ZeroHour
Story · 1 source · 1 articlefirst updated ()

Passkey-Themed Vishing Campaign Hijacks Microsoft 365 Accounts to Feed Extortion Gangs

highPhishing & fraudexploited in the wildimportance 78
What's new: First merged summary of this story. Coverage opened Sept 8 with Arctic Wolf's PREY-0058 tracking (linked to Google TI's UNC6671) and CloudSEC's access to the BigBear 2.0 phishing panel. On Sept 10–11, Microsoft's reporting added attribution (Storm-3121 and Storm-3032), the device-code phishing vector, rogue MFA persistence, Microsoft Graph reconnaissance, sub-1,000 items/hour exfiltration…
Merged summary · glm-5.3 · rewritten as coverage arrives

Since May 2026, attackers impersonating IT help desks have used passkey/MFA/SSO lures with AiTM phishing and device-code flows to steal Microsoft 365 tokens, persist via rogue MFA, and slowly exfiltrate SharePoint/OneDrive/Exchange data for extortion groups…

Microsoft Security Research has tracked active cloud intrusions since May 2026 in which attackers call, text, or message (including via Teams from compromised accounts) employees' personal phones posing as IT help-desk staff, urging urgent passkey, MFA, or SSO updates via domains such as add-passkey[.]com, contoso[.]add-passkey[.]com, passkeyhelpdesk.com, and setupmypasskey.com. The lures lead to adversary-in-the-middle (AiTM) phishing pages or device-code authentication flows that yield credentials, session tokens, and OAuth tokens even when MFA succeeds; device-code phishing issues OAuth tokens to attacker-controlled apps, exposing Salesforce, Slack, Dropbox, and other SSO-integrated services. Attackers register their own MFA methods (authenticator apps, phone numbers, software OTP) for persistence that survives password resets and token expiry, then use Microsoft Graph to enumerate users, SharePoint sites, and OAuth grants, with the python-httpx user agent observed in high-volume access. Data from SharePoint, OneDrive, and Exchange Online (Arctic Wolf also observed Box) is exfiltrated at deliberately throttled rates below 1,000 files or messages per hour to avoid detection, with compromised sessions reaching OfficeHome, Outlook Web, and internal applications within minutes. Attribution varies by vendor: Microsoft names Storm-3121 (feeding ShinyHunters/Falcon extortion) and Storm-3032 (BlackFile members now operating as Helix); Google Threat Intelligence tracks related activity as UNC6671, linked to BlackFile, Helix, Falcon, Pink, and Redact; Arctic Wolf tracks the campaign as PREY-0058, targeting mostly US-based executives in construction, healthcare, real estate, finance, and professional services, noting exfiltration traffic shifted from datacenter ASNs to the NodeMaven residential proxy network and assessing Cinder as a continuation of Pink. Recommended defenses include phishing-resistant MFA (FIDO2), Conditional Access, blocking device-code flows, app-consent admin approval, managed-device requirements, revoking rogue MFA methods/sessions/tokens, help-desk training, and correlating Graph telemetry with SaaS access. In related but separate Microsoft 365 threat reporting the same week: CloudSEC accessed the BigBear 2.0 Evilginx2-based phishing-as-a-service panel run by 'General Boss', finding 5,137 stolen records across 461 organizations (1,032 plaintext passwords, 4,148 session cookies, 474 complete MFA-bypassed authentications), with custom…

  • Campaign active since May 2026; attackers impersonate IT help desk via calls, SMS, and Teams to personal/BYOD phones with fake passkey, MFA, or SSO update lures.
  • Lure domains include add-passkey[.]com, contoso[.]add-passkey[.]com, passkeyhelpdesk.com, and setupmypasskey.com.
  • Initial access via AiTM phishing or device-code authentication; stolen tokens bypass MFA without defeating it, capturing usable sessions even when MFA succeeds.
  • Persistence via attacker-registered MFA methods (authenticator, phone, software OTP) that survive password resets and token expiry.
  • Microsoft Graph enumeration of users, SharePoint, and OAuth grants; python-httpx user agent seen in high-volume SharePoint/OneDrive activity.
  • Exfiltration from SharePoint, OneDrive, and Exchange Online (plus Box per Arctic Wolf) deliberately throttled below 1,000 files or emails per hour; compromised sessions accessed OfficeHome, Outlook Web, and internal apps within minutes.
  • Attribution: Microsoft names Storm-3121 (ShinyHunters/Falcon-linked) and Storm-3032 (BlackFile members now operating as Helix); Google Threat Intelligence tracks related activity as UNC6671 (BlackFile, Helix, Falcon, Pink, Redact); Arctic…
  • Arctic Wolf: targets are mostly US-based executives in construction, healthcare, real estate, finance, and professional services; exfiltration shifted from datacenter ASNs to the NodeMaven residential proxy network.

Coverage timeline

  1. · 7d ago
    Help Net Security· 68
    IT help-desk vishing tricks executives into handing over Microsoft 365 access

    Arctic Wolf tracks PREY-0058 (linked to UNC6671), a vishing campaign stealing Microsoft 365 session tokens via AiTM panels for SaaS data theft and extortion.