Vishing actors target Entra passkey enrollment
Since April 2026, threat actors operating under O-UNC-066 have deployed a sophisticated vishing campaign targeting Microsoft 365 passkey enrollment. Attackers register domains containing 'passkey' and call victims to convince them to register new passkeys. Victims are directed to operator-controlled phishing kits that mimic Microsoft's enrollment process while attackers simultaneously register their own passkeys in victim accounts. The kit uses real-time polling and adapts to various MFA requirements including TOTP, push notifications, and SMS OTP. Targeted organizations span food and beverage, technology, healthcare, automotive, construction, and aviation industries. The campaign leverages Microsoft's legitimate passkey registration campaigns as a pretext, with primary motivation being data extortion through the Pink data leak site. Infrastructure is hosted on DDoS-Guard and IQWeb FZ-LLC.
AI Analysis
Technical Summary
This campaign involves sophisticated phone-based social engineering (vishing) combined with operator-controlled phishing kits that impersonate Microsoft 365 passkey enrollment. Attackers register domains containing 'passkey' and call victims to convince them to enroll new passkeys. The phishing infrastructure supports real-time polling and adapts to MFA methods including TOTP, push notifications, and SMS OTP. While victims complete the enrollment, attackers simultaneously register their own passkeys to gain account access. The campaign leverages legitimate Microsoft passkey campaigns as a pretext and targets organizations across diverse sectors. The attackers' primary objective is data extortion through the Pink data leak site. The infrastructure is hosted on DDoS-Guard and IQWeb FZ-LLC.
Potential Impact
Successful exploitation allows attackers to bypass multi-factor authentication by registering their own passkeys on victim accounts, potentially leading to unauthorized access to Microsoft 365 accounts. This can result in data theft and subsequent extortion via the Pink data leak site. The campaign affects organizations in multiple industries, increasing the risk of sensitive data compromise.
Mitigation Recommendations
No official patch or fix applies as this is a social engineering campaign. Organizations should educate users about vishing threats and the risks of unsolicited calls requesting passkey enrollment. Verification of enrollment requests through official channels is recommended. Monitoring for suspicious domain registrations containing 'passkey' and blocking known phishing infrastructure may help reduce exposure. Since this is not a software vulnerability, technical patching is not applicable.
Indicators of Compromise
- domain: deploypasskey.com
- domain: passkeyadd.com
- domain: passkeydeploy.com
- domain: setpasskey.com
- domain: assignpasskey.com
- domain: exampleentity.setpasskey.com
Vishing actors target Entra passkey enrollment
Description
Since April 2026, threat actors operating under O-UNC-066 have deployed a sophisticated vishing campaign targeting Microsoft 365 passkey enrollment. Attackers register domains containing 'passkey' and call victims to convince them to register new passkeys. Victims are directed to operator-controlled phishing kits that mimic Microsoft's enrollment process while attackers simultaneously register their own passkeys in victim accounts. The kit uses real-time polling and adapts to various MFA requirements including TOTP, push notifications, and SMS OTP. Targeted organizations span food and beverage, technology, healthcare, automotive, construction, and aviation industries. The campaign leverages Microsoft's legitimate passkey registration campaigns as a pretext, with primary motivation being data extortion through the Pink data leak site. Infrastructure is hosted on DDoS-Guard and IQWeb FZ-LLC.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This campaign involves sophisticated phone-based social engineering (vishing) combined with operator-controlled phishing kits that impersonate Microsoft 365 passkey enrollment. Attackers register domains containing 'passkey' and call victims to convince them to enroll new passkeys. The phishing infrastructure supports real-time polling and adapts to MFA methods including TOTP, push notifications, and SMS OTP. While victims complete the enrollment, attackers simultaneously register their own passkeys to gain account access. The campaign leverages legitimate Microsoft passkey campaigns as a pretext and targets organizations across diverse sectors. The attackers' primary objective is data extortion through the Pink data leak site. The infrastructure is hosted on DDoS-Guard and IQWeb FZ-LLC.
Potential Impact
Successful exploitation allows attackers to bypass multi-factor authentication by registering their own passkeys on victim accounts, potentially leading to unauthorized access to Microsoft 365 accounts. This can result in data theft and subsequent extortion via the Pink data leak site. The campaign affects organizations in multiple industries, increasing the risk of sensitive data compromise.
Mitigation Recommendations
No official patch or fix applies as this is a social engineering campaign. Organizations should educate users about vishing threats and the risks of unsolicited calls requesting passkey enrollment. Verification of enrollment requests through official channels is recommended. Monitoring for suspicious domain registrations containing 'passkey' and blocking known phishing infrastructure may help reduce exposure. Since this is not a software vulnerability, technical patching is not applicable.
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://www.okta.com/en-au/blog/threat-intelligence/vishing-actors-target-microsoft-entra-passkey-enrollment-"]
- Adversary
- O-UNC-066
- Pulse Id
- 6a50aa1cde3ff232cf43db03
- Threat Score
- null
Indicators of Compromise
Domain
| Value | Description | Copy |
|---|---|---|
domaindeploypasskey.com | — | |
domainpasskeyadd.com | — | |
domainpasskeydeploy.com | — | |
domainsetpasskey.com | — | |
domainassignpasskey.com | — | |
domainexampleentity.setpasskey.com | — |
Threat ID: 6a5e02712a4a8d5989efa101
Added to database: 07/20/2026, 11:11:45 UTC
Last enriched: 07/20/2026, 11:30:54 UTC
Last updated: 07/21/2026, 08:33:25 UTC
Views: 19
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.