AUTO-UPDATED

Hackers Use Fake Microsoft Entra Passkey Enrollment to Gain Microsoft 365 Access

A threat actor identified as O-UNC-066 is targeting Microsoft 365 users with voice-based phishing attacks designed to trick employees into registering attacker-controlled passkeys for unauthorized account access.

Key Points

  • The threat actor, O-UNC-066, uses "vishing" calls to persuade employees to register fake passkeys under the guise of security updates.
  • Phishing kits mimic the legitimate Microsoft 365 passkey enrollment process to capture credentials and multi-factor authentication tokens in real-time.
  • Targeted sectors include healthcare, technology, aviation, construction, automotive, and food and beverage industries.
  • The attack chain uses a distraction mechanism involving a 12-word recovery phrase to keep victims occupied while the attacker gains account access.
  • Researchers link this activity to the cybercrime collective known as The Com, which also includes groups like Scattered Spider and LAPSUS$.

Why it Matters

This campaign exploits the industry-wide transition toward passwordless authentication by weaponizing user unfamiliarity with new security protocols. By successfully enrolling their own passkeys, attackers gain persistent, high-level access to corporate environments, significantly increasing the risk of large-scale data extortion.
Internet Published by info@thehackernews.com (The Hacker News)
Read original