Skip to content
Auto-CTI
Back to today
NEW CRITICAL B3

Passkey-themed social engineering leads to identity and cloud compromise

B Microsoft Security Blog ·

Admiralty grading (A–F · 1–6)

Source reliability

  • A Completely reliable
  • B Usually reliable
  • C Fairly reliable
  • D Not usually reliable
  • E Unreliable
  • F Cannot be judged

Information credibility

  • 1 Confirmed
  • 2 Probably true
  • 3 Possibly true
  • 4 Doubtful
  • 5 Improbable
  • 6 Cannot be judged

NATO Admiralty (AJP-2.1) grades confidence, independent of the risk score. Cross-source corroboration isn't tracked for non-CVE news, so single-source items are capped at a lower credibility number; a low number does not imply low quality.

Key insight

Targeted social engineering campaign exploits passkey themes to compromise cloud identities, establishes MFA persistence, and systematically extracts data via Microsoft Graph, SharePoint, and REST APIs , typical pattern of state-sponsored APT operations with long-term persistence objectives.

Description

An active, human-operated intrusion campaign since May 2026 leverages passkey-themed social engineering and identity impersonation to compromise Microsoft cloud environments. Following successful authentication, attackers register threat-actor-controlled MFA methods to establish persistent access factors. Subsequently, they conduct automated reconnaissance via Microsoft Graph, download data from SharePoint and OneDrive, and collect email through REST APIs. The sequence exhibits classic advanced persistence patterns: initial access via social engineering, rapid MFA enrollment for persistence, and systematic data exfiltration through cloud APIs using proxy-associated infrastructure.

Risk score

Review required 42
cvss base
45.00
kev bonus
0.00
epss bonus
0.00
poc bonus
0.00
raw before weight
45.00
industry weight
1.10
freshness factor
1.00
exploitability factor
1.00
days old
0.00
vendor mismatch penalty
0.00
consensus penalty
-8.00

Path: operational

Consensus check

The pipeline self-checks before delivery. These rules lowered the score:

  • TTP_MISMATCH ATT&CK techniques in text absent from structured mapping −8
Consensus penalty:
−8.0
Total penalty:
−8.0

MITRE ATT&CK mapping

5 TTPs
Recon
Resource Dev
Initial Access
Execution
Persistence
Priv. Escal.
Def. Evasion
Cred. Access
Discovery
Lateral Mov.
Collection
C2
Exfiltration
Impact
Conf.: high medium low

Procedure details

Technique Tactic Procedure Conf. Source
T1583.001
Technique T1583.001 explicitly referenced in source: Microsoft Security Blog high primary
T1583
Technique T1583 explicitly referenced in source: Microsoft Security Blog high primary
T1585.002
Technique T1585.002 explicitly referenced in source: Microsoft Security Blog high primary
T1585
Technique T1585 explicitly referenced in source: Microsoft Security Blog high primary
T1078.004
Technique T1078.004 explicitly referenced in source: Microsoft Security Blog high primary
ESC