Overview
- Security researchers say the campaign has been active since April and uses voice calls that impersonate IT to push employees to a fake Entra passkey enrollment site.
- Operators steer victims through an operator-controlled PHP phishing panel that polls every second and adapts to each user’s MFA method, such as TOTP, push notifications, or SMS one-time codes.
- Victims think they are creating a passkey but the attackers relay credentials and MFA responses in real time to register a passkey the attacker controls and take over the Microsoft account.
- After takeover the actors rapidly search SharePoint and OneDrive for sensitive files, publish stolen samples on an extortion site, and use compromised accounts to send ransom messages.
- Researchers warn organizations to verify any unsolicited helpdesk calls, monitor unusual passkey registrations and account activity, and restrict passkey enrollment nudges where possible.