ZeroHour
Story · 9 sources · 13 articlesfirst updated ()1

Passkey-themed vishing by Storm-3121/Storm-3032, N0va phishkit, blob-URL phishing, and M365 Direct Send spoofing headline a week of identity attacks

highPhishing & fraudexploited in the wildimportance 78
What's new: Since the previous summary, reports from Dark Reading, CSO Online, Infosecurity Magazine, and BleepingComputer (2026-09-10/11) add: Google Threat Intelligence's UNC6671 designation linking the activity to five extortion gangs (BlackFile, Helix, Falcon, Pink, Redact); the detail that device-code phishing exposes Salesforce, Slack, and Dropbox via attacker-controlled OAuth apps and that compromised…
Merged summary · glm-5.3 · rewritten as coverage arrives

Ten reports from 2026-09-09 to 2026-09-11 cover four distinct campaigns abusing Microsoft infrastructure: Microsoft-tracked passkey-themed vishing attributed to Storm-3121/Storm-3032 (UNC6671), ANY.RUN's N0va device-code phishkit, Barracuda's blob-URL…

Ten reports published 2026-09-09 through 2026-09-11 describe four separate identity-attack analyses that abuse legitimate Microsoft infrastructure and authentication; the sources do not state the campaigns are related. The largest thread is Microsoft Security Research's tracking of cloud intrusions observed since May 2026 (Microsoft Security Blog 2026-09-09; GBHackers, Cyber Security News, Help Net Security 2026-09-10; Dark Reading 2026-09-10; CSO Online 2026-09-11; BleepingComputer 2026-09-11). Attackers impersonate IT helpdesk staff in calls and SMS to employees' personal phones urging urgent passkey, MFA, or SSO updates, and also use Teams messages from compromised accounts (CSO Online); lures lead to adversary-in-the-middle phishing or device-code authentication flows that capture credentials, session tokens, or OAuth tokens even when MFA succeeds. Lure domains embed victim organization names as subdomains (e.g., contoso.add-passkey[.]com, plus add-passkey[.]com, passkeyhelpdesk[.]com, and setupmypasskey[.]com), are often registered with Nicenic, and go operational within hours. Post-compromise, actors register their own MFA methods (phone numbers, authenticator apps, software OTP) for persistence, enumerate users, SharePoint, and OAuth grants via Microsoft Graph, and collect SharePoint, OneDrive, and Exchange Online data at deliberately low rates (often under 1,000 files or messages per hour), with python-httpx seen in high-volume file access; BleepingComputer adds that compromised sessions accessed OfficeHome, SharePoint Online, Outlook Web, and internal applications within minutes, and that device-code phishing issues OAuth tokens to attacker-controlled apps exposing Salesforce, Slack, Dropbox, and other SSO apps. Microsoft attributes initial-access tradecraft to Storm-3121 (linked to ShinyHunters and Falcon) and Storm-3032 (BlackFile members now operating as Helix); Google Threat Intelligence tracks related activity as UNC6671, linked to the BlackFile, Helix, Falcon, Pink, and Redact extortion gangs. Dark Reading frames the activity as exploiting BYOD contexts, with the Graph API used to identify lucrative targets and access passed to extortion groups such as ShinyHunters. Recommended defenses across reports: revoke sessions, remove unauthorized authentication methods, phishing-resistant MFA, Conditional Access, managed-device requirements, app-consent admin approval, and blocking device-code flows. Separately, ANY.RUN (Cyber Security News,…

  • Microsoft-tracked intrusions observed since May 2026 use helpdesk-impersonation calls/SMS (and Teams messages from compromised accounts) urging passkey, MFA, or SSO updates, leading to AiTM phishing or device-code flows that capture…
  • Microsoft attributes initial access to Storm-3121 (linked to ShinyHunters and Falcon) and Storm-3032 (BlackFile members now operating as Helix); Google Threat Intelligence tracks related activity as UNC6671, linked to BlackFile, Helix,…
  • Lure domains embed victim org names as subdomains, e.g., contoso.add-passkey[.]com, plus add-passkey[.]com, passkeyhelpdesk[.]com, and setupmypasskey[.]com; often registered via Nicenic and operational within hours
  • Post-compromise: attacker-registered MFA methods for persistence, Microsoft Graph enumeration of users/SharePoint/OAuth grants, and SharePoint, OneDrive, and Exchange Online collection throttled below 1,000 files or emails per hour;…
  • Device-code phishing issues OAuth tokens to attacker-controlled apps, exposing Salesforce, Slack, Dropbox, and other SSO apps; compromised sessions accessed OfficeHome, SharePoint Online, Outlook Web, and internal applications within…
  • Dark Reading: voice social engineering exploits BYOD contexts, with Graph API used to identify lucrative targets and access passed to extortion groups including ShinyHunters
  • Defenses recommended across Microsoft-campaign reports: revoke sessions, remove unauthorized MFA methods, phishing-resistant MFA, Conditional Access, managed-device requirements, app-consent admin approval, blocking device-code flows
  • ANY.RUN's N0va phishkit targets government, technology, consulting, and healthcare sectors in North America and the EU, imitating Microsoft Teams, SharePoint, OneDrive, DocuSign, Google Drive, Dropbox, Zoom, and Adobe Sign; it captures…

Coverage timeline

  1. · 6d ago
    SecurityWeek· 52
    New Phishing Attack Creates Malicious Pages Inside the Victim’s Browser

    Barracuda details a phishing campaign that renders pages in-browser via blob URLs, routed through Microsoft Teams and cdn.bloom[.]io to evade detection.

  2. · 6d ago
    Cyber Security News· 56
    New N0va Phishkit Targets North America and EU: A Growing Identity Risk for SOCs

    ANY.RUN researchers uncovered the N0va phishkit targeting government, technology, consulting, and healthcare organizations across North America and the EU via device code phishing.

  3. · 6d ago
    Microsoft Security Blog· 76
    Passkey-themed social engineering leads to identity and cloud compromise

    Microsoft tracks ongoing cloud intrusions where passkey-themed helpdesk lures enable AiTM credential theft, MFA persistence, and SharePoint data theft.

  4. · 5d ago
    Help Net Security· 55
    Cybercriminals are building phishing pages that exist only inside victims’ browsers

    Barracuda details a DocuSign-themed phishing campaign that renders login pages locally via blob URLs, abusing genuine Microsoft OAuth and Teams infrastructure.

  5. · 5d ago
    GBHackers· 72
    Hackers Pose as IT Support to Hijack Microsoft 365 Accounts With Fake Passkey Alerts

    Microsoft warns of vishing campaigns by Storm-3121 and Storm-3032 hijacking Microsoft 365 accounts via fake passkey alerts, adding attacker-controlled MFA and exfiltrating cloud data.

  6. · 5d ago
    GBHackers· 48
    New Phishing Attack Uses Blob URLs to Hide Malicious Pages From Security Scanners

    Barracuda detailed a DocuSign-themed phishing campaign that renders credential-harvesting pages as browser blob URLs, evading URL reputation and blocklist defenses.

  7. · 5d ago
    Cyber Security News· 66
    Hackers Use Passkey-Themed Phishing to Hijack Microsoft 365 Accounts and Steal Cloud Data

    Microsoft reports passkey-themed phishing campaigns hijacking Microsoft 365 accounts via AiTM and device-code flows, then exfiltrating cloud data.

  8. · 5d ago
    Help Net Security· 74
    Attackers call employees’ personal phones to break into Microsoft 365 accounts

    Microsoft tracks vishing campaigns by Storm-3121 and Storm-3032 that impersonate IT staff, phish Microsoft 365 credentials, and steal cloud data.

  9. · 5d ago
    Cyber Security News· 48
    Hackers Use Blob URLs and Microsoft Teams to Create Phishing Pages Inside Victims’ Browsers

    Barracuda details a phishing campaign using Microsoft Teams OAuth redirects and browser blob URLs to render local fake DocuSign login pages for credential theft.

  10. · 5d ago
    Dark Reading· 70
    Voice Callers Exploit BYOD to Reach Microsoft 365, Corporate Data

    Threat actors use voice calls and Microsoft Graph API via BYOD devices to access Microsoft 365, then sell access to extortion groups like ShinyHunters.

  11. · 4d ago
    CSO Online· 78
    Attackers use passkey-themed scams to hijack Microsoft 365 accounts

    Microsoft tracks ongoing M365 cloud intrusions since May using passkey-themed helpdesk vishing, AiTM phishing, and device-code abuse.

  12. · 4d ago
    Infosecurity Magazine· 58
    Hackers Favor US Eastern Business Hours in M365 Phishing Campaign

    KnowBe4 tracked 29,785 phishing emails abusing Microsoft 365 Direct Send to spoof internal senders while timing sends to US Eastern business hours.

  13. · 4d ago
    BleepingComputer· 78
    Passkey-themed phishing attacks lead to Microsoft 365 data theft

    Microsoft links ShinyHunters- and Helix-affiliated actors to passkey-themed vishing and device-code phishing that compromises Microsoft 365 accounts and steals cloud data.