Microsoft 365 users beware: A sophisticated vishing campaign is targeting your passkeys. The cyber extortion group Pink has been observed exploiting Microsoft's passkey enrollment process to gain access to victim networks. What makes this attack particularly insidious is the hackers' ability to impersonate a victim organization's Microsoft Entra ID login pages in real-time, complete with Microsoft branding and the targeted organization's branding. This level of realism makes the phishing attempt more convincing and increases the chances of success.
The hackers are using a panel-controlled phishing kit that mimics the Microsoft passkey enrollment process, including the security upgrade reminder that Microsoft itself sent out in May. By leveraging this well-intentioned security measure, the threat actors are abusing the enrollment process to further their objectives. The hackers' motives are clear: financial gain. As Pink states on their darknet leak site, they are a financially motivated group, and their sole goal is profit. They understand the value of the data they are stealing and expect to get their value out of it.
The targeted sectors include food and beverage, technology, healthcare, automotive, construction, and aviation industries. The hackers are using various domains to create their targeted subdomains, such as assignpasskey[.]com, deploypasskey[.]com, passkeydeploy[.]com, passkeyadd[.]com, and setpasskey[.]com. For example, if a victim's name is ExampleEntity, the malicious subdomain would be exampleentity[.]setpasskey[.]com.
This vishing campaign highlights the importance of vigilance and security measures. Users should be cautious when receiving unexpected phone calls or emails requesting passkey registration. Organizations should also implement robust security protocols and stay updated on the latest threat intelligence to protect their networks and data. As Pink's motives are clear, it is crucial to take proactive steps to safeguard against such cyber extortion attempts.