Microsoft Warns of Sophisticated Passkey Phishing Campaign Targeting Cloud Accounts
Microsoft says attackers posing as IT help desk staff are using phone calls, SMS links and adversary-in-the-middle sites to steal cloud accounts and files from SharePoint, OneDrive and Exchange Online.
The attack begins with extensive pre-attack research, Microsoft said. Threat actors gather information about targets, including their workplace, position and personal phone number, to make the impersonation convincing. Microsoft said the actor appears to invest heavily in pre-attack research, likely collecting details about employees and organizational structure from public sources such as social networking and professional profiling platforms.
Once that preparation is complete, victims receive a phone call from someone claiming to be their organization's IT help desk. The caller tells them they need to update their passkey, or multifactor authentication setting depending on the setup, immediately to avoid disruption to their operations. After the call, victims receive an SMS message with a link to update their security configuration.
The link leads to a website that looks like Microsoft's legitimate login landing page. In reality, Microsoft said, it is a pre-built malicious site that uses adversary-in-the-middle techniques. Those techniques can allow attackers to obtain access on the actor's behalf or capture credentials. The campaign therefore seeks to bypass the security benefits of passkeys, which have made stealing passwords less useful, by tricking users into authenticating on systems controlled by the attacker.
Microsoft also described a smaller number of cases in which attackers use already compromised accounts to expand their reach. In those cases, the actors send similar passkey-themed messages through Microsoft Teams. The report said the campaign's apparent goal is to exfiltrate files from SharePoint and OneDrive as well as email data from Microsoft Exchange Online.
Microsoft did not name a single threat actor as responsible. It said many collectives are engaged in such or similar campaigns, including Cordial Spider and Storm-3121. The company advised organizations to use phishing-resistant multifactor authentication. The warning underscores a shift in attack methods as passkeys and other passwordless technologies become more common: rather than simply stealing passwords, attackers are trying to fool users into authenticating on attacker-controlled computers.
TechRadar reported that passkeys have made stealing passwords obsolete, prompting hackers to adapt. Microsoft's report says the campaign remains ongoing, and the company did not provide a victim count.
Editor's Summary
Microsoft is warning about an ongoing passkey phishing campaign that impersonates IT help desks, sends SMS links to fake Microsoft login pages and uses adversary-in-the-middle techniques to compromise cloud accounts. The attackers have targeted files in SharePoint and OneDrive and email in Exchange Online since at least May, though Microsoft has not disclosed victim numbers or attributed the campaign to one group. The company advises phishing-resistant MFA.