MICROSOFT SECURITY BLOG
Passkey-themed social engineering leads to identity and cloud compromise
CRITICAL cloud-compromise MFA-persistence social-engineering Microsoft-Graph-abuse
Strategic summary
Targeted social engineering campaign exploits passkey themes to compromise cloud identities, establishes MFA persistence, and systematically extracts data via Microsoft Graph, SharePoint, and REST APIs , typical pattern of state-sponsored APT operations with long-term persistence objectives.
Relevance for you
Targeted social engineering campaign exploits passkey themes to compromise cloud identities, establishes MFA persistence, and systematically extracts data via Microsoft Graph, SharePoint, and REST APIs , typical pattern of state-sponsored APT operations with long-term persistence objectives.
Risk score
Review required 42
- cvss base
- 45.00
- kev bonus
- 0.00
- epss bonus
- 0.00
- poc bonus
- 0.00
- raw before weight
- 45.00
- industry weight
- 1.10
- freshness factor
- 1.00
- exploitability factor
- 1.00
- days old
- 0.00
- vendor mismatch penalty
- 0.00
- consensus penalty
- -8.00
Path: operational
Consensus check
The pipeline self-checks before delivery. These rules lowered the score:
-
TTP_MISMATCHATT&CK techniques in text absent from structured mapping −8
- Consensus penalty:
- −8.0
- Total penalty:
- −8.0
MITRE ATT&CK mapping
5 TTPsProcedure details
| Technique | Tactic | Procedure | Conf. | Source |
|---|---|---|---|---|
| T1583.001 | Technique T1583.001 explicitly referenced in source: Microsoft Security Blog | high | primary | |
| T1583 | Technique T1583 explicitly referenced in source: Microsoft Security Blog | high | primary | |
| T1585.002 | Technique T1585.002 explicitly referenced in source: Microsoft Security Blog | high | primary | |
| T1585 | Technique T1585 explicitly referenced in source: Microsoft Security Blog | high | primary | |
| T1078.004 | Technique T1078.004 explicitly referenced in source: Microsoft Security Blog | high | primary |