Phishing Attacks Use Fake Passkeys to Compromise Cloud Accounts
Microsoft researchers have discovered a social engineering campaign where attackers are impersonating IT help desks and using fake passkey setup requests to compromise employee identities and gain access to enterprise cloud data.
The attacks, which began in May 2023, involve phone calls or messages sent to employees' personal phones, claiming that a passkey, multifactor authentication (MFA), or single sign-on configuration needs to be updated to avoid disruption.
Victims are then directed to a website designed to resemble a legitimate Microsoft sign-in experience, where they are asked to enroll in a passkey. However, the attackers' actual objective is not to defeat the technology but to convince employees that they need help setting it up, thereby gaining their trust and compromising their identities.
The attackers then use this access to capture credentials and session tokens through adversary-in-the-middle attacks or trick victims into authorizing access for an attacker-controlled client using device-code phishing. This allows them to persist in the compromised account and eventually access mail, files, attachments, and other document content.