Search This Blog

Powered by Blogger.

Blog Archive

Labels

Footer About

Footer About

Labels

Okta Uncovers Vishing Campaign Using Fake Microsoft Entra ID Pages to Hijack Microsoft 365 Accounts

To support the campaign, the attackers have registered multiple domains containing the word "passkey".

 

Okta has identified a sophisticated vishing campaign targeting organizations across multiple industries, where attackers attempt to steal Microsoft 365 credentials by directing victims to fraudulent Microsoft Entra ID login pages.

The campaign, which began in April, uses voice calls to persuade employees that they need to register a new passkey for their Microsoft account. Victims are then guided to convincing fake Microsoft Entra ID pages designed to capture their credentials.

The threat activity, tracked as O-UNC-066 and also referred to as CL-CRI-1147 or Pink, has primarily targeted organizations in the automotive, aviation, construction, food and beverage, healthcare, and technology sectors. The group's primary objective appears to be data extortion.

To support the campaign, the attackers have registered multiple domains containing the word "passkey" and created phishing pages that closely imitate Microsoft's legitimate passkey enrollment experience.

“It appears engineered to convince a targeted user they are in the process of enrolling a passkey with Microsoft, while the threat actor simultaneously registers their own passkey in the targeted user’s Microsoft account,” Okta says.

According to Okta, the fake Microsoft Entra ID login portals are customized for each intended victim through the phishing kit's backend. These pages incorporate authentic Microsoft branding and even load content directly from Microsoft's content delivery network to appear legitimate.

Unlike conventional phishing kits that automatically harvest usernames, passwords, MFA tokens, and session cookies, this toolkit relies on a manually operated PHP control panel. The attacker actively interacts with victims in real time, adjusting the phishing pages throughout the authentication process to accommodate different multi-factor authentication methods.

“It is likely that the threat actor uses the kit to take over the user account and trick the user into approving an attacker-initiated registration of a passkey,” Okta notes.

Throughout the attack sequence, the phishing pages conduct anti-analysis checks, collect usernames without redirecting users to federated identity providers, and prompt victims to enter their passwords. The attackers are believed to use these credentials immediately to access the targeted Microsoft account.

After the initial login, victims are shown a processing screen while the attacker determines which MFA method is enabled, such as SMS one-time passwords, time-based one-time passwords (TOTP), or push notifications, and modifies the phishing flow accordingly.

As part of the deception, victims are eventually redirected to a fake passkey registration page. There, they are instructed to save a recovery key generated from a list of attacker-controlled BIP-39 seed phrases before verifying the final word in the phrase.

“The phishing kit appears to prey on the lack of user familiarity with passkey authentication. In a real passkey registration ceremony, the user might expect a system dialog to register a passkey on their device. The passkey pages in this phishing kit appear to mimic this process without registering a passkey,” Okta notes.

Okta points out that BIP-39 seed phrases have no apparent role in Microsoft Entra passkey registration, suggesting that this step is merely a distraction while attackers secretly enroll their own passkeys into compromised accounts.

The company also highlighted that Microsoft automatically sends legitimate email notifications whenever a new passkey is registered. However, because the attackers complete the enrollment directly with Microsoft, they can assign the passkey an innocent-looking name, reducing the likelihood of raising suspicion.

“Any time a user enrolls a passkey with Microsoft, the owner of the compromised account receives a legitimate Microsoft email to notify them that a new passkey has been registered in their account. During an attack, the passkey was actually enrolled by the threat actor directly with Microsoft, and the threat actor is in a position to name the passkey with something the targeted user would view as benign,” Okta explains.
Share it:

Cyber Fraud

Microsoft 365

Microsoft Entra ID

Okta

passkey phishing

phishing campaign

vishing attack