The point: Attackers control fake passkey registration pages in real time via PHP panel to bypass multi-factor authentication and gain access to Microsoft 365 accounts.
Since April 2026, the group O-UNC-066 (Pink) has conducted coordinated phone calls to persuade Microsoft 365 users to register manipulated passkeys. The attackers exploit a new Microsoft administrative function and subsequently compromise business-critical data.
The attack campaign specifically targets employees in food, technology, healthcare, automotive, construction and aviation companies. The attackers use phone calls in which they pose as security update notifications and request installation of a new passkey. This tactic is based on an administration function released by Microsoft in May that allows IT teams to initiate company-wide passkey registration campaigns.
The phishing kit does not function as an automated proxy, but rather as a PHP panel directly controlled by the attacker with 1-second heartbeat polling. This allows the attacker to control the authentication steps displayed in the victim’s browser in real time and flexibly respond to all common multi-factor procedures – from TOTP apps to push notifications to SMS codes. All data entered by the user is forwarded directly to the attacker, who uses it to authenticate to the compromised Microsoft account.
After successfully gaining access, the fake pages display alleged confirmation screens in Microsoft design with recovery phrases following the BIP-39 cryptography standard. These phrases have no technical function for genuine Entra passkeys, but serve to distract and reinforce the deception. Following the compromise, the attackers copy data from SharePoint and OneDrive to publish it on their own platform for extortion purposes.
Source: www.it-daily.net · Published 10 July 2026
Lumi AI News — AI-assisted curation pursuant to Article 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.