Attackers Use Passkey-Themed Phishing to Breach Cloud Environments
ID: 33bd1ba4-d56d-5bb3-835a-d67e8f417329
STIX ID: report--33bd1ba4-d56d-5bb3-835a-d67e8f417329
Feed Name: KnowBe4 Blog
Researchers at Microsoft report a coordinated social engineering campaign where attackers impersonate IT helpdesk staff and use passkey/MFA-themed pretexts to trick users into visiting phishing sites or approving device-code flows; the goal is to intercept device codes and session tokens (AiTM and device-code attacks) to obtain persistent access to accounts and cloud environments. Attacks are highly personalized, phone-based, leave little forensic evidence, and are attributed to actors tied to extortion groups.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
