Hackers Use Fake Microsoft Entra Passkey Enrollment to Gain Microsoft 365 Access
A threat actor, linked to the O-UNC-066 group (affiliated with The Com/Scattered Spider), is using a sophisticated, operator-controlled phishing kit to trick users into enrolling fake Microsoft Entra passkeys, gaining unauthorized access to Microsoft 365 accounts. The kit mimics the legitimate Microsoft passkey enrollment process, leveraging a voice-based (vishing) scheme to bypass user awareness of passkey authentication and steal credentials for account takeover. The attacker then uses these stolen credentials to register their own passkeys, effectively gaining persistent access to victim organizations’ Microsoft 365 accounts.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
