Close Menu
Mozbot
    Facebook X (Twitter) Instagram
    Button
    MozbotMozbot
    Facebook X (Twitter) Instagram YouTube
    • About us
    • Technology
    • Gadgets
    • Apps & Software
      • Computing
    • News
    • Contact Us
    • Article Submissions
    Mozbot
    Home » News » Microsoft 365 Passkey Phishing Campaign Tied to ShinyHunters and Helix Gangs
    Technology

    Microsoft 365 Passkey Phishing Campaign Tied to ShinyHunters and Helix Gangs

    Gary BehanBy Gary Behan19/09/2026No Comments4 Mins Read
    Facebook Twitter Pinterest LinkedIn Reddit WhatsApp Email
    Microsoft 365 passkey phishing
    Share
    Facebook Twitter Pinterest Reddit WhatsApp Email

    Microsoft has detailed a Microsoft 365 passkey phishing campaign active since May 2026, in which threat actors impersonate corporate IT help desks to trick employees into handing over session tokens and credentials, with ShinyHunters, Helix, and related extortion groups identified as participants.

    The attacks begin well before any phone call or message is sent. According to Microsoft, the actors invest heavily in pre-attack research, gathering information about employees and organisational structure from public sources such as social networking and professional profiling platforms. Once they have enough to sound plausible, they contact targets directly (by phone or message) claiming that a passkey, multi-factor authentication (MFA), or single sign-on (SSO) configuration must be updated urgently to avoid losing access to corporate systems.

    Passkey Lures, AiTM Sites and Device-Code Tricks

    Despite the passkey-themed pretexts, Microsoft is clear that the attackers are not actually trying to enrol a passkey. The lures serve a different purpose: pushing victims toward adversary-in-the-middle (AiTM) phishing sites that mimic Microsoft login pages, or into device-code authentication flows. AiTM attacks let the threat actors capture both credentials and session tokens in real time. Device-code phishing takes a different route, convincing victims to enter a supplied code into Microsoft’s legitimate authentication page, which issues an authentication token to an attacker-controlled OAuth application, bypassing any further MFA challenge entirely.

    The phishing infrastructure is purpose-built. Microsoft 365 passkey phishing domains observed include passkeyhelpdesk[.]com, secure-passkey[.]com, setupmypasskey[.]com, integratedsso[.]com, and oktasession[.]com, among others. Attackers commonly place the victim company’s name in a subdomain, for example, company-name.secure-passkey[.]com, to make the portal appear more convincing. Links are sometimes delivered via SMS to employees’ personal phones, sidestepping corporate email filtering.

    Microsoft attributes the initial-access activity to multiple threat actors it tracks as Storm-3121 and Storm-3032. Storm-3121 is associated with ShinyHunters and Falcon extortion, while Storm-3032 is believed to be tied to BlackFile extortion group members now operating under the Helix name. The activity overlaps with attacks previously documented by Google Threat Intelligence under the UNC6671 threat cluster, which Google has linked to the same extortion ecosystem, including BlackFile, Helix, Falcon, Pink, and Redact.

    Inside the Microsoft Cloud After Compromise

    Microsoft’s research maps out what happens once an account falls. In one investigated intrusion, a suspicious sign-in from an unmanaged device to a Microsoft 365 service appeared in Entra logs. After completing MFA, the attacker established a valid session and within minutes began checking what resources the compromised account could access, moving through My Apps, My Profile, Microsoft Approval Management, account-management interfaces, and My Sign-Ins, before progressing to SharePoint Online, Outlook Web, and collaboration services. The session remained active for approximately one hour while the attacker listed sensitive files and internal applications.

    In a third investigated attack, the threat actors performed reconnaissance using an automated Node.js system and Microsoft Graph after gaining access via previously compromised credentials. Graph requests covering organisations, users, groups, directory roles, OAuth permissions, SharePoint sites, OneDrive resources, and mail folders were all observed. Microsoft notes that individual Graph requests such as /users or /groups are common in enterprise environments and may not trigger alerts, the pattern becomes suspicious when the same account rapidly moves across different resource types, checks privileges and authentication settings, and then begins accessing email and files.

    After reconnaissance, the attackers pivot to data collection. Microsoft observed high-volume access and download activity targeting SharePoint Online and OneDrive for Business, with some intrusions extending into Exchange Online through REST API-based access to email content. The exfiltration does not follow a smash-and-grab pattern: threat actors access fewer than 1,000 files or emails in a single hour to blend in with legitimate traffic, and the activity can stretch from a few hours to multiple days. Connections during SharePoint and OneDrive exfiltration used the python-httpx user agent.

    Persistence is established by registering MFA methods the attackers control, new phone numbers, authenticator applications, or software-based one-time password tokens added to compromised identities. Microsoft notes that this persistence does not survive a complete credential and session reset, which remains the recommended remediation step alongside revoking active sessions, removing attacker-added authentication methods or mailbox rules, and requiring re-registration of authentication methods.

    Defensive Steps Microsoft Recommends

    On the prevention side, Microsoft recommends using phishing-resistant MFA, limiting sensitive cloud resources to managed devices, and disabling device-code authentication where it is not needed. Security teams should watch for unusual sign-ins followed by new MFA registrations, Microsoft Graph reconnaissance activity, and suspicious access patterns across Salesforce, SharePoint, OneDrive, or Exchange, services that connected SSO accounts can expose once a single Microsoft 365 passkey phishing attack succeeds.

    Share. Facebook Twitter Pinterest LinkedIn WhatsApp Reddit Email
    Previous ArticleAI Platform Malware Attacks Exploit Claude, ChatGPT and Grok User Trust
    Gary Behan

    Software engineer and video game uber-nerd.

    Related Posts

    AI Platform Malware Attacks Exploit Claude, ChatGPT and Grok User Trust

    19/09/2026

    GitLab path traversal flaw rated maximum severity gets emergency patch

    19/09/2026

    Trezor Brevo phishing attack hit 347,000 inboxes via SAML exploit

    18/09/2026

    Mantax Otax Android malware blends ransomware and spyware to harass victims into paying

    18/09/2026

    PaperCut AI Exploitation Campaign Breached 395 Organisations Across 48 Countries

    18/09/2026

    KB5124008 patches Windows 11 mouse settings reset caused by August update

    17/09/2026
    Add A Comment

    Comments are closed.

    Categories
    • Apps & Software
    • Artificial Intelligence
    • Business
    • Computing
    • Education
    • Energy
    • Featured
    • Finance
    • Gadgets
    • Gaming
    • Health and Safety
    • Home
    • Lifestyle
    • Marketing
    • Medical
    • News
    • NFT
    • Opinions
    • Social
    • Technology
    • Travel & Tourism
    Mozbot
    Facebook X (Twitter) Instagram Pinterest
    © 2026 M0ZBOT. All Rights Reserved.

    Type above and press Enter to search. Press Esc to cancel.