top of page

Vishing campaign targets Microsoft 365 users

A sophisticated voice phishing (vishing) campaign is directly targeting Microsoft 365 users. Notably, attackers are exploiting the recent wave of security upgrades to turn them into a perfect trap for hijacking corporate accounts.

Impersonating technical staff for "security upgrades"

This past May, Microsoft introduced a new feature allowing system administrators to roll out campaigns encouraging employees to register passkeys to enhance security. Alarmingly, the hacker group stayed one step ahead by initiating vishing calls as early as April.

Their script is highly methodical: calling employees within organizations directly, posing as the support department, and demanding that they register a new Microsoft Entra key for security reasons. After convincing the victims, the fraudsters guide them to links (URLs) containing the word “passkey” in the domain name to boost credibility.

These websites are sophisticatedly designed, replicating the entire interface and brand identity of the victim's own company, leading users to believe they are operating on an official Microsoft system.

Fake passkey creation page
Fake passkey creation page

Manipulating authentication processes in real-time

Unlike conventional adversary-in-the-middle attacks, this phishing kit utilizes a PHP control panel directly operated by the hackers. This system functions by continuously sending polling signals once every second to closely monitor the victim's behavior.

According to analysis from identity management company Okta, attackers can see the victim's progress almost instantly. From there, they dynamically alter the spoofed website's interface to match the multi-factor authentication (MFA) method used by the victim's company, whether it is an OTP code sent via SMS, an authenticator app (TOTP), or a number-matching push notification.

Once users enter their login credentials and MFA codes into the fake website, the data is immediately transmitted to the operator, allowing them to log into the victim's actual Microsoft account. While users think they are creating a passkey for themselves, they are actually helping the attacker register a passkey under the attacker's control.

To enhance authenticity and distract inexperienced individuals, the phishing website also requires victims to save a fake recovery phrase sequence (BIP-39 standard). Experts note that the legitimate Microsoft Entra registration process does not utilize this type of recovery phrase at all.

Fake recovery phrase
Fake recovery phrase

The extortion gang behind the campaign

Security research experts from Okta identify this hacker group as O-UNC-066, which is operating an extortion campaign named Pink. Meanwhile, Palo Alto Networks' Unit 42 stated that Pink is a new extortion branch affiliated with a decentralized cybercrime network called "The Com" (The Community).

The Pink group is notorious for its tactics of impersonating information technology (IT) personnel and making vishing calls to hijack accounts. Their ultimate goal is to steal corporate data.

The group's speed of action is highly alarming: immediately after gaining access to a Microsoft 365 account, they instantly scan and exfiltrate data from cloud storage services like SharePoint and OneDrive. By May 31, the group had even set up a dedicated extortion website to leak sample data snippets to exert ransom pressure on victims.

Currently, this campaign spares no one, with the list of victims spanning across numerous sectors, including:

  • Technology, Healthcare, Aviation

  • Food and Beverage

  • Automotive, Construction

What should businesses do to protect themselves?

In the face of this sophisticated voice phishing campaign, experts from Okta recommend that organizations and businesses tighten their internal operational processes through two core solutions:

  • Two-way identity verification: Establish a clear mechanism for employees to re-authenticate the identity of helpdesk personnel before complying with any technical requests over the phone.

  • Geoblocking: Configure systems to outright deny login requests originating from geographical regions or countries where the business has no operations or services.

  • Enhancing employee awareness: Humans are always the decisive link in an organization's security system. Regularly updating cybersecurity knowledge will help personnel proactively identify risks and protect digital assets from threats arising from a lack of vigilance.


The Pink gang's phishing campaign proves that as security technology advances, hackers' social engineering tactics become increasingly sophisticated. Equipping employees with awareness regarding legitimate passkey registration processes and fostering skepticism toward unexpected security-related calls is the most essential shield today.

Reference: The Cyber Express

Comments


follow ipsip vietnam.png
40051abd5a76713af8f015988fc6780e-blue-phone-icon-with-a-wave-on-it.webp
whatsapp-mobile-software-icon-png-image_6315991.png
pngtree-minimal-calendar-icon-vector-png-image_21233134.png
IPSIP logo transparent.png

IPSIP VIETNAM ONE MEMBER LIMITED LIABILITY COMPANY (IPSIP VIETNAM OMLLC)

Tax code: 0313859600

🏢 SH05.01, B4 Street, Saritown Area, An Khanh Ward, Ho Chi Minh City, Vietnam

​☎  +84 918 397 489

  • Linkedin
  • Facebook
  • TikTok
  • Email liên hệ
png-clipart-iso-iec-27001-information-security-management-iso-iec-27002-international-orga
soc 2 type ii

Our Services

Sign up to receive in-depth cybersecurity documents and news from IPSIP Vietnam.

bottom of page