bleeping-computer · Crawled Jul 8, 2026

Entra passkey enrollment vishing targets Microsoft 365 users

1 IoCs
Read original article ↗

AI Summary

A threat actor tracked as O-UNC-066, associated with the Pink extortion gang, is conducting vishing attacks to trick Microsoft 365 users into enrolling Entra passkeys under the attacker's control. The campaign uses voice phishing and phishing kits that mimic legitimate Microsoft enrollment pages, enabling real-time credential and MFA interception. The attacker exploits a new Microsoft passkey registration feature and uses fake BIP-39 recovery phrases to distract victims while stealing credentials. Post-compromise, the actor exfiltrates data from SharePoint and OneDrive to support extortion efforts.

AI-extracted · verify before operational use

Indicators of Compromise 1 extracted

Type Value Detail
Domain passkey Details →