The campaign targets employees via phone calls or messages from individuals impersonating corporate IT help desks, Microsoft said in newly published research. Victims are told they must urgently update a passkey, multi-factor authentication (MFA), or single sign-on (SSO) configuration to avoid losing access to corporate systems.
Attackers direct employees to phishing sites designed to resemble legitimate Microsoft login pages, with links sometimes sent via SMS to personal phones. While the lures revolve around passkeys, Microsoft noted that the attackers are not attempting to actually enroll a passkey. Instead, victims are tricked into signing in to adversary-in-the-middle (AiTM) phishing sites or using device-code authentication flows, allowing threat actors to capture credentials and session tokens.
Microsoft attributed the activity to multiple threat actors operating in the same extortion ecosystem, including groups tracked as Storm-3121 and Storm-3032. Storm-3121 is associated with ShinyHunters and Falcon extortion, while Storm-3032 is tied to members of the BlackFile extortion group that now operates under the Helix name.
Google Threat Intelligence has previously documented similar activity under the UNC6671 threat cluster, linking it to the same extortion gangs including BlackFile, Helix, Falcon, Pink, and Redact.
According to Microsoft, threat actors invest heavily in pre-attack research, gathering information from public sources such as social networking and professional profiling platforms. They register phishing domains that combine company names with words related to passkeys, SSO, key synchronization, and identity verification. Examples observed include passkeyhelpdesk[.]com, secure-passkey[.]com, and setupmypasskey[.]com. Attackers often place the victim company's name in a subdomain to make the portal appear more convincing.
Once inside a compromised account, Microsoft researchers documented the attackers mapping the environment, enumerating SharePoint sites, identifying privileged accounts, and accessing Azure infrastructure. The research detailed how attackers searched for sensitive data, including financial documents, intellectual property, and credentials stored in documents and configuration files. In some cases, threat actors attempted to set up email forwarding rules and establish persistence by creating new service principals with high privileges.