Passkey-themed vishing by Storm-3121/Storm-3032, N0va phishkit, blob-URL phishing, and M365 Direct Send spoofing headline a week of identity attacks
Ten reports from 2026-09-09 to 2026-09-11 cover four distinct campaigns abusing Microsoft infrastructure: Microsoft-tracked passkey-themed vishing attributed to Storm-3121/Storm-3032 (UNC6671), ANY.RUN's N0va device-code phishkit, Barracuda's blob-URL…
Ten reports published 2026-09-09 through 2026-09-11 describe four separate identity-attack analyses that abuse legitimate Microsoft infrastructure and authentication; the sources do not state the campaigns are related. The largest thread is Microsoft Security Research's tracking of cloud intrusions observed since May 2026 (Microsoft Security Blog 2026-09-09; GBHackers, Cyber Security News, Help Net Security 2026-09-10; Dark Reading 2026-09-10; CSO Online 2026-09-11; BleepingComputer 2026-09-11). Attackers impersonate IT helpdesk staff in calls and SMS to employees' personal phones urging urgent passkey, MFA, or SSO updates, and also use Teams messages from compromised accounts (CSO Online); lures lead to adversary-in-the-middle phishing or device-code authentication flows that capture credentials, session tokens, or OAuth tokens even when MFA succeeds. Lure domains embed victim organization names as subdomains (e.g., contoso.add-passkey[.]com, plus add-passkey[.]com, passkeyhelpdesk[.]com, and setupmypasskey[.]com), are often registered with Nicenic, and go operational within hours. Post-compromise, actors register their own MFA methods (phone numbers, authenticator apps, software OTP) for persistence, enumerate users, SharePoint, and OAuth grants via Microsoft Graph, and collect SharePoint, OneDrive, and Exchange Online data at deliberately low rates (often under 1,000 files or messages per hour), with python-httpx seen in high-volume file access; BleepingComputer adds that compromised sessions accessed OfficeHome, SharePoint Online, Outlook Web, and internal applications within minutes, and that device-code phishing issues OAuth tokens to attacker-controlled apps exposing Salesforce, Slack, Dropbox, and other SSO apps. Microsoft attributes initial-access tradecraft to Storm-3121 (linked to ShinyHunters and Falcon) and Storm-3032 (BlackFile members now operating as Helix); Google Threat Intelligence tracks related activity as UNC6671, linked to the BlackFile, Helix, Falcon, Pink, and Redact extortion gangs. Dark Reading frames the activity as exploiting BYOD contexts, with the Graph API used to identify lucrative targets and access passed to extortion groups such as ShinyHunters. Recommended defenses across reports: revoke sessions, remove unauthorized authentication methods, phishing-resistant MFA, Conditional Access, managed-device requirements, app-consent admin approval, and blocking device-code flows. Separately, ANY.RUN (Cyber Security News,…
- Microsoft-tracked intrusions observed since May 2026 use helpdesk-impersonation calls/SMS (and Teams messages from compromised accounts) urging passkey, MFA, or SSO updates, leading to AiTM phishing or device-code flows that capture…
- Microsoft attributes initial access to Storm-3121 (linked to ShinyHunters and Falcon) and Storm-3032 (BlackFile members now operating as Helix); Google Threat Intelligence tracks related activity as UNC6671, linked to BlackFile, Helix,…
- Lure domains embed victim org names as subdomains, e.g., contoso.add-passkey[.]com, plus add-passkey[.]com, passkeyhelpdesk[.]com, and setupmypasskey[.]com; often registered via Nicenic and operational within hours
- Post-compromise: attacker-registered MFA methods for persistence, Microsoft Graph enumeration of users/SharePoint/OAuth grants, and SharePoint, OneDrive, and Exchange Online collection throttled below 1,000 files or emails per hour;…
- Device-code phishing issues OAuth tokens to attacker-controlled apps, exposing Salesforce, Slack, Dropbox, and other SSO apps; compromised sessions accessed OfficeHome, SharePoint Online, Outlook Web, and internal applications within…
- Dark Reading: voice social engineering exploits BYOD contexts, with Graph API used to identify lucrative targets and access passed to extortion groups including ShinyHunters
- Defenses recommended across Microsoft-campaign reports: revoke sessions, remove unauthorized MFA methods, phishing-resistant MFA, Conditional Access, managed-device requirements, app-consent admin approval, blocking device-code flows
- ANY.RUN's N0va phishkit targets government, technology, consulting, and healthcare sectors in North America and the EU, imitating Microsoft Teams, SharePoint, OneDrive, DocuSign, Google Drive, Dropbox, Zoom, and Adobe Sign; it captures…
Coverage timelineoldest first · each row is one article
- · 6d agoNew Phishing Attack Creates Malicious Pages Inside the Victim’s Browser
SecurityWeek· 52
Barracuda details a phishing campaign that renders pages in-browser via blob URLs, routed through Microsoft Teams and cdn.bloom[.]io to evade detection.
- · 6d agoNew N0va Phishkit Targets North America and EU: A Growing Identity Risk for SOCs
Cyber Security News· 56
ANY.RUN researchers uncovered the N0va phishkit targeting government, technology, consulting, and healthcare organizations across North America and the EU via device code phishing.
- · 6d agoPasskey-themed social engineering leads to identity and cloud compromise
Microsoft Security Blog· 76
Microsoft tracks ongoing cloud intrusions where passkey-themed helpdesk lures enable AiTM credential theft, MFA persistence, and SharePoint data theft.
- · 5d agoCybercriminals are building phishing pages that exist only inside victims’ browsers
Help Net Security· 55
Barracuda details a DocuSign-themed phishing campaign that renders login pages locally via blob URLs, abusing genuine Microsoft OAuth and Teams infrastructure.
- · 5d agoHackers Pose as IT Support to Hijack Microsoft 365 Accounts With Fake Passkey Alerts
GBHackers· 72
Microsoft warns of vishing campaigns by Storm-3121 and Storm-3032 hijacking Microsoft 365 accounts via fake passkey alerts, adding attacker-controlled MFA and exfiltrating cloud data.
- · 5d agoNew Phishing Attack Uses Blob URLs to Hide Malicious Pages From Security Scanners
GBHackers· 48
Barracuda detailed a DocuSign-themed phishing campaign that renders credential-harvesting pages as browser blob URLs, evading URL reputation and blocklist defenses.
- · 5d agoHackers Use Passkey-Themed Phishing to Hijack Microsoft 365 Accounts and Steal Cloud Data
Cyber Security News· 66
Microsoft reports passkey-themed phishing campaigns hijacking Microsoft 365 accounts via AiTM and device-code flows, then exfiltrating cloud data.
- · 5d agoAttackers call employees’ personal phones to break into Microsoft 365 accounts
Help Net Security· 74
Microsoft tracks vishing campaigns by Storm-3121 and Storm-3032 that impersonate IT staff, phish Microsoft 365 credentials, and steal cloud data.
- · 5d agoHackers Use Blob URLs and Microsoft Teams to Create Phishing Pages Inside Victims’ Browsers
Cyber Security News· 48
Barracuda details a phishing campaign using Microsoft Teams OAuth redirects and browser blob URLs to render local fake DocuSign login pages for credential theft.
- · 5d agoVoice Callers Exploit BYOD to Reach Microsoft 365, Corporate Data
Dark Reading· 70
Threat actors use voice calls and Microsoft Graph API via BYOD devices to access Microsoft 365, then sell access to extortion groups like ShinyHunters.
- · 4d agoAttackers use passkey-themed scams to hijack Microsoft 365 accounts
CSO Online· 78
Microsoft tracks ongoing M365 cloud intrusions since May using passkey-themed helpdesk vishing, AiTM phishing, and device-code abuse.
- · 4d agoHackers Favor US Eastern Business Hours in M365 Phishing Campaign
Infosecurity Magazine· 58
KnowBe4 tracked 29,785 phishing emails abusing Microsoft 365 Direct Send to spoof internal senders while timing sends to US Eastern business hours.
- · 4d agoPasskey-themed phishing attacks lead to Microsoft 365 data theft
BleepingComputer· 78
Microsoft links ShinyHunters- and Helix-affiliated actors to passkey-themed vishing and device-code phishing that compromises Microsoft 365 accounts and steals cloud data.