Microsoft 365 in the crosshairs: passkey-themed vishing by Storm-3121/Storm-3032, BigBear 2.0 phishing panel exposed, and Direct Send spoofing wave
Reports from Sept 8-11, 2026 cover three distinct Microsoft 365 threats: a Microsoft-tracked passkey/MFA/SSO vishing campaign active since May 2026 by Storm-3121 and Storm-3032 that steals tokens and exfiltrates cloud data at low rates; CloudSEC's access to…
The dominant thread, reported by GBHackers, Cyber Security News, Help Net Security, CSO Online, BleepingComputer, and Dark Reading on Sept 10-11, is a Microsoft-tracked campaign active since May 2026 in which attackers call or text employees' personal phones posing as IT helpdesk staff and urge fake passkey, MFA, or SSO updates. Victims are directed to adversary-in-the-middle phishing pages or device-code authentication flows that yield credentials, session tokens, and OAuth tokens even when MFA succeeds. Attackers then register their own MFA methods (authenticator apps, phone numbers, OTP tokens) for persistence that survives password resets, enumerate tenants via Microsoft Graph, and collect SharePoint, OneDrive, and Exchange Online data throttled below 1,000 files or emails per hour, with the python-httpx user agent observed in high-volume access. Microsoft attributes initial access to Storm-3121, linked to ShinyHunters/Falcon extortion operations, and Storm-3032, tied to BlackFile members now operating as Helix; Google Threat Intelligence tracks related activity as UNC6671, linked to the BlackFile, Helix, Falcon, Pink, and Redact gangs. Lure domains cited include add-passkey[.]com and contoso[.]add-passkey[.]com (GBHackers) and passkeyhelpdesk.com and setupmypasskey.com (Cyber Security News) — the reports list different domains rather than contradicting each other. Dark Reading adds a BYOD framing: voice social engineering reaches corporate data on personal devices, and the stolen access is handed to extortion groups including ShinyHunters. Separately, The Register (Sept 8) reports that CloudSEC researchers accessed the admin panel of BigBear 2.0, an Evilginx2-based phishing-as-a-service operation run by an actor known as 'General Boss'. The panel held 5,137 Microsoft 365 records across 461 organizations — 1,032 plaintext passwords, 4,148 session cookies, and 474 complete MFA-bypassed authentications — and the operation was still active, using custom JavaScript to disable FIDO2/WebAuthn on phishing pages, a residential proxy pool spanning 69 countries, at least five affiliates, and real-time credential delivery via Telegram bots. In a third, distinct campaign, Infosecurity Magazine (Sept 11) reports KnowBe4 Threat Lab's observation of 29,785 confirmed phishing emails between July and August 2026 abusing Microsoft 365's Direct Send feature to spoof trusted internal senders such as HR or accounting, bypassing gateways by connecting directly to Exchange…
- Microsoft-tracked passkey-themed vishing campaign active since May 2026; attributed to Storm-3121 (linked to ShinyHunters/Falcon) and Storm-3032 (BlackFile members now operating as Helix).
- Google Threat Intelligence tracks related activity as UNC6671, linked to the BlackFile, Helix, Falcon, Pink, and Redact extortion gangs (BleepingComputer).
- Attack chain: IT-helpdesk impersonation via calls/SMS/Teams, fake passkey/MFA/SSO lures, AiTM phishing pages or device-code flows yielding credentials, session tokens, and OAuth tokens that bypass MFA.
- Lure domains reported: add-passkey[.]com and contoso[.]add-passkey[.]com (GBHackers); passkeyhelpdesk.com and setupmypasskey.com (Cyber Security News).
- Persistence via attacker-registered MFA methods (authenticator apps, phone numbers, software OTP) that survives stolen-token expiry and password resets.
- Post-compromise: Microsoft Graph enumeration of users, SharePoint, and OAuth grants; SharePoint/OneDrive/Exchange Online collection kept below 1,000 files or emails per hour; python-httpx user agent seen in high-volume access.
- Device-code phishing issues OAuth tokens to attacker-controlled apps, exposing Salesforce, Slack, Dropbox, and other SSO apps; compromised sessions accessed OfficeHome, SharePoint Online, Outlook Web, and internal applications within…
- Dark Reading: BYOD contexts heighten exposure to voice-led account takeover; Graph API used to identify lucrative targets; access passed to extortion groups including ShinyHunters.
Coverage timelineoldest first · each row is one article
- · 8d agoBigBear phishing crew nets thousands of Microsoft 365 credentials
The Register · Security· 60
CloudSEC accessed the BigBear 2.0 phishing panel, finding 5,137 stolen Microsoft 365 records across 461 organizations, including 474 MFA-bypassed sessions.