BlackTree Security · Infrastructure · Automation · AI

The Helpdesk Asked You to Upgrade Your Passkey. Then the Quiet Download Began.

The caller says your passkey must be upgraded before access stops working. The story sounds technical, urgent and helpful. It is also the first step in a cloud intrusion that can end with files and email leaving Microsoft 365 for days.

Microsoft says it has tracked the activity across multiple compromised accounts since May 2026. Attackers contact employees through personal mobile phones, impersonate the organisation’s IT helpdesk and use passkey, multi-factor authentication or single sign-on maintenance as the pretext.

The attackers are not generally breaking passkey cryptography. They are persuading users to complete an adversary-in-the-middle sign-in or a device-code flow, then turning the resulting session into persistent access, reconnaissance and controlled cloud collection.

The passkey was the story, not the target

A victim may receive a call or text on a personal number and be sent to a site that resembles Microsoft’s sign-in experience. In an adversary-in-the-middle flow, the attacker captures credentials and session tokens. In a device-code attack, the victim enters a code on Microsoft’s legitimate page and unknowingly authorises an attacker-controlled client.

The passkey theme makes the request timely as organisations migrate away from SMS and voice factors. BlackTree previously examined why Microsoft’s passkey transition turns every authentication exception into risk. This campaign exploits the operational change itself as social proof.

Microsoft observed attackers registering target-specific subdomains under generic domains, using names such as passkey setup, key synchronisation and SSO enrolment. In some cases, an already compromised employee account sent the lure through Microsoft Teams, adding the credibility of an internal identity.

One captured session becomes a durable identity foothold

After access, the actor often adds a phone number, authenticator application or software one-time-password token to the compromised identity. That new method lets the attacker satisfy future challenges without asking the victim again.

The added method is not invincible persistence. A complete credential reset, session revocation and authentication-method cleanup can remove it. It is durable enough to survive a response that only changes the password.

Microsoft also saw previously registered attacker-controlled methods used days after an earlier compromise. That gap means responders must review the history of authentication changes, not only events around the latest suspicious sign-in.

Graph requests look normal until the sequence is visible

The next phase uses Microsoft Graph to inventory the tenant. The actor queries users, groups, roles, registered authentication methods, applications, service principals, OAuth grants, SharePoint sites, OneDrive repositories and mailbox resources.

Any one of those requests can be legitimate. The signal emerges when the same identity, token or application crosses several categories in a short period, then starts opening files, attachments or message content.

Microsoft says attackers rotate infrastructure between authentication, reconnaissance and collection. A defender looking for one malicious IP can miss the relationship between stages. The identity and its behavioural progression are the more reliable thread.

The theft stayed below a dramatic rate

Microsoft observed high-volume access across SharePoint, OneDrive and Exchange, including automated collection associated with the python-httpx user agent. The operations were often measured rather than explosive.

The actors generally accessed fewer than 1,000 files or emails in any one-hour period. Collection continued for several hours or multiple days. That pace can still remove a large amount of information while avoiding the simple alert that looks only for a sudden download spike.

Microsoft associates parts of the initial-access ecosystem with Storm-3121, whose activity can lead to ShinyHunters and Falcon extortion, and Storm-3032, which represents operators now using the Helix extortion name. The techniques are not exclusive to one group, and a matching domain or infrastructure provider is not sufficient attribution.

The personal phone creates an evidence gap

When the lure arrives on a personal mobile device outside endpoint management, the organisation may have no record of the call, text or phishing page. Microsoft says the employee’s recollection can become the earliest and sometimes only evidence explaining how the cloud compromise began.

That changes incident interviews. A suspicious Entra sign-in should prompt questions about personal calls, text messages and urgent requests from supposed IT staff, even when the corporate endpoint shows nothing.

What defenders should do now

  • Review newly registered authentication methods after risky or unusual sign-ins and validate each change with the user.
  • Correlate authentication events with Microsoft Graph reconnaissance, SharePoint and OneDrive downloads, Exchange REST activity and attachment searches.
  • Investigate sustained collection rates, not only one-hour bursts. A controlled pace can still represent major exfiltration.
  • For confirmed compromise, revoke active sessions and refresh tokens, reset credentials, remove attacker-added authentication methods and delete malicious mailbox rules.
  • Require managed, compliant devices for sensitive Microsoft 365 and Graph access where operationally possible.
  • Use phishing-resistant authentication, but train users that attackers may use passkey language as a pretext for a different sign-in flow.
  • Give the helpdesk a clear, verifiable process for authentication changes so employees can distinguish a real migration request from an unsolicited call.

The BlackTree view

Passkeys remain one of the strongest practical defences against credential phishing. This campaign does not reverse that conclusion. It demonstrates that attackers can borrow the language of a stronger control while steering the victim into a weaker authorisation path.

The lasting lesson is to monitor identity as a sequence. The phone call, token, new MFA method, Graph reconnaissance and slow download are one incident. Separate tools may record each step as ordinary. The attack succeeds in the gaps between them.

Sources

Leave a Reply

Your email address will not be published. Required fields are marked *