Passkey-themed social engineering leads to identity and cloud compromise
Admiralty grading (A–F · 1–6)
Source reliability
- A Completely reliable
- B Usually reliable
- C Fairly reliable
- D Not usually reliable
- E Unreliable
- F Cannot be judged
Information credibility
- 1 Confirmed
- 2 Probably true
- 3 Possibly true
- 4 Doubtful
- 5 Improbable
- 6 Cannot be judged
NATO Admiralty (AJP-2.1) grades confidence, independent of the risk score. Cross-source corroboration isn't tracked for non-CVE news, so single-source items are capped at a lower credibility number; a low number does not imply low quality.
Key insight
Targeted social engineering campaign exploits passkey themes to compromise cloud identities, establishes MFA persistence, and systematically extracts data via Microsoft Graph, SharePoint, and REST APIs , typical pattern of state-sponsored APT operations with long-term persistence objectives.
Description
An active, human-operated intrusion campaign since May 2026 leverages passkey-themed social engineering and identity impersonation to compromise Microsoft cloud environments. Following successful authentication, attackers register threat-actor-controlled MFA methods to establish persistent access factors. Subsequently, they conduct automated reconnaissance via Microsoft Graph, download data from SharePoint and OneDrive, and collect email through REST APIs. The sequence exhibits classic advanced persistence patterns: initial access via social engineering, rapid MFA enrollment for persistence, and systematic data exfiltration through cloud APIs using proxy-associated infrastructure.
Risk score
- cvss base
- 45.00
- kev bonus
- 0.00
- epss bonus
- 0.00
- poc bonus
- 0.00
- raw before weight
- 45.00
- industry weight
- 1.10
- freshness factor
- 1.00
- exploitability factor
- 1.00
- days old
- 0.00
- vendor mismatch penalty
- 0.00
- consensus penalty
- -8.00
Path: operational
Consensus check
The pipeline self-checks before delivery. These rules lowered the score:
-
TTP_MISMATCHATT&CK techniques in text absent from structured mapping −8
- Consensus penalty:
- −8.0
- Total penalty:
- −8.0
MITRE ATT&CK mapping
5 TTPsProcedure details
| Technique | Tactic | Procedure | Conf. | Source |
|---|---|---|---|---|
| T1583.001 | Technique T1583.001 explicitly referenced in source: Microsoft Security Blog | high | primary | |
| T1583 | Technique T1583 explicitly referenced in source: Microsoft Security Blog | high | primary | |
| T1585.002 | Technique T1585.002 explicitly referenced in source: Microsoft Security Blog | high | primary | |
| T1585 | Technique T1585 explicitly referenced in source: Microsoft Security Blog | high | primary | |
| T1078.004 | Technique T1078.004 explicitly referenced in source: Microsoft Security Blog | high | primary |