Threat actors associated with major cybercrime groups are launching sophisticated phishing campaigns that exploit the very security features designed to protect corporate accounts. Instead of simply stealing passwords, attackers are now mimicking legitimate Microsoft 365 passkey and single sign-on (SSO) setup prompts to compromise enterprise data.
According to an advisory reported by BleepingComputer, criminal networks linked to groups like ShinyHunters and Helix are actively using this novel social engineering technique. The attack hinges on creating highly convincing lures that direct victims to fake login portals. These portals don't just harvest credentials; they are built using Adversary-in-the-Middle (AitM) proxy kits. This technical configuration allows attackers to steal both the username and password and the active session authentication token that follows.
Capturing this session token is the critical breakthrough for the attackers. It grants them persistent access to the victim's Microsoft 365 account, effectively bypassing traditional multi-factor authentication (MFA) challenges after the initial login. From there, they can pivot to steal sensitive corporate data stored in services like SharePoint, OneDrive, and Exchange Online.
The strategy represents a significant evolution in the phishing paradigm. Passkeys are widely promoted as a phishing-resistant authentication method, and users are being trained to trust and adopt them. Attackers are exploiting this growing familiarity by targeting the enrollment process itself. A phishing email might urgently prompt an employee to "register a new passkey for enhanced security" or "verify your single sign-on setup," creating a false sense of security that makes the malicious link more likely to be clicked.
For Hong Kong enterprises, which heavily rely on Microsoft 365 as a core productivity platform, this campaign underscores the urgent need for a layered defense. Technical controls are essential but must be paired with human awareness. Microsoft's own recommendations point toward several key priorities:
- Deploy Phishing-Resistant MFA: Mandate hardware-based security keys or platform authenticators that are inherently immune to AitM proxy attacks.
- Implement Conditional Access Policies: Enforce controls that can restrict logins from suspicious locations or devices and require step-up authentication for high-risk actions.
- Update User Training Immediately: The most critical defense is educating employees that legitimate passkey registration and SSO management are initiated from within trusted applications or operating system settings—never via an unsolicited email link. Users must be trained to be skeptical of any prompt asking them to set up security features, especially those creating a sense of urgency.
Security researchers note that the full scale of this campaign and its specific sectoral focus remain under investigation. However, the technique is highly scalable, likely leveraging spoofed but credible-looking domains or even compromised tenant-to-tenant email routing. As passkey adoption grows, this method of turning a security rollout into an attack vector is expected to become more prevalent, making proactive defense and user education a non-negotiable priority for IT security teams.
與大型網絡犯罪集團相關的威脅行為者正發動精密的網絡釣魚攻擊,利用旨在保護企業帳戶的安全功能。攻擊者不再只是竊取密碼,而是模仿合法的微軟365通行密鑰及單一登入設定提示,以危害企業資料。
根據 BleepingComputer 報導的公告,與 ShinyHunters 和 Helix 等集團有關的犯罪網絡正積極使用這種新穎的社交工程技術。攻擊的關鍵在於製造極具說服力的誘餌,將受害者引導至偽造的登入門戶。這些門戶不僅收集憑證;它們是使用中間人代理套件建立的。這種技術設定使攻擊者能夠竊取用戶名和密碼以及隨後產生的現有會話驗證令牌。
捕獲這個會話令牌是攻擊者的關鍵突破。它賦予他們對受害者微軟365帳戶的持續訪問權限,在初始登入後有效地繞過傳統的多因素認證挑戰。從那裡,他們可以橫向滲透,竊取儲存在 SharePoint、OneDrive 和 Exchange Online 等服務中的敏感企業資料。
該策略代表了網絡釣魚模式的重大演進。通行密鑰被廣泛宣傳為抗網絡釣魚的認證方法,用戶正被訓練信任並採用它們。攻擊者利用這種日益增長的熟悉感,直接針對註冊過程本身。網絡釣魚郵件可能緊急提示員工「為增強安全性註冊新通行密鑰」或「驗證您的單一登入設定」,製造虛假的安全感,使惡意連結更可能被點擊。
對於高度依賴微軟365作為核心生產力平台的香港企業而言,這場行動凸顯了建立分層防禦的迫切性。技術控制措施至關重要,但必須與人的意識相結合。微軟自身的建議指出幾個關鍵優先事項:
- 部署抗網絡釣魚的多因素認證: 強制使用基於硬體的安全密鑰或平台認證器,這些設備天生免疫中間人代理攻擊。
- 實施條件訪問策略: 強制執行可限制來自可疑位置或設備的登入控制,並對高風險操作要求升級認證。
- 立即更新用戶培訓: 最關鍵的防禦是教育員工,合法的通行密鑰註冊和單一登入管理是從受信任的應用程式或作業系統設定內部發起的——絕不通過未經請求的郵件連結。必須訓練用戶對任何要求設定安全功能的提示保持懷疑態度,尤其是那些製造緊迫感的提示。
安全研究人員指出,這場行動的完整規模及其特定的行業焦點仍在調查中。然而,該技術具有高度可擴展性,可能利用偽造但外觀可信的域名,甚至是被入侵的租戶間郵件路由。隨著通行密鑰的採用增長,這種將安全部署轉變為攻擊向量的方法預計將變得更加普遍,使得主動防禦和用戶教育成為 IT 安全團隊不可協商的優先事項。
