Microsoft has detailed a Microsoft 365 passkey phishing campaign active since May 2026, in which threat actors impersonate corporate IT help desks to trick employees into handing over session tokens and credentials, with ShinyHunters, Helix, and related extortion groups identified as participants.

The attacks begin well before any phone call or message is sent. According to Microsoft, the actors invest heavily in pre-attack research, gathering information about employees and organisational structure from public sources such as social networking and professional profiling platforms. Once they have enough to sound plausible, they contact targets directly (by phone or message) claiming that a passkey, multi-factor authentication (MFA), or single sign-on (SSO) configuration must be updated urgently to avoid losing access to corporate systems.

Passkey Lures, AiTM Sites and Device-Code Tricks

Despite the passkey-themed pretexts, Microsoft is clear that the attackers are not actually trying to enrol a passkey. The lures serve a different purpose: pushing victims toward adversary-in-the-middle (AiTM) phishing sites that mimic Microsoft login pages, or into device-code authentication flows. AiTM attacks let the threat actors capture both credentials and session tokens in real time. Device-code phishing takes a different route, convincing victims to enter a supplied code into Microsoft’s legitimate authentication page, which issues an authentication token to an attacker-controlled OAuth application, bypassing any further MFA challenge entirely.

The phishing infrastructure is purpose-built. Microsoft 365 passkey phishing domains observed include passkeyhelpdesk[.]com, secure-passkey[.]com, setupmypasskey[.]com, integratedsso[.]com, and oktasession[.]com, among others. Attackers commonly place the victim company’s name in a subdomain, for example, company-name.secure-passkey[.]com, to make the portal appear more convincing. Links are sometimes delivered via SMS to employees’ personal phones, sidestepping corporate email filtering.

Microsoft attributes the initial-access activity to multiple threat actors it tracks as Storm-3121 and Storm-3032. Storm-3121 is associated with ShinyHunters and Falcon extortion, while Storm-3032 is believed to be tied to BlackFile extortion group members now operating under the Helix name. The activity overlaps with attacks previously documented by Google Threat Intelligence under the UNC6671 threat cluster, which Google has linked to the same extortion ecosystem, including BlackFile, Helix, Falcon, Pink, and Redact.

Inside the Microsoft Cloud After Compromise

Microsoft’s research maps out what happens once an account falls. In one investigated intrusion, a suspicious sign-in from an unmanaged device to a Microsoft 365 service appeared in Entra logs. After completing MFA, the attacker established a valid session and within minutes began checking what resources the compromised account could access, moving through My Apps, My Profile, Microsoft Approval Management, account-management interfaces, and My Sign-Ins, before progressing to SharePoint Online, Outlook Web, and collaboration services. The session remained active for approximately one hour while the attacker listed sensitive files and internal applications.

In a third investigated attack, the threat actors performed reconnaissance using an automated Node.js system and Microsoft Graph after gaining access via previously compromised credentials. Graph requests covering organisations, users, groups, directory roles, OAuth permissions, SharePoint sites, OneDrive resources, and mail folders were all observed. Microsoft notes that individual Graph requests such as /users or /groups are common in enterprise environments and may not trigger alerts, the pattern becomes suspicious when the same account rapidly moves across different resource types, checks privileges and authentication settings, and then begins accessing email and files.

After reconnaissance, the attackers pivot to data collection. Microsoft observed high-volume access and download activity targeting SharePoint Online and OneDrive for Business, with some intrusions extending into Exchange Online through REST API-based access to email content. The exfiltration does not follow a smash-and-grab pattern: threat actors access fewer than 1,000 files or emails in a single hour to blend in with legitimate traffic, and the activity can stretch from a few hours to multiple days. Connections during SharePoint and OneDrive exfiltration used the python-httpx user agent.

Persistence is established by registering MFA methods the attackers control, new phone numbers, authenticator applications, or software-based one-time password tokens added to compromised identities. Microsoft notes that this persistence does not survive a complete credential and session reset, which remains the recommended remediation step alongside revoking active sessions, removing attacker-added authentication methods or mailbox rules, and requiring re-registration of authentication methods.

Defensive Steps Microsoft Recommends

On the prevention side, Microsoft recommends using phishing-resistant MFA, limiting sensitive cloud resources to managed devices, and disabling device-code authentication where it is not needed. Security teams should watch for unusual sign-ins followed by new MFA registrations, Microsoft Graph reconnaissance activity, and suspicious access patterns across Salesforce, SharePoint, OneDrive, or Exchange, services that connected SSO accounts can expose once a single Microsoft 365 passkey phishing attack succeeds.

Share.

Software engineer and video game uber-nerd.

Comments are closed.

Exit mobile version