Hackers Use Fake Microsoft Entra Passkey Enrollment to Target M365 Users

A threat actor known as O-UNC-066 is using a phishing kit to exploit Microsoft 365 users via fake Entra passkey enrollment requests, aiming at data extortion. This tactic spans multiple industry sectors and involves voice-based social engineering.

Why it matters

This attack targets the Microsoft 365 passkey enrollment process, posing a significant risk to enterprise security and user credentials.

SOC impact

SOC teams should validate exposure, identify affected assets, prioritize remediation, and monitor for exploitation attempts targeting vulnerable systems.

Recommended actions

  1. Identify whether affected products or versions exist in your environment.
  2. Prioritize patching or mitigation based on exploit activity and business criticality.
  3. Review vulnerability scanner results, EDR telemetry, and perimeter logs for exploitation attempts.

Executive Summary

A threat actor known as O-UNC-066 is using a phishing kit to exploit Microsoft 365 users via fake Entra passkey enrollment requests, aiming at data extortion. This tactic spans multiple industry sectors and involves voice-based social engineering. This attack targets the Microsoft 365 passkey enrollment process, posing a significant risk to enterprise security and user credentials.

SOC Impact

SOC teams should validate exposure, identify affected assets, prioritize remediation, and monitor for exploitation attempts targeting vulnerable systems.

What SOC Teams Should Validate

  • Identify whether affected products or versions exist in your environment.
  • Prioritize patching or mitigation based on exploit activity and business criticality.
  • Review vulnerability scanner results, EDR telemetry, and perimeter logs for exploitation attempts.

Why It Matters

This attack targets the Microsoft 365 passkey enrollment process, posing a significant risk to enterprise security and user credentials.

Source