Hackers Use Fake Microsoft Entra Passkey Enrollment to Gain Microsoft 365 Access
AI Summary
A threat actor tracked as O-UNC-066 is conducting vishing attacks to trick Microsoft 365 users into enrolling attacker-controlled passkeys through a phishing kit that mimics the legitimate Microsoft Entra passkey enrollment process. The attackers register domains with 'passkey' in the name and use voice calls to socially engineer victims into following a fake enrollment flow, ultimately granting unauthorized access to their accounts. The phishing kit is operator-controlled and adapts in real time to the victim's MFA method, allowing the attacker to capture credentials and approve passkey registration. This campaign targets multiple industries and abuses Microsoft's passkey adoption initiative as a social engineering lure.
AI-extracted · verify before operational use
Extracted Entities 3 found
Indicators of Compromise 1 extracted
| Type | Value | Detail |
|---|---|---|
| Domain | passkey | Details → |