Illustration of a digital lock and key with cloud icons, symbolizing passkey phishing and cloud account compromise in cybersecurity.

Beyond Passkeys: Unmasking Sophisticated Phishing Campaigns Targeting Microsoft Cloud Users

Share
Share
Pinterest Hidden

In a stark warning to enterprises worldwide, Microsoft has revealed intricate details of two sophisticated cyber campaigns actively exploiting third-party email infrastructure and leveraging advanced social engineering tactics to breach cloud environments and exfiltrate sensitive data. These attacks highlight an escalating threat landscape where traditional defenses are increasingly challenged by highly organized and adaptive adversaries.

The Deceptive Art of Financial Fraud: CEO Impersonation and AI

The first campaign, a masterclass in financial deception, saw threat actors unleash over a million scam emails within a mere three days (August 3-5, 2026). Masquerading as chief executive officers (CEOs) of target companies, these attackers meticulously crafted messages aimed at persuading accounts payable departments to initiate fraudulent Automated Clearing House (ACH) transfers. The pretext? A bogus ServiceNow annual subscription.

AI-Powered Persuasion and Layered Lures

What sets this campaign apart is the evident use of generative artificial intelligence (AI). Microsoft’s research indicates AI was instrumental in creating highly convincing email templates and drafting personalized messages, significantly enhancing the campaign’s efficacy. Targeting enterprise users primarily in the U.S. across IT services, consumer goods, real estate, and manufacturing, the attackers employed a multi-layered social engineering approach.

“Unlike traditional invoice scams that rely on a single social engineering lure, this campaign layered executive impersonation, vendor branding, fabricated invoices, and supporting email conversations into a unified narrative intended to reduce recipient skepticism,” explained the Microsoft Security Research team. The spoofed emails even included a fabricated “approval” of the fake invoice, complete with forged email threads and signatures of actual CEOs, CFOs, and presidents from the victim organizations, lending an unsettling veneer of legitimacy. Bogus domains like service-nowinc[.]com and domainlify[.]net further cemented the illusion.

Passkey Phishing: A Direct Assault on Cloud Identities

The second, equally alarming campaign documented by Redmond focuses on direct cloud-based intrusions. Detected since May 2026, this activity involves suspicious sign-ins followed by threat actors adding their own authentication methods, engaging in high-volume Microsoft Graph activity, downloading data from SharePoint and OneDrive, and collecting mailbox contents via REST APIs. This pattern is consistent with “automated collection from compromised cloud identities using proxy-associated infrastructure.”

Adversary-in-the-Middle (AitM) and Device-Code Flows

The initial breach often stems from identity-focused social engineering. Attackers contact users via personal phone numbers, posing as IT help desk personnel. They urgently instruct victims to update their passkey, multi-factor authentication (MFA), or single sign-on (SSO) configurations to prevent “access disruptions.” Unsuspecting employees are then redirected via SMS to counterfeit websites that meticulously mimic the legitimate Microsoft sign-in experience. The ultimate goal is to guide victims through adversary-in-the-middle (AitM) or device-code authentication flows, either capturing their credentials directly or tricking them into unknowingly granting access on the attacker’s behalf.

Microsoft noted, “The actor appears to invest heavily in pre-attack research, likely gathering information about employees and organizational structure from public sources such as social networking and professional profiling platforms.” In some instances, already compromised accounts are leveraged to broaden the attack surface, with similar passkey-themed messages disseminated through Microsoft Teams. The threat actors also register deceptive domains incorporating target organization names, such as passkeyhelpdesk[.]com, secure-passkey[.]com, and integratedsso[.]com.

Connecting the Dots: The Cordial Spider Collective

Intriguingly, this modus operandi bears a striking resemblance to a notorious cybercrime collective known by various monikers, including Cordial Spider, O-UNC-045, PREY-0058, and UNC6671. This coordinated group of threat actors is recognized for operating multiple public extortion brands, sharing common phishing infrastructure and targeting strategies. Their use of credential harvesting panels hosted on generic root domains, designed to appear legitimate, further solidifies this connection.

Protecting Your Digital Fortress

These campaigns underscore the critical need for robust cybersecurity measures. Organizations must prioritize comprehensive employee training on identifying sophisticated phishing and social engineering attempts, particularly those involving executive impersonation or urgent IT requests. Implementing strong multi-factor authentication, regularly auditing cloud access, and deploying advanced threat detection systems are paramount to safeguarding against such evolving and persistent threats. Staying vigilant and informed is the first line of defense in the ongoing battle against cyber adversaries.


For more details, visit our website.

Source: Link

Share

Leave a comment

Leave a Reply

Your email address will not be published. Required fields are marked *