AI Security AI安全 6h ago Updated 2h ago 更新于 2小时前 46

Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data 攻击者利用Passkey钓鱼劫持微软云账户并窃取数据

Microsoft disclosed two distinct threat campaigns: one using AI-generated CEO impersonation emails to execute ACH fraud, and another leveraging passkey-themed social engineering to compromise cloud accounts The first campaign sent over a million scam emails between August 3-5, 2026, targeting U.S. enterprise accounts payable departments across IT services, consumer goods, real estate, and manufacturing sectors The second campaign, active since May 2026, uses voice phishing and SMS to trick emplo 微软披露两起网络攻击活动:一是利用生成式AI批量创建个性化钓鱼邮件冒充CEO进行金融诈骗,二是通过Passkey主题社会工程学攻击劫持Microsoft云账户 第一起攻击在2026年8月3日至5日期间发送超过百万封欺诈邮件,针对美国企业财务部门,嵌入伪造发票和邮件对话降低受害者警惕性 第二起攻击采用"中间人"(AitM)技术,攻击者伪装成IT帮助台通过语音钓鱼引导用户访问伪造的Passkey更新页面,窃取凭据并添加自己的认证方法 攻击者注册了大量伪装成Passkey/SSO服务的恶意域名(如passkeyhelpdesk.com、secure-passkey.com等),并结合已泄露账户通过M

72
Hot 热度
65
Quality 质量
58
Impact 影响力

Analysis 深度分析

TL;DR

  • Microsoft disclosed two distinct threat campaigns: one using AI-generated CEO impersonation emails to execute ACH fraud, and another leveraging passkey-themed social engineering to compromise cloud accounts
  • The first campaign sent over a million scam emails between August 3-5, 2026, targeting U.S. enterprise accounts payable departments across IT services, consumer goods, real estate, and manufacturing sectors
  • The second campaign, active since May 2026, uses voice phishing and SMS to trick employees into updating passkeys/MFA on counterfeit Microsoft sign-in pages, enabling adversary-in-the-middle attacks
  • Threat actors are increasingly combining generative AI with layered social engineering narratives, moving beyond single-lure scams to unified deceptive stories incorporating executive impersonation, vendor branding, fabricated invoices, and forged email threads
  • The passkey phishing campaign overlaps with the UNC6671 collective (also tracked as Cordial Spider, O-UNC-045, PREY-0058), which shares commoditized phishing infrastructure, voice-phishing callers, and initial access playbooks across splintered affiliates

Why It Matters

This disclosure highlights a significant escalation in how threat actors are weaponizing generative AI and social engineering to bypass traditional security controls, making phishing attacks more personalized, credible, and harder to detect. For AI and security practitioners, it underscores the critical importance of verifying authentication requests through out-of-band channels and implementing robust email and identity governance policies. The convergence of AI-assisted content generation with adversary-in-the-middle techniques represents a growing threat vector that organizations must address proactively.

Technical Details

  • AI-Enhanced CEO Impersonation Campaign: Threat actors registered impersonation domains (e.g., service-nowinc[.]com, domainlify[.]net) and used generative AI to create tailored email templates and drafts. The campaign layered executive impersonation, vendor branding (ServiceNow), fabricated invoices, forged approval emails, and supporting email conversations into a unified narrative to reduce recipient skepticism. Targets were identified by scraping CEO, CFO, and president names from public sources and inserting them into email signatures.

  • Passkey Phishing via Adversary-in-the-Middle (AitM): The second campaign begins with voice phishing or SMS messages claiming to be from IT help desks, urging users to update passkeys, MFA, or SSO configurations. Victims are redirected to counterfeit Microsoft sign-in pages that capture credentials or force device-code authentication flows, allowing attackers to maintain persistent access even after password changes.

  • Infrastructure and Domain Patterns: Attackers registered domains using themes like passkeys, SSO enrollment, account activation, and identity verification, often appending victim organization names as subdomains (e.g., <company>.passkeyhelpdesk[.]com). Proxy-associated infrastructure was used for automated collection from compromised cloud identities via Microsoft Graph APIs, SharePoint, and OneDrive.

  • Threat Actor Attribution: Microsoft attributed initial access activity to Storm-3121 (leading to ShinyHunters and Falcon extortion) and Storm-3032 (linked to UNC6671, a splinter group from BlackFile operating under the Helix extortion brand). The loose-knit collective shares commoditized phishing panels, voice-phishing operations, and initial access playbooks across affiliates.

  • Data Exfiltration Tactics: Post-compromise activity includes high-volume Microsoft Graph API calls, SharePoint and OneDrive downloads, and mailbox collection through REST APIs, indicating automated, large-scale data harvesting from breached cloud environments.

Industry Insight

  • Organizations should implement strict verification protocols for payment requests, requiring out-of-band confirmation for any ACH or wire transfer instructions, especially those involving vendor subscriptions or urgent executive directives. Security awareness training must emphasize that no legitimate IT department will request passkey or MFA updates via unsolicited phone calls or SMS.
  • The commoditization of phishing infrastructure and shared playbooks among cybercrime collectives means that defensive strategies cannot rely on signature-based detection alone. Zero-trust identity architectures, continuous authentication monitoring, and behavioral analytics are essential to detect anomalous sign-in patterns and unauthorized authentication method additions.
  • As generative AI lowers the barrier to creating convincing phishing content at scale, enterprises should invest in AI-driven email security solutions capable of detecting subtle narrative inconsistencies, deepfake audio cues, and domain spoofing techniques that go beyond traditional header analysis.

TL;DR

  • 微软披露两起网络攻击活动:一是利用生成式AI批量创建个性化钓鱼邮件冒充CEO进行金融诈骗,二是通过Passkey主题社会工程学攻击劫持Microsoft云账户
  • 第一起攻击在2026年8月3日至5日期间发送超过百万封欺诈邮件,针对美国企业财务部门,嵌入伪造发票和邮件对话降低受害者警惕性
  • 第二起攻击采用"中间人"(AitM)技术,攻击者伪装成IT帮助台通过语音钓鱼引导用户访问伪造的Passkey更新页面,窃取凭据并添加自己的认证方法
  • 攻击者注册了大量伪装成Passkey/SSO服务的恶意域名(如passkeyhelpdesk.com、secure-passkey.com等),并结合已泄露账户通过Microsoft Teams二次传播
  • 攻击基础设施与多个网络犯罪组织有关联,包括Cordial Spider、UNC6671、Storm-3121、Storm-3032等,共享钓鱼面板和初始访问手册

为什么值得看

本文揭示了生成式AI如何被恶意利用于大规模社会工程学攻击,为AI安全从业者提供了重要的威胁情报和防御参考。同时展示了云安全领域新兴的Passkey钓鱼攻击模式,对安全团队构建云身份防护策略具有直接指导意义。

技术解析

AI驱动的钓鱼邮件生成:攻击者利用生成式AI创建个性化邮件模板和草稿,针对目标公司的CEO、CFO和总裁姓名及邮箱地址进行定制,嵌入伪造的ServiceNow年度订阅发票和"审批"邮件对话,形成多层叙事降低受害者怀疑。

Passkey钓鱼攻击链:攻击者通过语音或SMS联系员工,伪装成IT帮助台要求更新Passkey/MFA/SSO配置,引导用户访问伪造的Microsoft登录页面。采用中间人(AitM)或设备代码认证流程,窃取凭据或诱使用户授权访问。

恶意域名基础设施:攻击者注册了多个主题域名(passkeyhelpdesk.com、secure-passkey.com、setupmypasskey.com等),并采用"<公司名>.<恶意域名>.com"模式附加目标组织子域名,用于托管凭据收集面板和语音钓鱼活动。

预攻击情报收集:攻击者从LinkedIn等社交网络和职业资料平台收集员工和组织结构信息,部分案例利用已泄露账户通过Microsoft Teams发送钓鱼消息扩大影响范围。

攻击组织关联:活动与Cordial Spider、UNC6671、Storm-3121、Storm-3032等网络犯罪组织有关联,共享初始访问手册、钓鱼面板和语音钓鱼呼叫者资源。

行业启示

AI赋能的钓鱼攻击将成为常态:生成式AI大幅降低了大规模个性化钓鱼的攻击门槛,安全团队需建立AI生成内容检测机制,并加强对财务部门的专项培训。

云身份安全需重点关注Passkey/MFA钓鱼:攻击者正将社会工程学目标从传统密码转向Passkey和MFA配置,企业应实施设备信任管理、异常登录检测和零信任架构,减少单一认证因素依赖。

威胁情报共享与协同防御至关重要:攻击者共享基础设施和攻击手册,安全团队应加强行业间威胁情报共享,建立针对新型钓鱼域名和攻击模式的快速响应机制。

Disclaimer: The above content is generated by AI and is for reference only. 免责声明:以上内容由 AI 生成,仅供参考。

Security 安全 Research 科学研究