com Key synchronization Domain oskeysetup[.]com Key setup Dom
domainpasskeyhelpdesk.comm becoming a data breach. Type Indicator Description Domain passkeyhelpdesk[.]com Passkey support lure Domain secure-passkey[.]com Passkey
domainportalsetuphub.comvalidationsetupac[.]com Account validation and setup Domain portalsetuphub[.]com Portal setup Note: IP addresses and domains are intention
domainsecure-passkey.comon Domain passkeyhelpdesk[.]com Passkey support lure Domain secure-passkey[.]com Passkey security Domain setupmypasskey[.]com Passkey setu
domainsetupmypasskey.comrt lure Domain secure-passkey[.]com Passkey security Domain setupmypasskey[.]com Passkey setup Domain add-passkey[.]com Passkey enrollment
domainsyncmykey.comey setup Domain oskeyregister[.]com Key registration Domain syncmykey[.]com Key synchronization Domain myconnectkey[.]com Key connect
domainvalidationsetupac.comconnection Domain oskeyconnect[.]com Key connection Domain validationsetupac[.]com Account validation and setup Domain portalsetuphub[.]com
Full article817 words · extracted from cybersecuritynews.com · click to collapse

Hackers are using passkey-themed phishing to take control of Microsoft 365 accounts and collect cloud data. It can defeat MFA protections.

The campaign starts with calls and texts to employees. Attackers pose as IT support, claim a passkey, MFA, or single sign-on setting needs attention, and direct targets to lookalike sign-in pages.

Compromised accounts can also send lures through Microsoft Teams. Microsoft researchers identified the activity across cloud intrusions observed since May 2026.

They found unusual sign-ins followed by new authentication methods, Microsoft Graph queries, and downloads from SharePoint, OneDrive, and email services. The pattern indicates deliberate collection from compromised cloud identities.

Microsoft said in a report shared with Cyber Security News (CSN) that the attackers rotate infrastructure and may use separate connections for sign-in, discovery, and collection. This can resemble normal use while attackers map organizations and take files or messages.

Hackers Use Passkey-Themed Phishing

The passkey story is a pretext, not an effort to enroll a passkey. Victims can be put into an adversary-in-the-middle phishing flow, where a fake site relays their sign-in to the real service and captures credentials and session tokens.

They may instead complete a device-code sign-in that grants access to an attacker-controlled client. A user can complete MFA and still surrender a usable cloud session.

BigBear session theft campaign showed phishing pages can steal proof that MFA was completed. Authentication prompts deserve the same scrutiny as password requests, after an unexpected call or text.

In one sequence, an attacker signed in from an unmanaged device, then opened account portals with the same session.

Observed attack sequence (Source - Microsoft)
Observed attack sequence (Source – Microsoft)

In another, device-code approval produced a token replayed to bypass MFA. Researchers also saw attackers return using compromised credentials paired with an authenticator method registered earlier.

After entry, operators seek lasting access by adding a phone number, authenticator application, or software one-time-password token under their control. A password reset may not evict them if active sessions, refresh tokens, or rogue authentication methods remain. Teams should investigate risky sign-ins alongside every newly registered factor.

Organizations have faced Entra passkey enrollment attacks using phone impersonation. Employees should confirm unexpected helpdesk requests through a known internal channel, never a number or link given by the caller. A verified reporting route for authentication requests can stop the attack before access is granted.

From Account Access to Cloud Collection

Once persistence is established, the attackers use Microsoft Graph to learn what the user can reach. They enumerate users, groups, roles, applications, permissions, sites, drives, folders, files, mailboxes, and attachments. One request may be normal, but broad discovery followed by content retrieval reveals a coordinated intrusion.

The operators then target SharePoint Online and OneDrive for Business with high-volume file access and downloads. Some cases extended to Exchange Online REST API access to email content. Microsoft observed collection often below 1,000 files or emails per hour, a pace that can avoid attention while continuing for hours or days.

This resembles device code phishing abuse, in which a legitimate approval page is abused to gain access without taking a browser cookie. The damage follows when criminals search repositories and collect accessible data.

Defenders should correlate identity, Graph, SharePoint, OneDrive, and Exchange records, rather than treating an IP address or domain as conclusive. Important signals include an unusual sign-in followed by MFA enrollment, intensive Graph discovery, anonymous-proxy access, automated downloading, and concentrated mailbox or attachment searches.

For a confirmed compromise, teams should revoke active sessions and refresh tokens, reset credentials, remove unauthorized authentication methods and mailbox rules, then require secure MFA registration. They should require phishing-resistant MFA, limit cloud access from unmanaged devices, restrict device-code flows unless needed, and review application consent plus privileged Graph permissions.

The actions reflect lessons from M365 session hijacking cases, where stolen sessions may survive a password reset. Training should cover voice, text, and Teams scams, while cloud and mailbox auditing can prevent a routine-looking passkey update from becoming a data breach.

TypeIndicatorDescription
Domainpasskeyhelpdesk[.]comPasskey support lure
Domainsecure-passkey[.]comPasskey security
Domainsetupmypasskey[.]comPasskey setup
Domainadd-passkey[.]comPasskey enrollment
Domainintegratedsso[.]comSSO
Domainoktasession[.]comIdentity-provider session
Domainkeysyncos[.]comKey synchronization
Domainoskeysync[.]comKey synchronization
Domainoskeysetup[.]comKey setup
Domainoskeyregister[.]comKey registration
Domainsyncmykey[.]comKey synchronization
Domainmyconnectkey[.]comKey connection
Domainoskeyconnect[.]comKey connection
Domainvalidationsetupac[.]comAccount validation and setup
Domainportalsetuphub[.]comPortal setup

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Keep your SOC up to date on active malware & phishing within 24h of their emergence. Try ANYRUN to prevent incidents with early detection.

Tushar Subhra Dutta

Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.

Text extracted automatically; images, tables and formatting may be missing. Original: https://cybersecuritynews.com/passkey-themed-phishing/