一键重装系统工具 | U盘启动盘制作工具 | 误删文件恢复软件 | 硬盘数据抢救专家 | 电脑蓝屏修复助手 | C盘空间清理神器 | 电脑驱动离线安装工具 | 微信聊天记录恢复工具 | 照片误格式化恢复 | 电脑密码破解清除工具 | 系统崩溃紧急救援盘 | 电脑加速优化大师 | 电脑开不了机怎么重装系统 | 回收站清空了怎么恢复 | 硬盘分区丢失数据恢复 | 电脑卡顿重装系统有用吗 | U盘插入提示格式化数据恢复 | 电脑中毒文件被隐藏恢复 | 忘记电脑开机密码怎么办 | 新硬盘分区对齐工具 | 旧电脑装Win10流畅工具 | SD卡照片删除恢复免费版 | 移动硬盘打不开提示损坏修复 | 电脑无故重启系统修复工具 | 电脑小白一键重装神器 | 程序员电脑环境配置助手 | 设计师电脑字体/素材恢复工具 | 网吧网管系统维护工具箱 | 财务人员电脑发票备份恢复 | 学生党免费电脑系统安装包 | 电脑维修师傅必备工具盘 | 游戏玩家电脑性能优化助手 | 办公白领误删文档恢复软件 | 自媒体视频素材恢复工具 | 网课录制视频损坏修复工具 | 最好的U盘PE系统排名 | 数据恢复软件哪个最强 | 免费电脑助手与收费版区别 | 国产装机工具哪款无广告 | 离线版驱动助手推荐 | 轻量级电脑优化工具对比 | 支持NVMe驱动的PE工具 | 带网络功能的应急启动盘 | 2026最新版万能装机工具 | 支持Win11 24H2的PE工具 | 最新免激活系统重装工具 | 2026数据恢复软件破解版合集 | 纯净无捆绑装机助手V3.0 | 支持苹果M芯片的电脑助手 | 秋季更新版系统维护工具箱 | 电脑系统崩了怎么用U盘把重要资料拷贝出来 | 重装系统前哪些文件夹必须备份 | 固态硬盘误格式化还能恢复数据吗 | 如何制作一个既带PE又能存数据的双分区U盘 | 电脑总是弹窗广告用什么助手彻底拦截 后台管理
📢 欢迎访问系统之家!所有资源均经过安全检测。

Passkey

发布时间:2026-09-12 | 浏览:3
📥 下载地址(文章开头)
装机神器,可以安装一切系统。
Passkey-themed phishing attacks lead to Microsoft 365 data theft September 11, 2026 Microsoft says threat actors linked to ShinyHunters, Helix, and other extortion gangs are using passkey and single sign-on-themed social engineering attacks to compromise corporate Microsoft accounts and steal data from Microsoft 365 services. The activity has been observed since May 2026 and begins with the attackers researching targeted organizations and employees before calling or messaging victims while impersonating corporate IT help desks. The attackers tell employees that they must urgently update a passkey, multi-factor authentication (MFA), or single sign-on (SSO) configuration to avoid losing access to corporate systems. Victims are then directed to phishing sites designed to resemble legitimate Microsoft login pages, with links sometimes sent through SMS messages to employees' personal phones. Microsoft says that while the lures frequently revolve around passkeys, the attackers are not attempting to enroll a passkey. Instead, the passkey lures are used to trick targeted employees into signing in to adversary-in-the-middle (AiTM) phishing sites or using device-code authentication flows . AiTM attacks allow the threat actors to capture credentials and session tokens. Device code phishing tricks victims into authorizing access to their account via an attacker-controlled client using Microsoft's legitimate authentication pages. Microsoft says the attackers conduct extensive research before targeting employees. "The actor appears to invest heavily in pre-attack research, likely gathering information about employees and organizational structure from public sources such as social networking and professional profiling platforms," explains Microsoft. The threat actors also register phishing domains that combine company names with words related to passkeys, SSO, key synchronization, account setup, and identity verification. Some examples seen by Microsoft include: passkeyhelpdesk[.]com , secure-passkey[.]com , setupmypasskey[.]com , add-passkey[.]com , integratedsso[.]com , oktasession[.]com , keysyncos[.]com , and oskeysync[.]com . The attackers commonly place the victim company's name in a subdomain, such as company-name.secure-passkey[.]com , to make the phishing portal appear more convincing. Microsoft attributes the initial-access activity to multiple threat actors operating in the same extortion ecosystem, including groups it tracks as Storm-3121 and Storm-3032. Storm-3121 is associated with ShinyHunters and Falcon extortion, while Storm-3032 is believed to be tied to BlackFile extortion group members that now work under the Helix name. This activity overlaps with attacks previously documented by Google Threat Intelligence under the UNC6671 threat cluster. Google previously reported that UNC6671 uses phone-based social engineering and passkey-themed phishing infrastructure to compromise corporate identities before accessing enterprise cloud environments. Google has also linked UNC6671 activity to the same extortion gangs, including BlackFile, Helix, Falcon, Pink, and Redact. Mapping the Microsoft cloud after compromise Microsoft's new research gives a closer look at what happens inside Microsoft cloud environments after an account is compromised. In one investigated attack, Microsoft observed a suspicious sign-in from an unmanaged device to a Microsoft 365 service identified in Entra logs as "OfficeHome." OfficeHome is associated with the Office 365 portal's shared infrastructure, including Office applications accessed through a browser. After completing MFA, Microsoft says the attacker established a valid session and began checking what resources the compromised account could access. Within minutes, the session was used to access My Apps to see what applications are assigned to the account, My Profile for organizational information, Microsoft Approval Management, account-management interfaces, and My Sign-Ins. The attacker then accessed SharePoint Online, Outlook Web, Microsoft 365 collaboration and search services, an internal business application, and authentication flows associated with virtual desktops. Microsoft says the session remained active for approximately one hour while the attacker listed sensitive files and internal applications. In another attack, the passkey social engineering attacks led to device-code phishing, where the victim was convinced to enter a supplied code into Microsoft's legitimate authentication page. This issues an authentication token to the attacker-controlled OAuth application, allowing the threat actor to access the victim's account without completing another MFA challenge. The attacker now has access to all of the user's resources and connected SSO applications, whether they be Microsoft 365, Salesforce, Google Workspace, Dropbox, Adobe, SAP, Slack, Zendesk, Atlassian, and many others. In a third attack, the threat actor used previously compromised credentials for an account where it is believed an authenticator application had been registered days earlier. Microsoft says the threat actors then performed reconnaissance using an automated Node.js system and Microsoft Graph. After gaining access, the attackers often gain persistence by adding an MFA method they control. Microsoft says the attackers register new phone numbers, authenticator applications, and software-based one-time password tokens with compromised identities. This allows the threat actor to satisfy future MFA challenges without the victim's help, although Microsoft notes that the persistence does not survive a complete credential and session reset. The attackers then use Microsoft Graph to enumerate the victim's cloud environment. Microsoft saw Graph requests that enumerate: Organizations, licenses, and enabled services Users, groups, and group membership Directory roles and privileged accounts Registered authentication methods Applications and service principals
📥 下载地址(文章中间)
装机神器,可以安装一切系统。
OAuth permissions and application role assignments SharePoint sites, document libraries, folders, and files OneDrive resources Mail folders, messages, and attachments Microsoft says Graph requests such as /users , /groups , or /sites are common in enterprise environments, so they may not raise alarms. However, the activity becomes more suspicious when the same account, application, or access token rapidly moves across different resources, checks privileges and authentication settings, and then begins accessing email, attachments, files, or documents. After reconnaissance, the attackers move into cloud data collection from Microsoft 365. "Microsoft observed high-volume access and download activity targeting Microsoft SharePoint Online and Microsoft OneDrive for Business, with some intrusions extending into Microsoft Exchange Online through REST API-based access to email content," explained Microsoft. "Across SharePoint and OneDrive, the activity generated significant volumes of FileAccessed and FileDownloaded events, indicating systematic retrieval of cloud-hosted documents and organizational data." Microsoft says the activity appears automated, with connections using the python-httpx user agent during SharePoint and OneDrive access exfiltration. The attackers also appear to avoid rapid "smash-and-grab" exfiltration to avoid detection. Microsoft says the data theft instead lasts from a few hours to multiple days, with threat actors accessing fewer than 1,000 files or emails in a single hour to blend in with legitimate traffic. Microsoft recommends looking for unusual sign-ins followed by new MFA registrations, Microsoft Graph reconnaissance, and suspicious access to SharePoint, OneDrive, or Exchange. If an account is compromised, administrators should revoke active sessions and tokens, reset credentials, remove any authentication methods or mailbox rules added by the attackers, and require the user to re-register their authentication methods. Microsoft also recommends using phishing-resistant MFA, limiting sensitive cloud resources to managed devices, and disabling device-code authentication when it is not needed. Build your security blueprint for AI-powered attacks Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed. Related Articles: Hedge fund cyberattacks tied to BlackFile-linked UNC6671 extortion group Man gets six years for hacking 750 women's Snapchat accounts ShinyHunters hackers claim breach of Florida "DAVID" DMV database Novocure data breach affects more than 1,400 cancer patients ReliaQuest confirms failed data-theft attack after ShinyHunters breach Social Engineering Previous Article Not a member yet? Register Now You may also like: September Windows Server updates break Remote Desktop Services September Windows Server updates break Remote Desktop Services Microsoft Excel KB5002914 update breaks copy and paste for some users Microsoft Excel KB5002914 update breaks copy and paste for some users New Microsoft Defender 'ShieldCrash' zero-day grants SYSTEM access New Microsoft Defender 'ShieldCrash' zero-day grants SYSTEM access Find your gaps before an auditor does. Check your EU CRA readiness in 5 questions. Find your gaps before an auditor does. Check your EU CRA readiness in 5 questions. Overdue a password health-check? Audit your Active Directory for free Overdue a password health-check? Audit your Active Directory for free Stay one step ahead of new threats in the new year. Join Huntress for the monthly Tradecraft Tuesday. Stay one step ahead of new threats in the new year. Join Huntress for the monthly Tradecraft Tuesday. EtherHiding Malware on macOS: How Attackers Hide C2 on the Blockchain EtherHiding Malware on macOS: How Attackers Hide C2 on the Blockchain
📥 下载地址(文章结尾)
装机神器,可以安装一切系统。