Vishing Campaign Exploits Passkeys to Hijack Microsoft 365

Jul 20, 2026
Guide
Vishing Campaign Exploits Passkeys to Hijack Microsoft 365

Traditional security perimeters crumble when a confident voice on the telephone convinces an employee to surrender the keys to the entire corporate kingdom through a process they barely understand. This shift from automated, bot-driven phishing to sophisticated, human-led vishing campaigns represents a significant escalation in the cyber threat landscape. The threat group tracked as O-UNC-066, also known as Pink, has refined this approach to target critical infrastructure sectors including healthcare, technology, and aviation. By exploiting the very technologies designed to protect modern enterprises, these adversaries demonstrate that human trust remains the most vulnerable entry point.

The movement toward passwordless authentication and the implementation of Microsoft Entra ID were supposed to render credential theft obsolete. However, the current campaign highlights how these frameworks can become a double-edged sword when users are unfamiliar with the underlying registration mechanics. Attackers have successfully pivoted from harvesting static passwords to manipulating the identity registration process itself. This transition allows them to bypass phishing-resistant multi-factor authentication by inserting their own controlled devices into the victim’s security profile.

The Rise of Real-Time Social Engineering Against Microsoft 365

Modern attackers no longer rely solely on static fake login pages that might be caught by automated email filters or browser protections. Instead, they utilize direct voice communication to establish a sense of urgency and professional rapport with their targets. This manual intervention allows the threat actor to guide the victim through complex technical steps that would otherwise be ignored. The goal is no longer just a temporary session token but the establishment of a permanent foothold within the organizational tenant.

Furthermore, the focus on high-value industries like healthcare and aviation suggests a strategic intent beyond simple financial theft. These sectors often maintain high-pressure environments where employees are conditioned to cooperate with IT support to maintain operational continuity. By hijacking active sessions and registering unauthorized devices, O-UNC-066 creates a persistent threat that remains long after a single password change might have resolved a traditional breach.

Understanding the Fragility of Modern Authentication Frameworks

As organizations adopt passkeys to eliminate the risks associated with traditional passwords, a new knowledge gap has emerged. Users understand the concept of a login but often fail to grasp the technical implications of adding a new authentication device to their Entra ID account. This lack of awareness provides a perfect cover for adversaries who frame the registration of an unauthorized passkey as a routine security update or a necessary recovery procedure.

The significance of this tactical pivot cannot be overstated, as it marks the end of the era where multi-factor authentication was a silver bullet. When an attacker can convince a user to authorize a new device in real-time, the technical strength of the cryptographic key becomes irrelevant. This campaign demonstrates that the move toward a passwordless environment requires a parallel investment in user literacy regarding identity management workflows.

Deconstructing the Multi-Stage O-UNC-066 Attack Chain

1. Establishing Trust Through Professional Voice Phishing

The operation begins with a highly personalized phone call where the attacker poses as a member of the corporate IT help desk or a security administrator. By using internal jargon and referencing specific organizational structures, the caller lowers the victim’s defenses and builds a foundation of professional trust. This stage is critical because it sets the emotional tone of the interaction, making the employee feel as though they are assisting in a vital security task.

Targeting Vulnerabilities in Employee Psychology and IT Support Norms

Attackers exploit the psychological tendency to comply with authoritative requests, especially those framed as urgent security interventions. In many corporate cultures, questioning an IT professional is discouraged, which creates a permissive environment for social engineering. The vishing agent monitors the victim’s reactions in real-time, adjusting their script to overcome hesitation or confusion before it leads to suspicion.

2. Directing Victims to Dynamic Attacker-Controlled Panels

Once trust is established, the victim is directed to a customized phishing site that meticulously mirrors legitimate Microsoft branding to maintain the illusion of safety. These sites are not static; they are managed by a manual PHP operator who observes the victim’s progress and triggers specific prompts based on the account’s unique requirements. This allows the attacker to intercept various forms of multi-factor authentication, such as SMS codes or push notifications, as they occur.

Bypassing Automated Defenses Through Manual PHP Operator Intervention

The use of a human-controlled backend panel ensures that the attack can adapt to any security challenge presented by the Microsoft 365 environment. If the system requests a specific TOTP token, the operator manually updates the phishing page to ask for that exact information. This real-time interaction effectively neutralizes automated security triggers that might flag suspicious, high-velocity login attempts from unknown bots.

3. Exploiting Passkey Registration for Persistent Access

The most dangerous phase involves the victim unknowingly authorizing the attacker’s device as a legitimate passkey for their account. The attacker provides instructions that lead the user through the Entra ID device registration portal while the operator initiates the pairing process on their end. Because the victim believes they are securing their own account, they willingly approve the cryptographic handshake that links the attacker’s hardware to their corporate identity.

Utilizing Crypto-Themed Recovery Phrases as a Tactical Distraction

To keep the victim occupied and prevent them from questioning the technical steps, the attackers often introduce irrelevant concepts like BIP-39 recovery phrases. These twelve-word sequences, commonly used in cryptocurrency wallets, serve as a highly effective distraction while the real passkey registration happens in the background. The victim spends several minutes carefully recording these useless phrases, believing they are performing a high-level security backup.

Concealing Unauthorized Devices with Benign Labels to Prevent Detection

Even when Microsoft sends automated email notifications regarding a new passkey registration, the attackers take steps to minimize alarm. They frequently label their registered devices with names like “Work Phone” or “Security Key 1” to blend in with legitimate hardware. By the time the user or an administrator reviews the account settings, the unauthorized device appears to be a standard part of the employee’s technical profile.

Key Characteristics of the Vishing Campaign

This campaign is defined by its reliance on human interaction and the use of direct voice communication to bypass technical barriers. Unlike traditional phishing, this method prioritizes quality over quantity, targeting specific high-value individuals with tailored scripts. The real-time adaptation of the phishing panels ensures that the attacker stays one step ahead of the multi-factor authentication challenges presented by the Microsoft ecosystem.

Persistence is the ultimate goal, achieved through the registration of unauthorized attacker devices that provide long-term access without requiring recurring passwords. The use of misdirection, particularly the inclusion of cryptocurrency-themed recovery phrases, highlights the attacker’s understanding of modern technical trends and user psychology. These methods combined allow the O-UNC-066 group to maintain a low-profile presence within a compromised network for extended periods.

Broader Consequences for Enterprise Security Strategies

The success of these vishing tactics challenges the widespread reliance on purely technical MFA controls as a primary defense mechanism. Security leaders must recognize that no matter how strong the encryption is, it can be bypassed if the user is manipulated into granting access. This trend toward data extortion over traditional ransomware indicates a shift in adversary goals, where persistent identity access is more valuable than locking local files.

Furthermore, the evolution of these attacks suggests that securing identity-first architectures will require a focus on human-in-the-loop security. As adversaries become more adept at manipulating real-time user behavior, the industry must rethink how it validates device registration and identity changes. The challenge lies in balancing user convenience with the need for rigorous verification during critical account modifications.

Strategic Recommendations for Neutralizing Advanced Vishing Threats

Organizations implemented updated training programs that specifically addressed the mechanics of passkey registration and the dangers of voice-based social engineering. Security teams reviewed their Microsoft Entra ID notification settings to ensure that both users and administrators received immediate, clear alerts when new authentication methods were added. Stricter policies were established for the registration of new devices, often requiring a secondary out-of-band verification before a passkey could be finalized.

Leadership reflected on the balance between seamless user experience and the inherent risks of a passwordless environment. They concluded that while technical controls remained essential, the most effective defense involved empowering employees to recognize and report suspicious IT-themed interactions. By fostering a culture of healthy skepticism, companies successfully reduced the success rate of vishing campaigns that relied on the exploitation of human trust.

Trending

Subscribe to Newsletter

Stay informed about the latest news, developments, and solutions in data security and management.

Invalid Email Address
Invalid Email Address

We'll Be Sending You Our Best Soon

You’re all set to receive our content directly in your inbox.

Something went wrong, please try again later

Subscribe to Newsletter

Stay informed about the latest news, developments, and solutions in data security and management.

Invalid Email Address
Invalid Email Address

We'll Be Sending You Our Best Soon

You’re all set to receive our content directly in your inbox.

Something went wrong, please try again later