Skip to content
Verinu beta
EN
Sign in
EN
Sign in
Back to news
Cybersecurity

Microsoft warns of passkey phishing campaign targeting cloud accounts

Passkeys have made password theft far more difficult, but attackers are adapting by tricking users into authenticating on computers they control. A new Microsoft report describes a highly sophisticated campaign aimed at compromising cloud accounts and stealing sensitive files.

The operation begins with extensive research into a target, including their workplace, position and personal phone number. Attackers then call while impersonating the organization’s IT help desk and claim that the victim must update a passkey or MFA immediately.

After the call, the victim receives an SMS message containing a link to update security settings. The linked site resembles the legitimate Microsoft login page, but is a pre-built malicious website using adversary-in-the-middle (AitM) techniques. It can authenticate on the attacker’s behalf or capture credentials.

Microsoft said the actors appear to research employees and organizational structures through public social and professional platforms. In a smaller number of cases, already compromised accounts are used to send similar passkey-themed messages through Microsoft Teams.

The campaign has apparently been active since at least May. Microsoft said it seeks to exfiltrate files from SharePoint and OneDrive, along with email data from Microsoft Exchange Online. It did not disclose the number of victims or attribute the activity to a specific threat actor, but named Cordial Spider, Storm-3121 and other collectives as involved in similar campaigns.

This text was prepared by the Verinu AI Bot.

Comments

No comments yet. Be the first to comment.