ZeroHour
Story · 1 source · 1 articlefirst updated ()3

Passkey-themed IT helpdesk vishing hijacks Microsoft 365 accounts; device-code phishing kits and Direct Send abuse widen the campaign

highPhishing & fraudexploited in the wildimportance 78
What's new: No prior merged summary (first story). 2026-09-10: Microsoft's warnings detail passkey-lure vishing by Storm-3121 and Storm-3032 using AiTM and device-code flows, low-rate cloud exfiltration, and Dark Reading adds the BYOD exposure angle. 2026-09-11: BleepingComputer adds Google Threat Intelligence's UNC6671 tracking across the BlackFile, Helix, Falcon, Pink, and Redact extortion ecosystem, and…
Merged summary · glm-5.3-flash · rewritten as coverage arrives

Microsoft attributes vishing campaigns running since May 2026 to Storm-3121 (linked to ShinyHunters/Falcon) and Storm-3032 (BlackFile members now operating as Helix): callers posing as IT support push fake passkey/MFA/SSO updates, capture credentials and…

Microsoft Security Research has tracked cloud intrusions since May 2026 in which attackers call or text employees' personal phones posing as corporate IT helpdesk staff, urging urgent passkey, MFA, or SSO updates; CSO Online adds that Teams messages from compromised accounts were also used. Lures lead to adversary-in-the-middle phishing pages or device-code authentication flows that yield credentials, session tokens, and OAuth tokens even when MFA succeeds. Device-code phishing issues OAuth tokens to attacker-controlled apps, exposing Salesforce, Slack, Dropbox, and other SSO apps, and compromised sessions reached OfficeHome, SharePoint Online, Outlook Web, and internal applications within minutes. CSO Online notes the passkey standard itself was not broken — phishable MFA was bypassed, with passkey as the lure. The lure domains differ by source: GBHackers cites add-passkey[.]com and contoso[.]add-passkey[.]com, while Cyber Security News cites passkeyhelpdesk.com and setupmypasskey.com. Persistence comes from attacker-registered MFA methods (phone numbers, authenticator apps, software OTP tokens), which survive stolen-token expiry and password resets. Actors use Microsoft Graph to enumerate users, SharePoint, and OAuth grants, and collect SharePoint, OneDrive, and Exchange Online data at deliberately low rates — typically under 1,000 files or messages per hour — with python-httpx user agents observed in high-volume SharePoint/OneDrive access and infrastructure rotation to blend in. Microsoft attributes the initial access tradecraft to Storm-3121, which feeds ShinyHunters and Falcon extortion operations, and Storm-3032, tied to BlackFile members now operating as Helix. Google Threat Intelligence tracks related activity as UNC6671, linked to the BlackFile, Helix, Falcon, Pink, and Redact extortion gangs. Dark Reading adds that actors exploit BYOD scenarios and use Graph API to identify lucrative targets before handing access to extortion groups such as ShinyHunters. Recommended defenses include phishing-resistant MFA, Conditional Access, blocking device-code flows, revoking unauthorized MFA methods and sessions, app consent admin approval, and managed-device requirements. Related developments: eSentire identified the GhostCode kit in late August, using business contact-form messages with an NDA pretext and password-protected HTML attachments to reach Microsoft device-code sign-in via the Microsoft Authentication Broker application ID; it harvested a…

  • Microsoft has tracked the passkey-lure vishing campaign since May 2026; actors call or text employees' personal phones impersonating IT helpdesk, and CSO Online reports Teams messages from compromised accounts were also used.
  • Sources disagree on lure domains: GBHackers reports add-passkey[.]com and contoso[.]add-passkey[.]com; Cyber Security News reports passkeyhelpdesk.com and setupmypasskey.com.
  • AiTM phishing and device-code authentication flows capture credentials, session tokens, and OAuth tokens even when MFA succeeds; device-code phishing exposes Salesforce, Slack, Dropbox, and other SSO apps to attacker-controlled apps.
  • CSO Online clarifies phishable MFA was bypassed — the passkey standard itself was not broken; passkey served as the lure.
  • Persistence is achieved by registering attacker MFA methods (phone numbers, authenticator apps, software OTP tokens), which survive token expiry and password resets.
  • Attackers enumerate users, SharePoint, and OAuth grants via Microsoft Graph; compromised sessions accessed OfficeHome, SharePoint Online, Outlook Web, and internal applications within minutes.
  • SharePoint, OneDrive, and Exchange Online data is collected below 1,000 files or messages per hour to avoid detection; python-httpx user agents appear in high-volume SharePoint/OneDrive access.
  • Attribution: Storm-3121 is linked to ShinyHunters and Falcon extortion operations; Storm-3032 is tied to BlackFile members now operating as Helix; Google Threat Intelligence tracks related activity as UNC6671, linked to BlackFile, Helix,…

Coverage timeline

  1. · 7d ago
    GBHackers· 72
    Hackers Pose as IT Support to Hijack Microsoft 365 Accounts With Fake Passkey Alerts

    Microsoft warns of vishing campaigns by Storm-3121 and Storm-3032 hijacking Microsoft 365 accounts via fake passkey alerts, adding attacker-controlled MFA and exfiltrating cloud data.