Okta Sounds Alarm on Sophisticated Vishing Attacks Targeting Microsoft 365 Users
A wave of highly targeted and sophisticated vishing attacks is currently sweeping through various industries, with threat actors aiming to harvest sensitive information from unsuspecting Microsoft 365 users. The campaign, which kicked off in April, has been linked to a hacking group known as O-UNC-066, also tracked as CL-CRI-1147 and ‘Pink’. What’s alarming is the level of customization and sophistication involved in these attacks, making it crucial for organizations to take immediate action to protect their users.
The hacking group has been targeting various sectors, including automotive, aviation, construction, food and beverage, healthcare, and technology. The attackers are using voice calls to direct victims to fake Microsoft Entra ID login pages, convincing them that they need to register a new passkey. This is where things get tricky – the threat actor is simultaneously registering their own passkey in the victim’s Microsoft account, often without even collecting sensitive information like passwords or MFA tokens.
This campaign is notable for its operator-controlled PHP panel, which doesn’t automatically collect user credentials or other sensitive data. Instead, the attackers direct victims through multiple authentication stages in near-real time, adapting the page’s content and notifications to accommodate various multi-factor authentication (MFA) requirements. This highly adaptable nature of the phishing kit makes it extremely difficult for users to detect.
What’s even more concerning is that the attackers use anti-analysis checks on the phishing pages, making it challenging for security researchers to analyze the code without raising suspicions. Moreover, the threat actor can redirect victims to a passkey registration page, where they are asked to save a recovery key from a list of BIP-39 phrases controlled by the attacker.
According to Okta, the attackers may be using this step as a distraction, and the actual goal is to enroll an attacker-controlled passkey in the victim’s account. What’s alarming is that any time a user enrolls a passkey with Microsoft, the owner of the compromised account receives a legitimate email notification – but in an attack scenario, it’s actually the threat actor who has registered the passkey directly with Microsoft.
The takeaway from this campaign is clear: organizations must educate their users about the risks of vishing attacks and ensure that they are aware of the warning signs. Additionally, administrators should take immediate action to strengthen their security posture by implementing robust multi-factor authentication, regularly updating software and plugins, and monitoring user activity for suspicious behavior. By staying vigilant and proactive, we can mitigate the impact of these sophisticated attacks and protect our sensitive information from falling into the wrong hands.
Source: SecurityWeek — 2026-07-10