Once initial access is secured, attackers utilize the Microsoft Graph API to programmatically map organizational structures and identify the location of sensitive SharePoint and OneDrive repositories. This methodical execution underscores a significant trend in the 2026 threat landscape, where the focus has moved from simple credential theft to deep infrastructure exploitation. While the global shift toward passwordless authentication and passkeys was marketed as a definitive solution for identity security, sophisticated threat actors have managed to subvert these very mechanisms. By targeting the enrollment and session management phases within Microsoft 365 and Entra ID, attackers are turning secure protocols into a primary vector for breach. These campaigns exploit the trust users place in modern security prompts, often using the transition to “secure” passkeys as a deceptive lure. As organizations migrate away from traditional passwords, they must confront the reality that adversaries are already waiting at the next stage of the authentication journey.
E-Crime Collectives: The Architects of Identity Theft
The organizational structure behind these sophisticated campaigns is led by two prominent e-crime collectives identified as Storm-3121 and Storm-3032. Storm-3121 maintains a close association with the “ShinyHunters” brand, a name synonymous with some of the most significant data breaches in recent history. This group possesses a highly mature infrastructure that is specifically optimized for the management, processing, and monetization of massive volumes of exfiltrated corporate intelligence. Their operations are characterized by a level of technical and financial resources typically reserved for state-sponsored actors, allowing them to maintain persistence in complex cloud environments for extended periods. Their primary motivation remains high-pressure extortion, leveraging the sensitive nature of the data they harvest to demand substantial payments from their targets. The involvement of such a high-tier group indicates that passkey phishing is no longer a fringe technique but a cornerstone of elite operations.
Operating alongside these major groups is Storm-3032, also known by its “Helix” moniker, which specializes in the rapid adoption of emerging exploitation techniques. This group is particularly known for its agility, often being among the first to weaponize changes in Microsoft’s authentication workflows before defensive organizations can adjust their security postures. These threat actors do not work in isolation but are part of a broader, interconnected e-crime ecosystem where advanced phishing kits and operational playbooks are traded like commodities. This collaborative environment ensures that when one group develops a successful method for bypassing passkey registration, the technique is quickly disseminated among a wider network of affiliates. This synergy creates a persistent and evolving threat that is difficult for traditional security measures to mitigate, as the infrastructure used for these attacks is rotated frequently to evade detection. The result is a highly resilient attack surface that continuously challenges the boundaries of identity security.
Technical Manipulation: Bypassing Modern Authentication
A critical component of the technical exploitation strategy is the use of Adversary-in-the-Middle (AiTM) attacks, which are designed to intercept authenticated sessions in real-time. In an AiTM scenario, the attacker deploys a malicious proxy server that acts as a bridge between the victim and the legitimate Microsoft login portal. As the user enters their credentials and completes the multi-factor authentication process, the proxy server captures the resulting session token. This token essentially provides the attacker with a “pre-authenticated” pass into the target environment, completely bypassing the need to interact with the user’s actual passkey hardware after the initial setup. The deceptive nature of this attack is enhanced by the use of high-fidelity phishing domains that mimic official corporate portals. Because the user is interacting with a site that looks and behaves exactly like the real Entra ID interface, the likelihood of detection during the authentication process is extremely low, making it an effective method.
In addition to session hijacking, these threat actors frequently abuse the “device code flow” to establish unauthorized access to cloud environments. This authentication mechanism was originally intended for devices with limited input capabilities, but it has been repurposed by attackers as a powerful bypass for traditional security controls. By generating a code on their own device and using social engineering to trick a victim into authorizing it on a legitimate Microsoft page, the attacker can link their machine directly to the victim’s account. This method is particularly dangerous because the victim is often directed to a genuine Microsoft URL to enter the code, providing a sense of legitimacy that is difficult to replicate with standard phishing pages. Once the code is authorized, the attacker gains a high-privileged session that is often immune to subsequent password changes or certain conditional access policies. This exploitation of an alternative authentication feature highlights the creative ways in which adversaries probe for functional gaps.
Stealthy Presence: Persistence and Internal Reconnaissance
Building upon their initial access, these adversaries focus on establishing deep persistence to ensure that their presence survives any immediate remediation efforts. A common tactic involves the registration of additional, attacker-controlled multi-factor authentication methods to the compromised account. This may include adding a new phone number for SMS verification or linking a rogue authenticator app to the user’s identity profile. By doing so, the attacker ensures they can always generate a valid authentication code, even if the user’s original password or passkey is revoked. This maneuver effectively turns the compromised account into a permanent asset for the threat actor, allowing for long-term access without the need for repeated phishing attempts. Furthermore, the use of the Microsoft Graph API allows the attackers to monitor the account for any security changes, providing them with early warnings. This strategic focus on identity persistence is what transforms a temporary breach into a long-term intelligence-gathering operation.
Once persistence is secured, the attackers leverage the inherent trust within the organization to move laterally and compromise additional high-value targets. By using the compromised internal account to send messages through Microsoft Teams or internal email systems, they can bypass many of the security filters that usually block external threats. An internal request for a colleague to “test a new security passkey” or “review an urgent IT document” is much more likely to be accepted because it originates from a known and trusted identity. This method of internal phishing is highly effective for escalating privileges, as it allows the attacker to target administrators or executives who might have more stringent protections against external communications. This spread of the infection from within the corporate perimeter creates a cascading failure of security, where the tools designed for collaboration are used to dismantle the organization’s integrity. The ability to move silently between departments makes it difficult to contain.
Data Exfiltration: Automation and Industry Impact
The ultimate objective of these campaigns is the systematic theft of intellectual property and sensitive corporate data, achieved through the use of high-speed automation. Attackers have been observed using the python-httpx library to script the bulk retrieval of files from SharePoint Online, OneDrive, and Exchange. This specific technical choice allows them to exfiltrate massive quantities of data with a level of efficiency that manual methods cannot match. By automating the download process, the threat actors can systematically crawl through every accessible folder, identifying and stealing the most valuable assets in a matter of hours. The python-httpx library also provides the flexibility to rotate IP addresses and mimic legitimate traffic patterns, making the exfiltration process appear like normal cloud activity to many monitoring systems. This high-volume data theft is often the precursor to a double-extortion attempt, where the stolen data is used as leverage to force the victim into paying a ransom.
The targeting patterns observed throughout 2026 reveal a strategic focus on industries with high-value digital assets and critical intellectual property. Sectors such as IT services, discrete manufacturing, and real estate have been particularly hard-hit by these passkey-themed phishing campaigns. These industries are chosen not only for their financial resources but for the strategic value of their proprietary designs, trade secrets, and transactional data. Attackers often perform extensive reconnaissance on professional networks to identify specific individuals who possess administrative access or hold key roles in sensitive projects. This allows for the creation of highly personalized social engineering lures that are specifically tailored to the victim’s professional context, significantly increasing the probability of a successful compromise. The global nature of these attacks, combined with the focus on specific high-value sectors, demonstrates a calculated and predatory approach to cloud exploitation.
Strategic Response: Implementing Identity Threat Detection
Defending against the evolution of passkey phishing requires organizations to move beyond traditional security mindsets and adopt an Identity Threat Detection and Response framework. One of the most effective strategic moves is the enforcement of FIDO2 hardware-backed security keys, which provide a significant layer of protection against the session hijacking and proxy techniques used in AiTM attacks. Additionally, security teams must implement more granular Conditional Access policies that strictly limit authentication based on device health, geographic location, and network reputation. Monitoring the enrollment phase of the identity lifecycle is also critical, as this is the primary point of failure in current passkey implementations. By treating any changes to a user’s authentication methods as a critical security event, administrators can take immediate action to investigate and contain potential breaches. This proactive approach to identity governance is essential for maintaining a secure and resilient cloud environment.
To counter these persistent threats, the most resilient organizations implemented comprehensive security protocols that prioritized the integrity of the identity enrollment process. They successfully deployed automated monitoring tools to detect unauthorized changes in multi-factor authentication settings, ensuring that any rogue device registrations were immediately flagged for investigation. Furthermore, these companies moved away from legacy authentication flows, such as device code authorization, which had previously served as a primary bypass for attackers. Security teams also utilized advanced analytics to hunt for indicators of compromise, such as the unusual presence of the python-httpx library in cloud access logs. Employees were provided with specialized training that focused on the nuances of passkey phishing, which significantly improved the overall detection of social engineering attempts. By fostering a culture of security awareness, these organizations effectively minimized their exposure to the sophisticated tactics used by modern adversaries.
