A criminal group called Pink is phoning employees, pretending to be internal IT staff, and walking them
through a fake Microsoft passkey setup page. While the employee follows the fake steps, the attacker
quietly registers their own login key on the employee’s Microsoft 365 account, then steals company
files and demands payment under a 72-hour deadline. Organisations in six industries have been hit
since April 2026.
1.Campaign Timeline
Active since April 2026. Okta tracks the actor as O-UNC-066; Palo Alto Networks Unit 42 tracks it as Pink (CL-CRI-1147) and assesses it is likely Com-affiliated, with techniques similar to Bling Libra (ShinyHunters) and CL-CRI-1116 (Blackfile/Redact). The first phishing domain was registered on 21 April 2026. The Pink leak site went live on 31 May 2026 and already lists multiple victims. On 1 June 2026, a stale extortion negotiation from a likely Com-related cluster was re-contacted under the Pink brand with a new qTox ID. Confirmed targeting spans food and beverage, technology,healthcare, automotive, construction, and aviation.
2. Attack Chain
- Vishing call
The actor phones a targeted user, impersonates internal IT, and persuades them they must register a new
passkey. The user is directed to a per-target subdomain carrying their organisation’s real logo and branding.
- Credential capture
Fake Microsoft sign-in pages collect the username and password, which post to an operator panel. The operator replays them at the legitimate Microsoft sign-in page within seconds.
- MFA relay
The operator watches which multi-factor challenge Microsoft presents and pushes the matching page (SMS code, authenticator code, or push number matching) to the victim, who unknowingly approves the attacker’s session.
- Passkey enrolment
The attacker registers their own passkey on the compromised Microsoft 365 account. Fake recovery-key pages using BIP-39 seed phrases keep the user busy so the legitimate enrolment notification email looks expected.
- Exfiltration
The actor rapidly identifies and steals data from SharePoint and OneDrive, consistent with other Com-affiliated groups.
- Extortion
The actor sends the extortion email and internal Teams messages from the compromised account, sets a 72-hour deadline, and applies public pressure through the Pink leak site.
3. Phishing Kit Capabilities
The kit is not an adversary-in-the-middle proxy. It is an operator-controlled PHP panel that steers each victim through the attack in close to real time using a 1-second polling mechanism.
- Per-victim branding Generic Microsoft styling loads from Microsoft’s own content delivery network; each target organisation’s logo and background are pre-staged per subdomain.
- Live MFA adaptation The operator selects SMS OTP, authenticator TOTP, or push number-matching pages on demand to match the victim’s real MFA requirements.
- No federation handling The kit does not redirect to third-party identity providers such as Okta. Okta has not observed direct compromise through federation.
4. Recommendations
- Review Microsoft Entra ID audit and sign-in logs for passkey (FIDO2) registrations since April 2026, and verify every new authenticator with the account owner.
- For affected accounts, remove unrecognised passkeys and authenticators, revoke active sessions, then reset passwords, in that order.
- Restrict security-info registration with Entra Conditional Access to managed devices, and turn on user notifications for every new authenticator enrolment.
- Brief users and helpdesk staff: IT will never call to ask a user to register a passkey. Verify caller identity through an established channel before acting.
- Monitor for the listed user-agent strings during SharePoint and OneDrive access. Block the IOCs at their respective controls.
Sources
- https://www.okta.com/en-au/blog/threat-intelligence/vishing-actors-target-microsoft-entra-passkey-enrollment-
- https://x.com/Unit42_Intel/status/2062216815967625558
Enjoyed reading this Threat Intelligence Advisory? Stay updated with our latest exclusive content by following us on Twitter and LinkedIn
No related posts found.