Online Security & Privacy

Microsoft Uncovers Sophisticated Dual-Front Cyber Campaign Combining AI-Driven Invoice Fraud and Identity-Based Cloud Intrusions

Microsoft’s threat intelligence division has released a comprehensive report detailing a pair of high-stakes cyber campaigns that demonstrate an alarming evolution in the tactics used by threat actors to breach enterprise environments. The disclosures highlight two distinct, yet equally dangerous, methodologies: a massive, AI-enhanced financial fraud operation targeting corporate finance departments and a persistent, identity-focused social engineering scheme designed to compromise cloud-based authentication systems. These findings underscore a critical shift in the threat landscape, where attackers are increasingly leveraging generative artificial intelligence to manufacture credibility and targeting specific organizational vulnerabilities to bypass robust security measures.

The Rise of AI-Assisted Executive Impersonation

The first campaign, active between August 3 and August 5, 2026, involved the deployment of over one million malicious emails. This operation represented a significant departure from traditional, broad-spectrum phishing. Instead, the attackers employed a highly coordinated, multi-layered strategy that mimicked legitimate business communications with startling precision. By impersonating high-ranking executives—specifically CEOs and CFOs—the attackers targeted accounts payable departments across sectors including IT services, consumer goods, real estate, and manufacturing.

Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data

The core objective was to coerce financial personnel into initiating Automated Clearing House (ACH) transfers under the guise of paying for an annual ServiceNow subscription. What distinguished this campaign was the integration of generative AI. The attackers utilized these tools to generate hyper-personalized email templates, synthesize realistic professional correspondence, and craft forged invoices that appeared to originate from trusted vendors. By layering executive impersonation with fabricated email threads that included "approvals" from leadership, the threat actors successfully reduced the natural skepticism of financial employees.

The sophistication of this approach reflects a growing trend in business email compromise (BEC) attacks. By populating email signatures with the accurate names and contact information of company leadership—information often scraped from professional networking sites—the attackers created a veneer of legitimacy that bypassed standard automated filters. Microsoft’s analysis suggests that the primary defense against such attacks is no longer just technical, but human: the verification of payment requests through out-of-band communication channels remains the most effective deterrent against these AI-driven fabrications.

Chronology of the Identity-Focused Cloud Compromise

The second campaign, which has been monitored since May 2026, focuses on the persistent compromise of cloud identities. Unlike the invoice fraud campaign, which seeks immediate financial gain, this operation aims to establish long-term, stealthy access to enterprise data. The threat actors have been observed utilizing sophisticated "vishing" (voice phishing) and social engineering techniques to manipulate employees into granting them access to secure accounts.

Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data

The attack lifecycle generally follows a predictable but highly effective sequence:

  1. Pre-Attack Reconnaissance: The actors gather detailed intelligence on organizational structure and specific employee roles using public professional profiles.
  2. Initial Contact: Attackers initiate contact via personal phone numbers or messaging platforms, posing as IT help desk staff.
  3. The Pretext: The victim is informed of an urgent need to update their passkey, multi-factor authentication (MFA), or single sign-on (SSO) configurations to prevent a service disruption.
  4. Credential Harvesting: The employee is directed to a counterfeit portal that perfectly replicates the Microsoft login experience.
  5. Session Hijacking: The attackers utilize adversary-in-the-middle (AitM) techniques or device-code authentication flows to capture credentials or session tokens, thereby bypassing standard MFA protections.

Once initial access is secured, the attackers prioritize persistence. In a significant number of cases, the actors registered their own MFA methods—such as a new phone number, authenticator app, or OTP token—under their control. This maneuver effectively locks the legitimate user out of the decision-making loop and allows the attackers to maintain a foothold in the corporate environment, even if the user changes their password.

Infrastructure and Attribution: The UNC6671 Connection

Microsoft has linked these identity-focused attacks to a loose-knit but highly coordinated cybercrime ecosystem. Cybersecurity researchers have tracked these actors under several aliases, including Cordial Spider, O-UNC-045, PREY-0058, and most notably, UNC6671. This group is known for operating multiple public extortion brands, such as the "Helix" extortion collective, which represents a rebranding of previous efforts by former members of the BlackFile group.

Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data

The infrastructure used by these actors is characterized by the use of generic root domains combined with victim-specific subdomains. For instance, a target company might receive a request to log in to a domain formatted as [company-name].[malicious-domain].com. This granular level of targeting suggests that the threat actors are not merely casting a wide net but are conducting specific campaigns against high-value targets. Microsoft has attributed the activity to specific "Storm" designations—Storm-3121 and Storm-3032—noting that these actors share access to commoditized phishing panels and infrastructure, suggesting a "phishing-as-a-service" model that allows even less skilled affiliates to execute high-impact breaches.

Broader Implications and Defensive Challenges

The implications of these campaigns are profound for modern enterprise security. The shift toward abusing Microsoft Graph APIs for post-exploitation reconnaissance is particularly concerning. Once an attacker has established a persistent foothold, they use these APIs to systematically enumerate sensitive files, download content from SharePoint and OneDrive, and gain deep insights into internal corporate services.

Microsoft’s security team has noted that the primary challenge in detecting this activity lies in the nature of the API calls themselves. A single Graph API request often appears benign. It is only when the activity is analyzed holistically—looking at the progression of events and cross-referencing user behavior—that the malicious intent becomes clear. This necessitates a move away from static, signature-based detection toward behavioral analytics that prioritize intent-based monitoring.

Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data

Furthermore, the abuse of MFA registration highlights the "human element" as the weakest link in the security chain. Even as organizations transition to more secure methods like passkeys, threat actors are adapting their social engineering scripts to exploit the confusion surrounding these new technologies. The goal of the attacker is to make the victim feel that their security is at risk, prompting them to act quickly and bypass standard safety protocols.

Strategic Recommendations

In response to these findings, cybersecurity experts emphasize several critical defensive layers:

  • Zero Trust Architecture: Organizations must assume that internal networks are compromised and implement strict identity verification for every access request, regardless of its origin.
  • Holistic Monitoring: Security Operations Centers (SOCs) should focus on "behavioral progression." Rather than alerting on individual API calls, systems should trigger warnings when a series of seemingly routine actions (like a sign-in from an unusual device followed by an API query) deviates from a baseline.
  • Out-of-Band Verification: For financial transactions, companies must implement a mandatory policy requiring verbal or secondary channel confirmation for any change in payment details or large transfers, regardless of who appears to be sending the request.
  • Employee Awareness Training: Training programs must evolve to reflect modern vishing and smishing tactics, specifically warning employees that IT departments will never ask for MFA credentials or passkey overrides over the phone.

As threat actors continue to integrate generative AI into their workflows, the speed and scale of these attacks will likely increase. The ability of groups like UNC6671 to pivot between extortion, data theft, and financial fraud indicates that the digital threat landscape is becoming increasingly fluid. For the modern enterprise, the primary lesson is clear: technical safeguards are vital, but they are only as effective as the processes that govern their use and the awareness of the employees tasked with upholding them. Security, in this new era, must be treated not as a static configuration, but as a dynamic and continuous dialogue between the organization and its users.

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *

Back to top button