Passkey-themed vishing and device-code phishing compromise Microsoft 365: Storm-3121/Storm-3032 linked to extortion gangs, N0va phishkit emerges, and 29,785 Direct Send spoofed…
Microsoft attributes a May 2026-onward campaign of IT-helpdesk vishing with passkey/MFA/SSO lures to Storm-3121 (ShinyHunters/Falcon-linked) and Storm-3032 (BlackFile/Helix), who use AiTM and device-code phishing to steal M365 credentials and tokens, register…
Microsoft Security Research is tracking active cloud intrusions, observed since May 2026, in which attackers call or text employees' personal phones while posing as IT helpdesk staff, urging urgent passkey, MFA, or SSO updates. The lures lead to adversary-in-the-middle phishing pages that capture credentials and session tokens, or device-code authentication flows that issue OAuth tokens to attacker-controlled apps, exposing SSO-connected services including Salesforce, Slack, and Dropbox. Lure domains observed include add-passkey[.]com and contoso.add-passkey[.]com (victim organization names embedded as subdomains), plus passkeyhelpdesk.com and setupmypasskey.com; they are often registered via Nicenic and go operational within hours. Post-compromise, actors enroll their own phone, authenticator, and software OTP MFA methods for persistence that survives token expiry and password resets, enumerate users, SharePoint, and OAuth grants via Microsoft Graph, and download SharePoint, OneDrive, and Exchange Online content at deliberately low rates (often under 1,000 files or messages per hour), with python-httpx seen in high-volume file access and compromised sessions reaching OfficeHome, SharePoint Online, Outlook Web, and internal applications within minutes. Microsoft attributes the initial access tradecraft to Storm-3121, linked to ShinyHunters and Falcon extortion operations, and Storm-3032, tied to BlackFile members now operating as Helix; Google Threat Intelligence tracks related activity as UNC6671, connected to the BlackFile, Helix, Falcon, Pink, and Redact extortion gangs, and Dark Reading reports access is passed to extortion groups such as ShinyHunters, with BYOD environments heightening exposure. CSO Online notes the passkey narrative is only the lure: phishable MFA was bypassed, not the passkey standard itself. In a parallel thread, ANY.RUN researchers uncovered the N0va phishkit, which imitates Microsoft Teams, SharePoint, OneDrive, DocuSign, Google Drive, Dropbox, Zoom, and Adobe Sign to draw victims into device-code authentication, captures access and refresh tokens after legitimate sign-in, and abuses token-exchange and device registration for persistent SSO access, targeting government, technology, consulting, and healthcare organizations in North America and the EU while evading MFA-focused detections. Separately, KnowBe4 Threat Lab observed 29,785 confirmed phishing emails between July and August 2026 abusing Microsoft 365 Direct Send to spoof…
- Microsoft has tracked the passkey-themed cloud intrusion campaign since May 2026; attackers call or SMS employees' personal phones impersonating IT helpdesk and urge urgent passkey, MFA, or SSO updates.
- Lures lead to adversary-in-the-middle phishing (capturing credentials and session tokens) or device-code authentication flows that grant actors OAuth tokens to attacker-controlled apps, exposing SSO apps including Salesforce, Slack, and…
- Observed lure domains include add-passkey[.]com, contoso.add-passkey[.]com (org names as subdomains), passkeyhelpdesk.com, and setupmypasskey.com; domains are often registered via Nicenic and go operational within hours.
- Persistence is achieved by registering attacker-controlled MFA methods (phone numbers, authenticator apps, software OTP), which survive stolen token expiry and password resets.
- Actors use Microsoft Graph to enumerate users, SharePoint, and OAuth grants, then collect SharePoint, OneDrive, and Exchange Online data at rates below 1,000 files or messages per hour; python-httpx appears in high-volume file access.
- Compromised sessions accessed OfficeHome, SharePoint Online, Outlook Web, and internal applications within minutes of compromise.
- Microsoft attributes the initial access tradecraft to Storm-3121 (feeding ShinyHunters and Falcon extortion operations) and Storm-3032 (BlackFile members now operating as Helix); Dark Reading reports access is handed to extortion groups…
- Google Threat Intelligence tracks related activity as UNC6671, linked to the BlackFile, Helix, Falcon, Pink, and Redact extortion gangs.
Coverage timelineoldest first · each row is one article
- · 6d agoNew N0va Phishkit Targets North America and EU: A Growing Identity Risk for SOCs
Cyber Security News· 56
ANY.RUN researchers uncovered the N0va phishkit targeting government, technology, consulting, and healthcare organizations across North America and the EU via device code phishing.
- · 6d agoPasskey-themed social engineering leads to identity and cloud compromise
Microsoft Security Blog· 76
Microsoft tracks ongoing cloud intrusions where passkey-themed helpdesk lures enable AiTM credential theft, MFA persistence, and SharePoint data theft.
- · 6d agoHackers Pose as IT Support to Hijack Microsoft 365 Accounts With Fake Passkey Alerts
GBHackers· 72
Microsoft warns of vishing campaigns by Storm-3121 and Storm-3032 hijacking Microsoft 365 accounts via fake passkey alerts, adding attacker-controlled MFA and exfiltrating cloud data.
- · 5d agoHackers Use Passkey-Themed Phishing to Hijack Microsoft 365 Accounts and Steal Cloud Data
Cyber Security News· 66
Microsoft reports passkey-themed phishing campaigns hijacking Microsoft 365 accounts via AiTM and device-code flows, then exfiltrating cloud data.
- · 5d agoAttackers call employees’ personal phones to break into Microsoft 365 accounts
Help Net Security· 74
Microsoft tracks vishing campaigns by Storm-3121 and Storm-3032 that impersonate IT staff, phish Microsoft 365 credentials, and steal cloud data.
- · 5d agoVoice Callers Exploit BYOD to Reach Microsoft 365, Corporate Data
Dark Reading· 70
Threat actors use voice calls and Microsoft Graph API via BYOD devices to access Microsoft 365, then sell access to extortion groups like ShinyHunters.
- · 5d agoAttackers use passkey-themed scams to hijack Microsoft 365 accounts
CSO Online· 78
Microsoft tracks ongoing M365 cloud intrusions since May using passkey-themed helpdesk vishing, AiTM phishing, and device-code abuse.
- · 4d agoHackers Favor US Eastern Business Hours in M365 Phishing Campaign
Infosecurity Magazine· 58
KnowBe4 tracked 29,785 phishing emails abusing Microsoft 365 Direct Send to spoof internal senders while timing sends to US Eastern business hours.
- · 4d agoPasskey-themed phishing attacks lead to Microsoft 365 data theft
BleepingComputer· 78
Microsoft links ShinyHunters- and Helix-affiliated actors to passkey-themed vishing and device-code phishing that compromises Microsoft 365 accounts and steals cloud data.