New Phishing Attacks Target Microsoft Cloud Passkey Users

New Phishing Attacks Target Microsoft Cloud Passkey Users

By integrating generative AI to craft professional communications, attackers are successfully bypassing traditional defenses and exfiltrating massive quantities of corporate data from SharePoint and OneDrive for Business. As the global enterprise landscape rapidly shifts toward passwordless authentication, the Microsoft Cloud ecosystem has become a primary staging ground for these high-sophistication campaigns. Security researchers have observed a concerning trend where the very protocols designed to eliminate credential theft, such as passkeys and Entra ID integration, are being leveraged as psychological lures to deceive employees. These campaigns do not merely aim for temporary access but seek to establish deep persistence within an organization’s digital infrastructure. By mimicking legitimate administrative workflows, threat actors exploit the inherent trust that users place in IT-mandated security updates, creating a dangerous paradox where increased security measures provide new avenues for compromise.

Exploiting the Enrollment Gap and Technical Flows

The current wave of attacks relies heavily on the enrollment gap, which represents the transitional period during which an organization educates its workforce on adopting new security protocols like passkeys. Attackers capitalize on this uncertainty by deploying social engineering tactics that include voice phishing and SMS-based lures, often impersonating corporate helpdesk technicians. These actors guide unsuspecting victims through what appears to be a standard security enrollment process, leveraging the urgency of compliance to bypass critical thinking. To bolster the illusion of legitimacy, the fraudulent sites often utilize typosquatted domains that incorporate the victim’s specific company name, making the URL look like an official internal resource. This strategy effectively neutralizes traditional awareness training by presenting a scenario that closely mirrors legitimate, recurring organizational changes in the modern cloud environment.

Technically, these campaigns utilize sophisticated Adversary-in-the-Middle architectures to intercept authentication flows in real-time. By acting as a transparent proxy between the user and the legitimate Microsoft login service, the phishing infrastructure captures not only the user’s credentials but also the session tokens required to bypass multi-factor authentication. This method allows attackers to maintain an active session even if the user has technically satisfied the security requirements. Another prevalent technique involves device code abuse, where a victim is tricked into entering a verification code on a legitimate Microsoft page, which unknowingly authorizes an attacker-controlled device to access the account. Once the initial access is secured, the attackers immediately utilize the Microsoft Graph API to perform automated reconnaissance, mapping the target’s organizational structure and identifying high-value file repositories across the cloud.

Threat Actor Profiles and Sophisticated AI Integration

The digital forensics associated with these campaigns point toward two highly organized e-crime collectives identified as Storm-3121 and Storm-3032. Storm-3121 is frequently linked to broader extortion operations involving brands like ShinyHunters and Falcon, specializing in high-impact data exfiltration for financial gain through double-extortion schemes. In parallel, Storm-3032, which recently rebranded as Helix following an internal restructuring from its previous BlackFile identity, continues to demonstrate elite levels of technical adaptability. Both groups have pioneered the use of generative AI to eliminate the grammatical errors and awkward phrasing that once characterized phishing attempts, creating impeccably professional communications. Their ability to rotate infrastructure rapidly ensures that their operations remain resilient against static blocklists, while their deep understanding of Microsoft’s cloud-native tools allows them to navigate enterprise environments with surgical precision.

Beyond individual skill sets, these threat actors operate within a collaborative ecosystem where advanced phishing kits and reconnaissance playbooks are shared across various dark web forums. This collective intelligence allows even smaller groups to execute attacks that were previously the domain of state-sponsored actors. The integration of generative AI specifically enables the mass production of personalized lures, allowing attackers to scale their operations without sacrificing the quality of the deception. By analyzing publicly available data about an organization’s internal structure, AI can draft messages that use the specific terminology, tone, and formatting unique to that company’s internal culture. This level of customization makes it nearly impossible for traditional email security gateways to flag the messages based on linguistic anomalies. Consequently, the combination of professional extortion experience and cutting-edge automation has created a threat that is exceptionally difficult to detect.

Lateral Movement and Internal Communication Hijacking

A single compromised account often serves as a tactical beachhead for wider organizational infiltration through lateral movement. Attackers have demonstrated a preference for hijacking Microsoft Teams sessions to distribute malicious lures internally, exploiting the high degree of trust that colleagues naturally extend to one another. Because these messages originate from a legitimate internal account, they bypass traditional external email filters and are far more likely to be acted upon by other employees. This internal infection vector allows threat actors to move horizontally across departments, eventually gaining access to accounts with administrative privileges or those belonging to high-ranking executives. Once deeper access is established, the actors register their own multi-factor authentication methods, such as secondary authenticator apps or phone numbers, ensuring that they maintain persistent access even if the original victim’s password is changed or their initial session token is revoked by the IT department.

This automated discovery process is significantly faster and more thorough than manual exploration, allowing the actors to move from initial compromise to data identification in a matter of minutes. The Microsoft Graph API allows for the programmatic querying of user lists, group memberships, and document permissions, providing the threat actor with a comprehensive blueprint of the internal network. By identifying users with privileged access, such as global administrators or financial officers, the attackers can focus their efforts on the most sensitive data streams. This use of legitimate developer tools for malicious purposes highlights the difficulty of distinguishing between standard administrative activity and a sophisticated breach, requiring a more nuanced approach to cloud monitoring. The speed at which these tools operate means that traditional incident response timelines are often insufficient to prevent the initial stages of reconnaissance from completing successfully.

Automated Data Exfiltration and Infrastructure Rotation

The final stage of the attack lifecycle involves the systematic and high-speed exfiltration of corporate intellectual property using automated scripting tools. Attackers frequently employ the python-httpx user agent to facilitate the rapid download of thousands of files from SharePoint Online and OneDrive for Business in an extremely short timeframe. To evade detection by security operations centers that monitor for impossible travel or unusual login volumes, these groups implement a strategy of functional infrastructure fragmentation. They utilize distinct sets of IP addresses for different phases of the attack: one pool for the initial credential capture, another for the Graph API-based reconnaissance, and a third for the actual data theft. This separation makes it incredibly difficult for automated defense systems to correlate the disparate activities into a single, cohesive threat incident, allowing the attackers to strip an organization of its sensitive data before an alert is ever triggered.

By rotating these exit nodes frequently, they circumvent reputation-based filtering systems that rely on historical threat data. This methodical approach to infrastructure management demonstrates a high level of operational security, mirroring the techniques used by advanced persistent threat actors rather than typical opportunistic phishers. Each functional node is often hosted in a different geographic region or on a different cloud provider, which further complicates the efforts of forensic analysts to piece together the full scope of the breach. This level of technical discipline ensures that even if one part of the attack infrastructure is identified and blocked, the other components remain viable for future operations. The use of automated scripts to manage these downloads ensures that the exfiltration process is not only fast but also highly consistent, reducing the likelihood of human error that could otherwise lead to early detection by behavioral monitoring tools.

Geographic Targets and Defensive Resilience Strategies

Since the middle of 2026, the focus of these passkey-themed campaigns has been predominantly concentrated on organizations within the United States. While no specific sector is completely immune, the threat actors have shown a calculated preference for industries that possess high-value intellectual property or critical supply chain data, including discrete manufacturing, real estate, and professional services. The targeting of administrative and executive accounts remains a priority, yet the actors are increasingly opportunistic, using any entry point to facilitate further movement within the cloud environment. This selective targeting suggests that the attackers are not merely seeking random data but are conducting detailed reconnaissance to maximize the potential ransom or resale value of the stolen information. The concentration on these specific sectors highlights a strategic shift toward quality over quantity in modern cybercrime as actors refine their ability to identify and exploit lucrative targets.

The evolution of passkey-themed phishing necessitated a fundamental shift in how enterprises approached identity protection within the Microsoft Cloud ecosystem. It became clear that the most effective defenses involved a combination of phishing-resistant hardware keys and rigorous auditing of all authentication health indicators. Security leaders prioritized the implementation of automated alerts for any modification to user multi-factor authentication profiles, treating such changes as high-severity events that required immediate verification. Additionally, user resilience training was updated to reflect the sophisticated nature of AI-generated lures, teaching employees to verify IT requests through secondary, out-of-band communication channels. By moving beyond a reliance on single security features and toward a comprehensive strategy of identity lifecycle management, organizations successfully mitigated the risks posed by automated data exfiltration. These proactive steps ensured that the transition to a passwordless environment delivered security.

Subscribe to our weekly news digest.

Join now and become a part of our fast-growing community.

Invalid Email Address
Thanks for Subscribing!
We'll be sending you our best soon!
Something went wrong, please try again later