Hackers Use Fake Microsoft Entra Passkey Enrollment to Gain Microsoft 365 Access

Source: The Hacker News

Author: info@thehackernews.com (The Hacker News)

URL: https://thehackernews.com/2026/07/hackers-use-fake-microsoft-entra.html

ONE SENTENCE SUMMARY:

O-UNC-066 uses vishing and a panel-driven phishing kit to enroll attacker passkeys in Microsoft 365 accounts for extortion.

MAIN POINTS:

  1. Okta tracks the threat actor as O-UNC-066 targeting multiple industry sectors.
  2. Campaign uses voice calls posing as security requests to persuade passkey enrollment.
  3. Domains containing “passkey” support the vishing-enabled phishing infrastructure.
  4. Victims are sent to Microsoft-like pages mimicking Entra passkey registration.
  5. Attack registers an attacker-controlled passkey onto the victim’s Microsoft account.
  6. Microsoft passkey registration campaigns provide timely pretext for the lure.
  7. Operator-controlled PHP panel guides victims through steps in near real time.
  8. MFA flows are adapted dynamically: TOTP, push number matching, or SMS OTP.
  9. Stolen credentials and OTPs are POSTed to an operator endpoint at /backend.php.
  10. Passkey “recovery key” seed phrase distracts users while attacker finalizes access.

TAKEAWAYS:

  1. Vishing plus realistic enrollment pages can bypass “phishing-resistant” narratives via social engineering.
  2. Real-time operator control enables tailored MFA prompting and higher takeover success rates.
  3. User unfamiliarity with passkeys is exploited by omitting genuine device passkey dialogs.
  4. Monitoring for suspicious passkey registrations can be as critical as credential-theft detection.
  5. Attribution links activity to Pink leak operations and The Com ecosystem (Unit 42: CL-CRI-1147).