Source: The Hacker News
Author: info@thehackernews.com (The Hacker News)
URL: https://thehackernews.com/2026/07/hackers-use-fake-microsoft-entra.html
ONE SENTENCE SUMMARY:
O-UNC-066 uses vishing and a panel-driven phishing kit to enroll attacker passkeys in Microsoft 365 accounts for extortion.
MAIN POINTS:
- Okta tracks the threat actor as O-UNC-066 targeting multiple industry sectors.
- Campaign uses voice calls posing as security requests to persuade passkey enrollment.
- Domains containing “passkey” support the vishing-enabled phishing infrastructure.
- Victims are sent to Microsoft-like pages mimicking Entra passkey registration.
- Attack registers an attacker-controlled passkey onto the victim’s Microsoft account.
- Microsoft passkey registration campaigns provide timely pretext for the lure.
- Operator-controlled PHP panel guides victims through steps in near real time.
- MFA flows are adapted dynamically: TOTP, push number matching, or SMS OTP.
- Stolen credentials and OTPs are POSTed to an operator endpoint at /backend.php.
- Passkey “recovery key” seed phrase distracts users while attacker finalizes access.
TAKEAWAYS:
- Vishing plus realistic enrollment pages can bypass “phishing-resistant” narratives via social engineering.
- Real-time operator control enables tailored MFA prompting and higher takeover success rates.
- User unfamiliarity with passkeys is exploited by omitting genuine device passkey dialogs.
- Monitoring for suspicious passkey registrations can be as critical as credential-theft detection.
- Attribution links activity to Pink leak operations and The Com ecosystem (Unit 42: CL-CRI-1147).