Microsoft has disclosed details of two campaigns in which threat actors are abusing third-party email delivery infrastructure to blast financial fraud scam messages and using passkey-themed social engineering to breach cloud environments. The first campaign, per the tech giant, involved sending over a million scam emails between August 3 and 5, 2026, by masquerading as chief executive officers (CEOs) of various target companies, aiming to persuade accounts payable departments at those firms to initiate Automated Clearing House (ACH) transfers for a supposed ServiceNow annual subscription. Evidence indicates that the operators behind the campaign have leveraged generative artificial intelligence (AI) to facilitate the creation of email templates and draft emails tailored to their recipients. The activity primarily singled out enterprise users in the U.S., spanning IT services, consumer goods, real estate, and discrete manufacturing sectors. "The campaign follows steps before and during the execution of the campaign: threat actors register impersonation domains, send executive-themed payment requests through trusted infrastructure, embed fabricated invoices and supporting conversations, and attempt to convince finance personnel to initiate ACH transfers," the Microsoft Security Research team said. "Unlike traditional invoice scams that rely on a single social engineering lure, this campaign layered executive impersonation, vendor branding, fabricated invoices, and supporting email conversations into a unified narrative intended to reduce recipient skepticism." The spoofed email messages contained a purported "approval" of the fake invoice to trick recipients into making payments to attacker-controlled accounts. To lend a veneer of legitimacy to the deception, the threat actor included a forged email thread along with the fabricated invoice. In a clever twist, the attackers identified CEOs, CFOs, and presidents at victim organizations and plugged their names and email addresses into the emails' signatures so that they look convincing to the targets. The campaign also heavily relied on bogus domains and content designed to impersonate trusted brands and individuals. Some of the registered domains are below - service-nowinc[.]com domainlify[.]net Passkey-Themed Social Engineering Leads to Cloud Compromise The second campaign documented by Redmond revolves around cloud-based intrusions targeting multiple accounts in which suspicious sign-ins are followed by the threat actors adding their own authentication methods, as well as high-volume Microsoft Graph activity, SharePoint and OneDrive downloads, and mailbox collection through REST APIs. The activity, which has been detected since May 2026, is consistent with "automated collection from compromised cloud identities using proxy-associated infrastructure," Microsoft said. The attack commonly begins with identity-focused social engineering. The threat actors call or message a user's personal phone number, while claiming to be from the organization's IT help desk and urging them to immediately update their passkey, multi-factor authentication (MFA), or single sign-on (SSO) configuration to avoid access disruptions. Unsuspecting employees are redirected to counterfeit websites that mimic the legitimate Microsoft sign-in experience via SMS messages sent to their personal devices. The end goal here is to use the pretext to guide them through adversary-in-the-middle (AitM) or device-code authentication flows and take control of their Microsoft accounts either by capturing the credentials or unknowingly granting access on the actor's behalf. "The actor appears to invest heavily in pre-attack research, likely gathering information about employees and organizational structure from public sources such as social networking and professional profiling platforms," Microsoft said. "In a smaller number of cases, actors take advantage of already compromised accounts to expand their reach" by sending similar passkey-themed messages via Microsoft Teams. What's more, the threat actor has been observed registering domains built around themes such as passkeys, SSO enrollment, account activation, and identity verification, at the same time including the target organization's name as a subdomain in the pattern: ".[.]com" - passkeyhelpdesk[.]com secure-passkey[.]com setupmypasskey[.]com add-passkey[.]com integratedsso[.]com oktasession[.]com syncmykey[.]com portalsetuphub[.]com It's worth noting that this modus operandi overlaps with a loose-knit cybercrime collective tracked by the cybersecurity community under the monikers Cordial Spider, O-UNC-045, PREY-0058, and UNC6671. The e-crime adversary has been described as a coordinated group of threat actors that operates multiple public extortion brands while sharing overlaps in the underlying phishing infrastructure and targeting footprint. "UNC6671 uses credential harvesting panels hosted on generic root domains masquerading as being related to passkeys, appending victim-specific subdomains to facilitate targeted voice phishing campaigns," noted last month. Although the exact nature of these connections is unclear, it's suspected that they have been driven by splintered affiliates retaining access to shared initial access playbooks or relying on the same commoditized phishing panels, voice-phishing callers, and shared infrastructure. Microsoft, for its part, has attributed the initial access activity observed in this campaign to a range of threat actors, including Storm-3121 and Storm-3032. While Storm-3121 carries out initial access activity leading to ShinyHunters and Falcon (aka CL-CRI-1182) extortion, Storm-3032 is its designation for UNC6671, which refers to a set of actors that broke off from the BlackFile (aka CL-CRI-1116) group and now operate under the Helix extortion brand. In at least one case investigated by Microsoft, the threat actors are said to have carried out an anomalous sign-in to Microsoft Office Home from an unmanaged device to expand their access to other applications like SharePoint Online and OneDrive through the Graph API and enumerate sensitive files and internal services. Another incident involved the use of a passkey lure to launch a device code phishing attack and gain control of a victim's account without having to steal their credentials or cookies, effectively getting around MFA safeguards. The third attack pattern detected by Microsoft employs compromised credentials, likely obtained from a prior event, to register their own phone-based method to bypass MFA and engage in reconnaissance and post-exploitation activity. "Following initial access, the actor's first objective was to transform a temporary compromise into a persistent foothold," the Windows maker said. "Rather than relying solely on stolen credentials, the actor enrolled an MFA method under their control, typically by registering a new phone number, authenticator application, or software-based one-time password (OTP) token." An advantage this actor-controlled second factor offers is that it allows the threat actor to sign-in into the victim's corporate account without their participation and maintain continued access in combination with unrevoked sessions or valid credentials. The various actions the threat actor can take upon establishing MFA persistence are as follows - Conduct extensive internal reconnaissance using the Graph API and inventory users, groups, permissions, resources, and accessible content across the tenant using the compromised identity. Inspect roles and high-value accounts and service identities for privilege escalation. Enumerate mailbox messages, folders, and attachment metadata for intelligence collection. Conduct high-volume access and download activity aimed at SharePoint Online and OneDrive for Business, and even Microsoft Exchange Online in some cases. Engage in sustained data exfiltration that lasts from several hours to multiple days depending on the volume of files and email content harvested from the compromised user. Deliberately rotate infrastructure across the attack lifecycle and use separate IP addresses for authentication, reconnaissance, and exfiltration activities so as to subvert network-based indicators. "The attack underscores a critical detection challenge: Microsoft Graph abuse rarely appears suspicious when viewed through a single API call," Microsoft said. "This attack serves as a strong example of why Graph activity must be assessed holistically, with emphasis on behavioral progression and cross-event correlation rather than individual API requests in isolation." Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data
Full Article
Original Source
Read the full article at Thehackernews →KhanList aggregates and links to publicly available news content. We do not host full articles from third-party sources. Always verify important information with original sources.