Hackers Use Fake Microsoft Entra Passkey Enrollment to Gain Microsoft 365 Access
Hackers are using fake Microsoft Entra passkey enrollment to gain Microsoft 365 access. A threat actor has been targeting organizations with voice-based fake security requests, prompting users to enroll a new Entra passkey.
Intelligence analysis by Llama

Hackers are using a phishing kit to trick users into enrolling a new Entra passkey, which grants them unauthorized access to Microsoft 365 accounts. The threat actor is using a voice-enabled phishing scheme to target users, who are then directed to a phishing kit that mimics the Microsoft passkey enrollment process.
Hackers are tricking people into giving them access to their Microsoft 365 accounts by pretending to be Microsoft and asking them to enroll a new passkey. They are using a fake website that looks like the real Microsoft website to get people to give them their account information.
Analysis
A New Tactic in the Making
The threat actor, tracked by Okta under the moniker O-UNC-066, has been targeting organizations spanning multiple sectors with voice-based fake security requests. The goal is to prompt Microsoft 365 users to enroll a new Entra passkey, which would grant the threat actor unauthorized access to the account.
How the Phishing Kit Works
The phishing kit used in these attacks is an operator-controlled PHP panel. The victim is guided through the passkey enrollment process in almost real-time, with the operator controlling and adjusting the user experience to each victim's MFA requirements. The kit is designed to take over the victim account and trick the user into approving an attacker-initiated registration of a passkey.
The Attack Chain
The attack chain begins with the threat actor registering domains that incorporate the word 'passkey' as part of a voice-enabled phishing scheme. The threat actor then calls targeted users on the phone, attempting to persuade them that they need to register a new passkey. The user is then directed to a phishing kit that mimics the Microsoft passkey enrollment process, giving the impression that they are adding a passkey with Microsoft. However, in reality, the threat actor registers their own passkey against the user's Microsoft account, granting them unauthorized access.
A Distraction Mechanism
The phishing kit appears to prey on lack of user familiarity with passkey authentication. In a real passkey registration ceremony, the user might expect a system dialog to register a passkey on their device. The passkey pages in this phishing kit appear to mimic this process without registering a passkey. The step is assessed to be a distraction mechanism to keep the victim occupied with the task while the threat actor enrolls their own passkey in the Microsoft account.
Key points
- Hackers are using fake Microsoft Entra passkey enrollment to gain Microsoft 365 access.
- The threat actor is using a voice-enabled phishing scheme to target users.
- The phishing kit is designed to take over the victim account and trick the user into approving an attacker-initiated registration of a passkey.
- The attack chain begins with the threat actor registering domains that incorporate the word 'passkey' as part of a voice-enabled phishing scheme.
- The phishing kit appears to prey on lack of user familiarity with passkey authentication.
If this development is addressed promptly, Microsoft can take steps to prevent similar attacks in the future. This could include implementing additional security measures to prevent phishing kits from mimicking the Microsoft passkey enrollment process.
The threat actor may continue to use this tactic, adapting and improving the phishing kit to evade detection. This could lead to a significant number of Microsoft 365 accounts being compromised, resulting in data extortion attacks.



