Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data
AI Summary
Microsoft identified two distinct attack campaigns targeting enterprise cloud environments. The first involved a large-scale phishing campaign using CEO impersonation and AI-generated content to trick finance teams into executing fraudulent ACH transfers. The second, more technically sophisticated campaign used social engineering around passkey and MFA updates to compromise Microsoft cloud identities, enabling persistent access through adversary-in-the-middle attacks and abuse of Microsoft Graph API for reconnaissance and data exfiltration. The activity is attributed to multiple threat actor groups, including Storm-3121 and Storm-3032 (UNC6671), with infrastructure linked to known cybercrime collectives.
AI-extracted · verify before operational use
Extracted Entities 2 found
Indicators of Compromise 10 extracted
| Type | Value | Detail |
|---|---|---|
| Domain | service-nowinc[.]com | Details → |
| Domain | domainlify[.]net | Details → |
| Domain | passkeyhelpdesk[.]com | Details → |
| Domain | secure-passkey[.]com | Details → |
| Domain | setupmypasskey[.]com | Details → |
| Domain | add-passkey[.]com | Details → |
| Domain | integratedsso[.]com | Details → |
| Domain | oktasession[.]com | Details → |
| Domain | syncmykey[.]com | Details → |
| Domain | portalsetuphub[.]com | Details → |