Storm Groups Unleash Passkey Phishing Campaigns on Microsoft Cloud Accounts
Passkey phishing attacks have escalated in recent months, targeting Microsoft Cloud accounts, including Microsoft 365 and Azure Active Directory. These campaigns exploit passwordless authentication and multi-factor authentication (MFA) by using social engineering, adversary-in-the-middle (AiTM) phishing, and device code abuse.
Attackers can hijack user identities, establish persistent access, and exfiltrate sensitive corporate data at scale. The sophistication of these attacks, including rapid infrastructure rotation and the abuse of legitimate authentication flows, presents a formidable challenge to traditional detection and response mechanisms.
The primary actors behind these campaigns are Storm-3121 and Storm-3032, both linked to high-impact extortion and data theft operations. These groups use highly targeted reconnaissance, generative AI for crafting convincing lures, and the rapid adaptation of new authentication technologies such as passkeys and device code flows.
Organizations should implement a multi-layered defense strategy to mitigate the risk posed by passkey phishing campaigns. Key recommendations include enforcing strong MFA policies, monitoring for changes to authentication methods, and restricting access from unmanaged devices and unfamiliar locations.