A threat actor identified as O-UNC-066 is targeting Microsoft 365 users with voice-based phishing attacks designed to trick employees into registering attacker-controlled passkeys for unauthorized account access.
Key Points
- The threat actor, O-UNC-066, uses "vishing" calls to persuade employees to register fake passkeys under the guise of security updates.
- Phishing kits mimic the legitimate Microsoft 365 passkey enrollment process to capture credentials and multi-factor authentication tokens in real-time.
- Targeted sectors include healthcare, technology, aviation, construction, automotive, and food and beverage industries.
- The attack chain uses a distraction mechanism involving a 12-word recovery phrase to keep victims occupied while the attacker gains account access.
- Researchers link this activity to the cybercrime collective known as The Com, which also includes groups like Scattered Spider and LAPSUS$.