ZeroHour
Story · 7 sources · 9 articlesfirst updated ()

Passkey-themed phishing and device-code kits compromise Microsoft 365 accounts despite MFA, feeding extortion operations

highPhishing & fraudexploited in the wildimportance 78
What's new: New reporting added: Barracuda's DocuSign-themed phishing chain abusing Microsoft OAuth redirects into Microsoft Teams and locally rendered blob-URL sign-in pages with service workers and sandboxed iframes that evade URL-reputation checks, previously absent from the story. Expanded detail on the passkey vishing campaign: lure domains passkeyhelpdesk.com and setupmypasskey.com, python-httpx…
Merged summary · glm-5.3-flash · rewritten as coverage arrives

Microsoft attributes passkey-themed IT-helpdesk vishing active since May 2026 to Storm-3121 and Storm-3032 (linked to ShinyHunters/Falcon and Helix/BlackFile; also tracked as UNC6671); AiTM and device-code phishing capture M365 sessions despite MFA, enabling…

Microsoft Security Research has tracked cloud intrusions since May 2026 in which attackers call or text employees' personal phones posing as IT help desk staff, using fake passkey, MFA, or SSO enrollment lures to steer victims to adversary-in-the-middle phishing pages or device-code authentication flows that capture credentials, session tokens, and OAuth tokens even when MFA succeeds. Microsoft attributes initial access to Storm-3121, which feeds ShinyHunters and Falcon extortion operations, and Storm-3032, the Helix extortion operation descended from BlackFile; Google Threat Intelligence tracks related activity as UNC6671, linked to the BlackFile, Helix, Falcon, Pink, and Redact gangs. Dark Reading adds that the voice-led social engineering exploits BYOD scenarios, with access passed to extortion groups such as ShinyHunters, though victim counts are unspecified. Post-compromise, attackers register their own MFA methods for persistence that survives token expiry and password resets, enumerate users, SharePoint, and OAuth grants via Microsoft Graph, and pull SharePoint, OneDrive, and Exchange data below 1,000 items per hour using python-httpx automation; observed lure domains include passkeyhelpdesk.com and setupmypasskey.com, device-code phishing exposes Salesforce, Slack, Dropbox, and other SSO apps, and compromised sessions reached OfficeHome, SharePoint Online, Outlook Web, and internal applications within minutes. Related kit activity includes N0va, tracked by ANY.RUN via a /api/verification/init pattern and targeting government, technology, consulting, and healthcare organizations in North America and Europe with Teams, SharePoint, OneDrive, DocuSign, Google Drive, Dropbox, Zoom, and Adobe Sign lures, and GhostCode, identified by eSentire in late August, which uses NDA-pretext contact-form lures and password-protected HTML attachments to run device-code phishing that harvests a Primary Refresh Token in 32 seconds and registers three devices in 78 seconds via the Microsoft Authentication Broker app ID, GHOSTnet-linked infrastructure, and residential proxies matching the victim's location. Barracuda separately documents DocuSign-themed emails with calendar invites that route through a Microsoft OAuth endpoint into Teams and render a locally assembled blob-URL sign-in page with service workers and sandboxed iframe execution, evading URL-reputation checks to steal credentials without exploiting a Teams flaw. KnowBe4 counted 29,785 confirmed phishing…

  • Microsoft has tracked the passkey-themed helpdesk vishing, AiTM phishing, and device-code intrusion set since May 2026.
  • Attribution: Storm-3121 feeds ShinyHunters and Falcon extortion operations; Storm-3032 is the Helix operation descended from BlackFile; Google Threat Intelligence tracks related activity as UNC6671, linked to BlackFile, Helix, Falcon,…
  • Attackers impersonate IT staff on victims' personal phones with passkey, MFA, or SSO lures; phishable MFA is bypassed, not the passkey standard itself.
  • Post-compromise persistence uses attacker-registered authenticator apps, phone numbers, and software OTP methods, surviving stolen-token expiry and password resets.
  • Microsoft Graph is abused to enumerate tenants, users, and OAuth grants; SharePoint, OneDrive, and Exchange data is exfiltrated below 1,000 files/emails per hour using a python-httpx user agent.
  • Observed lure domains include passkeyhelpdesk.com and setupmypasskey.com; compromised sessions accessed OfficeHome, SharePoint Online, Outlook Web, and internal applications within minutes.
  • Dark Reading reports the voice-led social engineering exploits BYOD scenarios, with access sold to extortion groups including ShinyHunters; victim counts are not specified.
  • GhostCode (eSentire, identified late August) harvests a Primary Refresh Token in 32 seconds and registers three devices in 78 seconds via the Microsoft Authentication Broker app ID, using password-protected HTML attachments, encrypted…

Coverage timeline

  1. · 6d ago
    Cyber Security News· 66
    Hackers Use Passkey-Themed Phishing to Hijack Microsoft 365 Accounts and Steal Cloud Data

    Microsoft reports passkey-themed phishing campaigns hijacking Microsoft 365 accounts via AiTM and device-code flows, then exfiltrating cloud data.

  2. · 6d ago
    Help Net Security· 74
    Attackers call employees’ personal phones to break into Microsoft 365 accounts

    Microsoft tracks vishing campaigns by Storm-3121 and Storm-3032 that impersonate IT staff, phish Microsoft 365 credentials, and steal cloud data.

  3. · 6d ago
    Cyber Security News· 48
    Hackers Use Blob URLs and Microsoft Teams to Create Phishing Pages Inside Victims’ Browsers

    Barracuda details a phishing campaign using Microsoft Teams OAuth redirects and browser blob URLs to render local fake DocuSign login pages for credential theft.

  4. · 6d ago
    Dark Reading· 70
    Voice Callers Exploit BYOD to Reach Microsoft 365, Corporate Data

    Threat actors use voice calls and Microsoft Graph API via BYOD devices to access Microsoft 365, then sell access to extortion groups like ShinyHunters.

  5. · 6d ago
    CSO Online· 78
    Attackers use passkey-themed scams to hijack Microsoft 365 accounts

    Microsoft tracks ongoing M365 cloud intrusions since May using passkey-themed helpdesk vishing, AiTM phishing, and device-code abuse.

  6. · 5d ago
    Infosecurity Magazine· 58
    Hackers Favor US Eastern Business Hours in M365 Phishing Campaign

    KnowBe4 tracked 29,785 phishing emails abusing Microsoft 365 Direct Send to spoof internal senders while timing sends to US Eastern business hours.

  7. · 5d ago
    BleepingComputer· 78
    Passkey-themed phishing attacks lead to Microsoft 365 data theft

    Microsoft links ShinyHunters- and Helix-affiliated actors to passkey-themed vishing and device-code phishing that compromises Microsoft 365 accounts and steals cloud data.

  8. · 23h ago
    The Hacker News· 58
    N0va Phishkit Targets US and EU Businesses: A New Challenge for Identity Security

    N0va phishkit targets US and EU organizations with trusted-brand lures, capturing tokens via legitimate authentication flows to gain SSO access to corporate resources.

  9. · 20h ago
    Cyber Security News· 72
    GhostCode Phishing Kit Bypasses Microsoft 365 MFA to Hijack Accounts in 78 Seconds

    eSentire identified GhostCode, a phishing kit abusing Microsoft 365 OAuth device-code sign-in to steal tokens and take over accounts in seconds.