news.mlab.sh
Back to the feed
threat-intel

Okta Warns of Vishing Attacks Targeting Microsoft 365 Customers

High
Summary

Okta has warned of a sophisticated vishing campaign targeting Microsoft 365 customers, primarily through impersonating legitimate Microsoft Entra ID login pages. The campaign, attributed to the O-UNC-066 threat actor group (also known as CL-CRI-1147 and Pink), involves tricking users into registering attacker-controlled passkeys within their Microsoft accounts, leveraging a custom phishing kit that mimics the passkey enrollment process and adapts to MFA requirements. The goal is likely data extortion.

Read the full article at SecurityWeek

Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data

Report an error
Confirmed errors are fixed and listed on /corrections.