news.mlab.sh
Back to the feed
threat-intel

Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data

High
Summary

Microsoft has uncovered two campaigns where threat actors are leveraging email delivery infrastructure and passkey-themed social engineering to breach cloud environments and steal data. The first campaign involved sending sophisticated scam emails impersonating CEOs to trick accounts payable departments into initiating ACH transfers, utilizing AI to craft convincing narratives and forged invoices. The second campaign involves cloud intrusions using compromised identities, adding their own authentication methods, and exploiting Microsoft Graph activity to gain persistent access and exfiltrate data. These activities are linked to a loose-knit cybercrime collective known as Cordial Spider, O-UNC-045, PREY-0058, and UNC6671, and are associated with threat actors like Storm-3121 and Storm-3032.

Microsoft has disclosed details of two campaigns in which threat actors are abusing third-party email delivery infrastructure to blast financial fraud scam messages and using passkey-themed social engineering to breach cloud environments. The first campaign involved sending over a million scam emails between August 3 and 5, 2026, masquerading as CEOs of various target companies, aiming to persuade accounts payable departments at those firms to initiate Automated Clearing House (ACH) transfers for a supposed ServiceNow annual subscription. Evidence indicates that the operators behind the campaign have leveraged generative artificial intelligence (AI) to facilitate the creation of email templates and draft emails tailored to their recipients. The activity primarily singled out enterprise users in the U.S., spanning IT services, consumer goods, real estate, and discrete manufacturing sectors.

"The campaign follows steps before and during the execution of the campaign: threat actors register impersonation domains, send executive-themed payment requests through trusted infrastructure, embed fabricated invoices and supporting conversations, and attempt to convince finance personnel to initiate ACH transfers," the Microsoft Security Research team said. "Unlike traditional invoice scams that rely on a single social engineering lure, this campaign layered executive impersonation, vendor branding, fabricated invoices, and supporting email conversations into a unified narrative intended to reduce recipient skepticism."

The spoofed email messages contained a purported "approval" of the fake invoice to trick recipients into making payments to attacker-controlled accounts. To lend a veneer of legitimacy to the deception, the threat actor included a forged email thread along with the fabricated invoice.

In a clever twist, the attackers identified CEOs, CFOs, and presidents at victim organizations and plugged their names and email addresses into the emails' signatures so that they look convincing to the targets. The campaign also heavily relied on bogus domains and content designed to impersonate trusted brands and individuals. Some of the registered domains are below:

  • service-nowinc[.]com
  • domainlify[.]net

Passkey-Themed Social Engineering Leads to Cloud Compromise The second campaign documented by Redmond revolves around cloud-based intrusions targeting multiple accounts in which suspicious sign-ins are followed by the threat actors adding their own authentication methods, as well as high-volume Microsoft Graph activity, SharePoint and OneDrive downloads, and mailbox collection through REST APIs. The activity, which has been detected since May 2026, is consistent with "automated collection from compromised cloud identities using proxy-associated infrastructure," Microsoft said.

The attack commonly begins with identity-focused social engineering. The threat actors call or message a user's personal phone number, while claiming to be from the organization's IT help desk and urging them to immediately update their passkey, multi-factor authentication (MFA), or single sign-on (SSO) configuration to avoid access disruptions. Unsuspecting employees are redirected to counterfeit websites that mimic the legitimate Microsoft sign-in experience via SMS messages sent to their personal devices. The end goal here is to use the pretext to guide them through adversary-in-the-middle (AitM) or device-code authentication flows and take control of their Microsoft accounts either by capturing the credentials or unknowingly granting access on the actor's behalf.

"UNC6671 uses credential harvesting panels hosted on generic root domains masquerading as being related to passkeys, appending victim-specific subdomains to facilitate targeted voice phishing campaigns," noted last month.

It's worth noting that this modus operandi overlaps with a loose-knit cybercrime collective tracked by the cybersecurity community under the monikers Cordial Spider, O-UNC-045, PREY-0058, and UNC6671. The e-crime adversary has been described as a coordinated group of threat actors that operates multiple public extortion brands while sharing overlaps in the underlying phishing infrastructure and targeting footprint.

"UNC6671 uses credential harvesting panels hosted on generic root domains masquerading as being related to passkeys, appending victim-specific subdomains to facilitate targeted voice phishing campaigns," noted last month.

Microsoft, for its part, has attributed the initial access activity observed in this campaign to a range of threat actors, including Storm-3121 and Storm-3032. While Storm-3121 carries out initial access activity leading to ShinyHunters and Falcon (aka CL-CRI-1182) extortion, Storm-3032 is its designation for UNC6671, which refers to a set of actors that broke off from the BlackFile (aka CL-CRI-1116) group and now operate under the Helix extortion brand.

In at least one case investigated by Microsoft, the threat actors are said to have carried out an anomalous sign-in to Microsoft Office Home from an unmanaged device to expand their access to other applications like SharePoint Online and OneDrive through the Graph API and enumerate sensitive files and internal services.

Another incident involved the use of a passkey lure to launch a device code phishing attack and gain control of a victim's account without having to steal their credentials or cookies, effectively getting around MFA safeguards. The third attack pattern detected by Microsoft employs compromised credentials, likely obtained from a prior event, to register their own phone-based method to bypass MFA and engage in reconnaissance and post-exploitation activity.

"Following initial access, the actor's first objective was to transform a temporary compromise into a persistent foothold," the Windows maker said. "Rather than relying solely on stolen credentials, the actor enrolled an MFA method under their control, typically by registering a new phone number, authenticator application, or software-based one-time password (OTP) token." The various actions the threat actor can take upon establishing MFA persistence are as follows:

  • Conduct extensive internal reconnaissance using the Graph API and inventory users, groups, permissions, resources, and accessible content across the tenant using the compromised identity.
  • Inspect roles and high-value accounts and service identities for privilege escalation.
  • Enumerate mailbox messages, folders, and attachment metadata for intelligence collection.
  • Conduct high-volume access and download activity aimed at SharePoint Online and OneDrive for Business, and even Microsoft Exchange Online in some cases.
  • Deliberately rotate infrastructure across the attack lifecycle and use separate IP addresses for authentication, reconnaissance, and exfiltration activities so as to subvert network-based indicators.

"The attack underscores a critical detection challenge: Microsoft Graph abuse rarely appears suspicious when viewed through a single API call," Microsoft said. "This attack serves as a strong example of why Graph activity must be assessed holistically, with emphasis on behavioral progression and cross-event correlation rather than individual API requests in isolation."

Read the full article at The Hacker News