ZeroHour
Story · 8 sources · 9 articlesfirst updated ()

Passkey-themed vishing and device-code phishing compromise Microsoft 365: Storm-3121/Storm-3032 linked to extortion gangs, N0va phishkit emerges, and 29,785 Direct Send spoofed…

highPhishing & fraudexploited in the wildimportance 78
What's new: First merged summary of this story (no prior summary existed). New in this reporting window (2026-09-09 to 2026-09-11): Microsoft publicly attributed the May 2026-onward passkey-themed vishing and device-code intrusion campaign to Storm-3121 and Storm-3032 and its extortion links; Google Threat Intelligence introduced the UNC6671 designation for related activity; ANY.RUN disclosed the N0va…
Merged summary · glm-5.3-flash · rewritten as coverage arrives

Microsoft attributes a May 2026-onward campaign of IT-helpdesk vishing with passkey/MFA/SSO lures to Storm-3121 (ShinyHunters/Falcon-linked) and Storm-3032 (BlackFile/Helix), who use AiTM and device-code phishing to steal M365 credentials and tokens, register…

Microsoft Security Research is tracking active cloud intrusions, observed since May 2026, in which attackers call or text employees' personal phones while posing as IT helpdesk staff, urging urgent passkey, MFA, or SSO updates. The lures lead to adversary-in-the-middle phishing pages that capture credentials and session tokens, or device-code authentication flows that issue OAuth tokens to attacker-controlled apps, exposing SSO-connected services including Salesforce, Slack, and Dropbox. Lure domains observed include add-passkey[.]com and contoso.add-passkey[.]com (victim organization names embedded as subdomains), plus passkeyhelpdesk.com and setupmypasskey.com; they are often registered via Nicenic and go operational within hours. Post-compromise, actors enroll their own phone, authenticator, and software OTP MFA methods for persistence that survives token expiry and password resets, enumerate users, SharePoint, and OAuth grants via Microsoft Graph, and download SharePoint, OneDrive, and Exchange Online content at deliberately low rates (often under 1,000 files or messages per hour), with python-httpx seen in high-volume file access and compromised sessions reaching OfficeHome, SharePoint Online, Outlook Web, and internal applications within minutes. Microsoft attributes the initial access tradecraft to Storm-3121, linked to ShinyHunters and Falcon extortion operations, and Storm-3032, tied to BlackFile members now operating as Helix; Google Threat Intelligence tracks related activity as UNC6671, connected to the BlackFile, Helix, Falcon, Pink, and Redact extortion gangs, and Dark Reading reports access is passed to extortion groups such as ShinyHunters, with BYOD environments heightening exposure. CSO Online notes the passkey narrative is only the lure: phishable MFA was bypassed, not the passkey standard itself. In a parallel thread, ANY.RUN researchers uncovered the N0va phishkit, which imitates Microsoft Teams, SharePoint, OneDrive, DocuSign, Google Drive, Dropbox, Zoom, and Adobe Sign to draw victims into device-code authentication, captures access and refresh tokens after legitimate sign-in, and abuses token-exchange and device registration for persistent SSO access, targeting government, technology, consulting, and healthcare organizations in North America and the EU while evading MFA-focused detections. Separately, KnowBe4 Threat Lab observed 29,785 confirmed phishing emails between July and August 2026 abusing Microsoft 365 Direct Send to spoof…

  • Microsoft has tracked the passkey-themed cloud intrusion campaign since May 2026; attackers call or SMS employees' personal phones impersonating IT helpdesk and urge urgent passkey, MFA, or SSO updates.
  • Lures lead to adversary-in-the-middle phishing (capturing credentials and session tokens) or device-code authentication flows that grant actors OAuth tokens to attacker-controlled apps, exposing SSO apps including Salesforce, Slack, and…
  • Observed lure domains include add-passkey[.]com, contoso.add-passkey[.]com (org names as subdomains), passkeyhelpdesk.com, and setupmypasskey.com; domains are often registered via Nicenic and go operational within hours.
  • Persistence is achieved by registering attacker-controlled MFA methods (phone numbers, authenticator apps, software OTP), which survive stolen token expiry and password resets.
  • Actors use Microsoft Graph to enumerate users, SharePoint, and OAuth grants, then collect SharePoint, OneDrive, and Exchange Online data at rates below 1,000 files or messages per hour; python-httpx appears in high-volume file access.
  • Compromised sessions accessed OfficeHome, SharePoint Online, Outlook Web, and internal applications within minutes of compromise.
  • Microsoft attributes the initial access tradecraft to Storm-3121 (feeding ShinyHunters and Falcon extortion operations) and Storm-3032 (BlackFile members now operating as Helix); Dark Reading reports access is handed to extortion groups…
  • Google Threat Intelligence tracks related activity as UNC6671, linked to the BlackFile, Helix, Falcon, Pink, and Redact extortion gangs.

Coverage timeline

  1. · 6d ago
    Cyber Security News· 56
    New N0va Phishkit Targets North America and EU: A Growing Identity Risk for SOCs

    ANY.RUN researchers uncovered the N0va phishkit targeting government, technology, consulting, and healthcare organizations across North America and the EU via device code phishing.

  2. · 6d ago
    Microsoft Security Blog· 76
    Passkey-themed social engineering leads to identity and cloud compromise

    Microsoft tracks ongoing cloud intrusions where passkey-themed helpdesk lures enable AiTM credential theft, MFA persistence, and SharePoint data theft.

  3. · 6d ago
    GBHackers· 72
    Hackers Pose as IT Support to Hijack Microsoft 365 Accounts With Fake Passkey Alerts

    Microsoft warns of vishing campaigns by Storm-3121 and Storm-3032 hijacking Microsoft 365 accounts via fake passkey alerts, adding attacker-controlled MFA and exfiltrating cloud data.

  4. · 5d ago
    Cyber Security News· 66
    Hackers Use Passkey-Themed Phishing to Hijack Microsoft 365 Accounts and Steal Cloud Data

    Microsoft reports passkey-themed phishing campaigns hijacking Microsoft 365 accounts via AiTM and device-code flows, then exfiltrating cloud data.

  5. · 5d ago
    Help Net Security· 74
    Attackers call employees’ personal phones to break into Microsoft 365 accounts

    Microsoft tracks vishing campaigns by Storm-3121 and Storm-3032 that impersonate IT staff, phish Microsoft 365 credentials, and steal cloud data.

  6. · 5d ago
    Dark Reading· 70
    Voice Callers Exploit BYOD to Reach Microsoft 365, Corporate Data

    Threat actors use voice calls and Microsoft Graph API via BYOD devices to access Microsoft 365, then sell access to extortion groups like ShinyHunters.

  7. · 5d ago
    CSO Online· 78
    Attackers use passkey-themed scams to hijack Microsoft 365 accounts

    Microsoft tracks ongoing M365 cloud intrusions since May using passkey-themed helpdesk vishing, AiTM phishing, and device-code abuse.

  8. · 4d ago
    Infosecurity Magazine· 58
    Hackers Favor US Eastern Business Hours in M365 Phishing Campaign

    KnowBe4 tracked 29,785 phishing emails abusing Microsoft 365 Direct Send to spoof internal senders while timing sends to US Eastern business hours.

  9. · 4d ago
    BleepingComputer· 78
    Passkey-themed phishing attacks lead to Microsoft 365 data theft

    Microsoft links ShinyHunters- and Helix-affiliated actors to passkey-themed vishing and device-code phishing that compromises Microsoft 365 accounts and steals cloud data.