hacker-news · Crawled Jul 10, 2026

Hackers Use Fake Microsoft Entra Passkey Enrollment to Gain Microsoft 365 Access

1 IoCs 3 Actors
Read original article ↗

AI Summary

A threat actor tracked as O-UNC-066 is conducting vishing attacks to trick Microsoft 365 users into enrolling attacker-controlled passkeys through a phishing kit that mimics the legitimate Microsoft Entra passkey enrollment process. The attackers register domains with 'passkey' in the name and use voice calls to socially engineer victims into following a fake enrollment flow, ultimately granting unauthorized access to their accounts. The phishing kit is operator-controlled and adapts in real time to the victim's MFA method, allowing the attacker to capture credentials and approve passkey registration. This campaign targets multiple industries and abuses Microsoft's passkey adoption initiative as a social engineering lure.

AI-extracted · verify before operational use

Extracted Entities 3 found

Indicators of Compromise 1 extracted

Type Value Detail
Domain passkey Details →

MITRE ATT&CK TTPs 170 techniques

T1003 OS Credential Dumping · Credential Access T1005 Data from Local System · Collection T1021 Remote Services · Lateral Movement T1021.001 Remote Desktop Protocol · Lateral Movement T1021.002 SMB/Windows Admin Shares · Lateral Movement T1021.003 Distributed Component Object Model · Lateral Movement T1021.004 SSH · Lateral Movement T1021.005 VNC · Lateral Movement T1021.006 Windows Remote Management · Lateral Movement T1021.007 Cloud Services · Lateral Movement T1021.008 Direct Cloud VM Connections · Lateral Movement T1021.009 T1021.009 T1021.010 T1021.010 T1021.011 T1021.011 T1021.012 T1021.012 T1021.013 T1021.013 T1021.014 T1021.014 T1021.015 T1021.015 T1021.016 T1021.016 T1021.017 T1021.017 T1021.018 T1021.018 T1021.019 T1021.019 T1021.020 T1021.020 T1021.021 T1021.021 T1021.022 T1021.022 T1021.023 T1021.023 T1021.024 T1021.024 T1021.025 T1021.025 T1021.026 T1021.026 T1021.027 T1021.027 T1021.028 T1021.028 T1021.029 T1021.029 T1021.030 T1021.030 T1021.031 T1021.031 T1021.032 T1021.032 T1021.033 T1021.033 T1021.034 T1021.034 T1021.035 T1021.035 T1021.036 T1021.036 T1021.037 T1021.037 T1021.038 T1021.038 T1021.039 T1021.039 T1021.040 T1021.040 T1021.041 T1021.041 T1021.042 T1021.042 T1021.043 T1021.043 T1021.044 T1021.044 T1021.045 T1021.045 T1021.046 T1021.046 T1021.047 T1021.047 T1021.048 T1021.048 T1021.049 T1021.049 T1021.050 T1021.050 T1021.051 T1021.051 T1021.052 T1021.052 T1021.053 T1021.053 T1021.054 T1021.054 T1021.055 T1021.055 T1021.056 T1021.056 T1021.057 T1021.057 T1021.058 T1021.058 T1021.059 T1021.059 T1021.060 T1021.060 T1021.061 T1021.061 T1021.062 T1021.062 T1021.063 T1021.063 T1021.064 T1021.064 T1021.065 T1021.065 T1021.066 T1021.066 T1021.067 T1021.067 T1021.068 T1021.068 T1021.069 T1021.069 T1021.070 T1021.070 T1021.071 T1021.071 T1021.072 T1021.072 T1021.073 T1021.073 T1021.074 T1021.074 T1021.075 T1021.075 T1021.076 T1021.076 T1021.077 T1021.077 T1021.078 T1021.078 T1021.079 T1021.079 T1021.080 T1021.080 T1021.081 T1021.081 T1021.082 T1021.082 T1021.083 T1021.083 T1021.084 T1021.084 T1021.085 T1021.085 T1021.086 T1021.086 T1021.087 T1021.087 T1021.088 T1021.088 T1021.089 T1021.089 T1021.090 T1021.090 T1021.091 T1021.091 T1021.092 T1021.092 T1021.093 T1021.093 T1021.094 T1021.094 T1021.095 T1021.095 T1021.096 T1021.096 T1021.097 T1021.097 T1021.098 T1021.098 T1021.099 T1021.099 T1021.100 T1021.100 T1027 Obfuscated Files or Information · Defense Evasion T1027.002 Software Packing · Defense Evasion T1048 Exfiltration Over Alternative Protocol · Exfiltration T1053.005 Scheduled Task · Execution T1055 Process Injection · Defense Evasion T1055.012 Process Hollowing · Defense Evasion T1056.001 Keylogging · Collection T1059.001 PowerShell · Execution T1059.005 Visual Basic · Execution T1070.004 File Deletion · Defense Evasion T1071 Application Layer Protocol · Command And Control T1071.001 Web Protocols · Command And Control T1071.002 File Transfer Protocols · Command And Control T1071.003 Mail Protocols · Command And Control T1071.004 DNS · Command And Control T1078 Valid Accounts · Defense Evasion T1082 System Information Discovery · Discovery T1085 T1085 T1090 Proxy · Command And Control T1095 Non-Application Layer Protocol · Command And Control T1102 Web Service · Command And Control T1105 Ingress Tool Transfer · Command And Control T1114.001 Local Email Collection · Collection T1133 External Remote Services · Persistence T1202 Indirect Command Execution · Defense Evasion T1484.001 Group Policy Modification · Defense Evasion T1484.002 Trust Modification · Defense Evasion T1489 Service Stop · Impact T1496 Resource Hijacking · Impact T1548 Abuse Elevation Control Mechanism · Privilege Escalation T1558.003 Kerberoasting · Credential Access T1566 Phishing · Initial Access T1566.002 Spearphishing Link · Initial Access T1003.002 Security Account Manager · Credential Access T1020 Automated Exfiltration · Exfiltration T1056.002 GUI Input Capture · Collection T1078.002 Domain Accounts · Defense Evasion T1078.004 Cloud Accounts · Defense Evasion T1083 File and Directory Discovery · Discovery T1098 Account Manipulation · Persistence T1110 Brute Force · Credential Access T1113 Screen Capture · Collection T1114 Email Collection · Collection T1120 Peripheral Device Discovery · Discovery T1132 Data Encoding · Command And Control T1190 Exploit Public-Facing Application · Initial Access T1192 T1192 T1195.002 Compromise Software Supply Chain · Initial Access T1204.002 Malicious File · Execution T1210 Exploitation of Remote Services · Lateral Movement T1212 Exploitation for Credential Access · Credential Access T1213 Data from Information Repositories · Collection T1400 T1400 T1485 Data Destruction · Impact T1490 Inhibit System Recovery · Impact T1491 Defacement · Impact T1499 Endpoint Denial of Service · Impact T1530 Data from Cloud Storage · Collection T1542 Pre-OS Boot · Defense Evasion T1543.003 Windows Service · Persistence T1557 Adversary-in-the-Middle · Credential Access T1558 Steal or Forge Kerberos Tickets · Credential Access T1566.001 Spearphishing Attachment · Initial Access T1573 Encrypted Channel · Command And Control T1588.001 Malware · Resource Development T1595 Active Scanning · Reconnaissance T1659 Content Injection · Initial Access