Microsoft has exposed a critical evolution in cloud account takeover, detailing campaigns where attackers are hijacking the passkey setup process to install persistent backdoors.

The tech giant disclosed two concurrent operations where threat actors abused third-party email services to launch massive phishing waves. Instead of just stealing credentials, the attacks leveraged sophisticated social engineering to trick victims into enrolling the attacker's own passkey for their account.

This presents a direct attack on the trust model of modern authentication. Passkeys are championed as a phishing-resistant defense, yet these campaigns weaponize the user's trust during the enrollment process itself to achieve a persistent breach.

The first campaign, tracked in early August 2026, involved over a million emails impersonating CEOs in financial fraud scams. A second, parallel lure focused on convincing targets to register a new security key or sign-in method. A successful compromise gives the adversary a durable authentication factor that can evade traditional security monitoring focused on stolen passwords.

For administrators of Microsoft 365 and Entra ID environments, this threat demands an immediate defensive overhaul focused on process and verification. Security guidance centers on four key actions:

First, conduct an emergency audit. Organizations must immediately review all passkeys registered for corporate accounts. Any credential not verified as legitimate user-created should be treated as a compromise indicator and investigated.

Second, harden enrollment via conditional access. Implement policies that restrict passkey registration to compliant, managed devices or trusted networks. This adds a necessary layer of verification beyond a simple user prompt.

Third, update security awareness training. Employees need clear, specific guidance to reject any unsolicited prompt to set up a new sign-in method. Training must reinforce that legitimate Microsoft services will not request passkey enrollment via embedded email links.

Fourth, deploy enhanced monitoring. IT teams should configure SIEM tools and Microsoft Defender for Cloud Apps to alert on anomalous authentication events, such as new passkey registrations from unfamiliar locations or devices.

These operations demonstrate a significant leap in attacker methodology, blending high-volume BEC scams with novel abuse of authentication features. The defense against such threats now requires a dual focus: technical controls like conditional access are essential, but they must be paired with vigilant process oversight and updated user education.


微軟揭露了一項關鍵的雲端賬戶接管演變,詳述了攻擊者劫持通密鑰設定過程以安裝持久性後門的攻擊活動。

這家科技巨頭披露了兩項同時進行的操作,其中威脅行為者濫用第三方電子郵件服務發動大規模釣魚攻擊。這些攻擊並非僅竊取憑證,而是利用精密的社會工程學手段,誘騙受害者為其賬戶註冊攻擊者自己的通密鑰。

這直接攻擊了現代認證的信任模型。通密鑰一直被宣傳為具備釣魚抵禦能力的防禦措施,然而這些攻擊活動卻將用戶在註冊過程中的信任武器化,以實現持久性入侵。

第一項攻擊活動於2026年8月初被追蹤,涉及超過一百萬封假冒CEO的電子郵件,用於金融詐騙。第二項並行的誘餌則專注於說服目標註冊新的「安全金鑰」或登入方法。成功入侵後,攻擊者可獲得一個持久的認證因子,能避開專注於竊取密碼的傳統安全監控。

對於 Microsoft 365 和 Entra ID 環境的管理員而言,此威脅要求立即進行以流程和驗證為重點的防禦革新。安全指引集中在四項關鍵行動:

首先,進行緊急審計。組織必須立即審查企業賬戶註冊的所有通密鑰。任何未經核實為合法用戶創建的憑證,都應被視為入侵指標並進行調查。

其次,通過條件式存取強化註冊。實施策略以限制通密鑰註冊僅限於合規的受管設備或可信網絡。這在簡單的用戶提示之外,增加了一層必要的驗證。

第三,更新安全意識培訓。員工需要清晰、具體的指引,以拒絕任何自發設置新登入方法的提示。培訓必須強化一點:合法的微軟服務不會透過嵌入式電子郵件連結要求註冊通密鑰。

第四,部署增強監控。IT 團隊應配置 SIEM 工具和 Microsoft Defender for Cloud Apps,以對異常認證事件發出警報,例如來自陌生位置或設備的新通密鑰註冊。

這些操作展示了攻擊者方法學的重大跳躍,將高容量的商務電郵詐騙與認證功能的新型濫用相結合。防禦此類威脅現需雙重焦點:技術控制(如條件式存取)至關重要,但必須與警覺的流程監督和更新的用戶教育相結合。

新聞來源 / Original News Source