Passkey-themed phishing and device-code kits compromise Microsoft 365 accounts despite MFA, feeding extortion operations
Microsoft attributes passkey-themed IT-helpdesk vishing active since May 2026 to Storm-3121 and Storm-3032 (linked to ShinyHunters/Falcon and Helix/BlackFile; also tracked as UNC6671); AiTM and device-code phishing capture M365 sessions despite MFA, enabling…
Microsoft Security Research has tracked cloud intrusions since May 2026 in which attackers call or text employees' personal phones posing as IT help desk staff, using fake passkey, MFA, or SSO enrollment lures to steer victims to adversary-in-the-middle phishing pages or device-code authentication flows that capture credentials, session tokens, and OAuth tokens even when MFA succeeds. Microsoft attributes initial access to Storm-3121, which feeds ShinyHunters and Falcon extortion operations, and Storm-3032, the Helix extortion operation descended from BlackFile; Google Threat Intelligence tracks related activity as UNC6671, linked to the BlackFile, Helix, Falcon, Pink, and Redact gangs. Dark Reading adds that the voice-led social engineering exploits BYOD scenarios, with access passed to extortion groups such as ShinyHunters, though victim counts are unspecified. Post-compromise, attackers register their own MFA methods for persistence that survives token expiry and password resets, enumerate users, SharePoint, and OAuth grants via Microsoft Graph, and pull SharePoint, OneDrive, and Exchange data below 1,000 items per hour using python-httpx automation; observed lure domains include passkeyhelpdesk.com and setupmypasskey.com, device-code phishing exposes Salesforce, Slack, Dropbox, and other SSO apps, and compromised sessions reached OfficeHome, SharePoint Online, Outlook Web, and internal applications within minutes. Related kit activity includes N0va, tracked by ANY.RUN via a /api/verification/init pattern and targeting government, technology, consulting, and healthcare organizations in North America and Europe with Teams, SharePoint, OneDrive, DocuSign, Google Drive, Dropbox, Zoom, and Adobe Sign lures, and GhostCode, identified by eSentire in late August, which uses NDA-pretext contact-form lures and password-protected HTML attachments to run device-code phishing that harvests a Primary Refresh Token in 32 seconds and registers three devices in 78 seconds via the Microsoft Authentication Broker app ID, GHOSTnet-linked infrastructure, and residential proxies matching the victim's location. Barracuda separately documents DocuSign-themed emails with calendar invites that route through a Microsoft OAuth endpoint into Teams and render a locally assembled blob-URL sign-in page with service workers and sandboxed iframe execution, evading URL-reputation checks to steal credentials without exploiting a Teams flaw. KnowBe4 counted 29,785 confirmed phishing…
- Microsoft has tracked the passkey-themed helpdesk vishing, AiTM phishing, and device-code intrusion set since May 2026.
- Attribution: Storm-3121 feeds ShinyHunters and Falcon extortion operations; Storm-3032 is the Helix operation descended from BlackFile; Google Threat Intelligence tracks related activity as UNC6671, linked to BlackFile, Helix, Falcon,…
- Attackers impersonate IT staff on victims' personal phones with passkey, MFA, or SSO lures; phishable MFA is bypassed, not the passkey standard itself.
- Post-compromise persistence uses attacker-registered authenticator apps, phone numbers, and software OTP methods, surviving stolen-token expiry and password resets.
- Microsoft Graph is abused to enumerate tenants, users, and OAuth grants; SharePoint, OneDrive, and Exchange data is exfiltrated below 1,000 files/emails per hour using a python-httpx user agent.
- Observed lure domains include passkeyhelpdesk.com and setupmypasskey.com; compromised sessions accessed OfficeHome, SharePoint Online, Outlook Web, and internal applications within minutes.
- Dark Reading reports the voice-led social engineering exploits BYOD scenarios, with access sold to extortion groups including ShinyHunters; victim counts are not specified.
- GhostCode (eSentire, identified late August) harvests a Primary Refresh Token in 32 seconds and registers three devices in 78 seconds via the Microsoft Authentication Broker app ID, using password-protected HTML attachments, encrypted…
Coverage timelineoldest first · each row is one article
- · 6d agoHackers Use Passkey-Themed Phishing to Hijack Microsoft 365 Accounts and Steal Cloud Data
Cyber Security News· 66
Microsoft reports passkey-themed phishing campaigns hijacking Microsoft 365 accounts via AiTM and device-code flows, then exfiltrating cloud data.
- · 6d agoAttackers call employees’ personal phones to break into Microsoft 365 accounts
Help Net Security· 74
Microsoft tracks vishing campaigns by Storm-3121 and Storm-3032 that impersonate IT staff, phish Microsoft 365 credentials, and steal cloud data.
- · 6d agoHackers Use Blob URLs and Microsoft Teams to Create Phishing Pages Inside Victims’ Browsers
Cyber Security News· 48
Barracuda details a phishing campaign using Microsoft Teams OAuth redirects and browser blob URLs to render local fake DocuSign login pages for credential theft.
- · 6d agoVoice Callers Exploit BYOD to Reach Microsoft 365, Corporate Data
Dark Reading· 70
Threat actors use voice calls and Microsoft Graph API via BYOD devices to access Microsoft 365, then sell access to extortion groups like ShinyHunters.
- · 6d agoAttackers use passkey-themed scams to hijack Microsoft 365 accounts
CSO Online· 78
Microsoft tracks ongoing M365 cloud intrusions since May using passkey-themed helpdesk vishing, AiTM phishing, and device-code abuse.
- · 5d agoHackers Favor US Eastern Business Hours in M365 Phishing Campaign
Infosecurity Magazine· 58
KnowBe4 tracked 29,785 phishing emails abusing Microsoft 365 Direct Send to spoof internal senders while timing sends to US Eastern business hours.
- · 5d agoPasskey-themed phishing attacks lead to Microsoft 365 data theft
BleepingComputer· 78
Microsoft links ShinyHunters- and Helix-affiliated actors to passkey-themed vishing and device-code phishing that compromises Microsoft 365 accounts and steals cloud data.
- · 23h agoN0va Phishkit Targets US and EU Businesses: A New Challenge for Identity Security
The Hacker News· 58
N0va phishkit targets US and EU organizations with trusted-brand lures, capturing tokens via legitimate authentication flows to gain SSO access to corporate resources.
- · 20h agoGhostCode Phishing Kit Bypasses Microsoft 365 MFA to Hijack Accounts in 78 Seconds
Cyber Security News· 72
eSentire identified GhostCode, a phishing kit abusing Microsoft 365 OAuth device-code sign-in to steal tokens and take over accounts in seconds.