O-UNC-066 ("Pink") Abuses Microsoft Entra Passkey Enrollment via Live-Operator Phone Phishing to Hijack Enterprise Accounts
O-UNC-066 ("Pink") Abuses Microsoft Entra Passkey Enrollment (TL-2026-1186), also tracked as Pink, is a high-severity phishing campaign, first published 2026-07-10. It is attributed to O-UNC-066 with medium confidence, affects Microsoft Microsoft Entra ID passkey self-service enrollment, maps to 18 MITRE ATT&CK techniques (T1078, T1078.004, T1098.005), and is covered by 9 detection rules and 22 indicators of compromise.
Key facts for TL-2026-1186
- Threat ID
- TL-2026-1186
- Also known as
- Pink, CL-CRI-1147, O-UNC-066
- Severity
- HIGH
- Status
- ACTIVE
- Category
- PHISHING
- First published
- 2026-07-10
- Last reviewed
- 2026-07-10
- Attribution
- O-UNC-066
- Attribution confidence
- MEDIUM
- Motivation
- FINANCIAL
- Target sectors
- food and beverage, technology, health, automotive, construction, aviation
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 22
Malware and tooling in O-UNC-066 ("Pink") Abuses Microsoft Entra Passkey Enrollment
Malware and tooling: Pink operator-controlled phishing panel
Since April 2026, threat actor O-UNC-066 (Okta) / CL-CRI-1147 (Palo Alto Networks Unit 42), operating a data-leak site named "Pink", has run live-operator vishing campaigns that trick employees into completing what appears to be Microsoft Entra passkey enrollment. Real-time operators relay victims' genuine MFA challenges to authenticate as the victim, then register an attacker-controlled passkey for persistent, password-reset-resistant access, followed by exfiltration of SharePoint/OneDrive data for extortion.
How O-UNC-066 ("Pink") Abuses Microsoft Entra Passkey Enrollment works
O-UNC-066, publicly branded "Pink" on its data-leak site (launched 2026-05-31) and tracked by Palo Alto Networks Unit 42 as CL-CRI-1147, is a financially motivated extortion group assessed to be affiliated with the decentralized cybercrime collective known as "The Com", the same loose network associated with Scattered Spider, ShinyHunters, and LAPSUS$. Since April 2026 the group has run a live-operator, phone-based social engineering (vishing) campaign against enterprise employees, using Microsoft's 2026 default rollout of passkey-enrollment "nudge" prompts as a pretext.
A caller impersonating IT support tells the target that a new Microsoft Entra passkey must be registered for security reasons and directs them to a phishing URL on an attacker-registered domain containing the word "passkey" (e.g. setpasskey[.]com), using a per-target subdomain ("[target-entity].[base-domain]") customized with the victim organization's real branding to look like a legitimate Entra enrollment portal.
The phishing kit is not a transparent adversary-in-the-middle (AitM) reverse proxy; it is an operator-controlled PHP panel that polls for instructions roughly once per second, letting a live human operator decide in real time which fake screen the victim sees next. The kit walks the victim through: an anti-analysis gate (/gate), username capture (/identify), password capture (/password, POSTed to a backend operator panel at /backend.php), a stalling "processing" screen (/processing) while the operator uses the stolen credentials to authenticate to the real Microsoft tenant, and then adaptive MFA-capture screens matched to whatever factor the real login actually prompts for: SMS OTP (/submit-otp), TOTP (/submit-authenticator), or push/number-matching approval (/approve-authenticator). Because the operator observes the real authentication flow and requests the matching code or approval from the victim, this functions as real-time MFA interception/relay rather than a bypass of any MFA weakness.
Once the operator has completed the real login, they use the legitimate Microsoft interface to register their own passkey against the victim's account. To keep the victim from noticing, the kit simultaneously displays a fake passkey-registration flow to the victim, including an arbitrary BIP-39-style "recovery seed phrase" that has no cryptographic relationship to Microsoft Entra passkeys and exists purely as a distraction (/passkey/register, /passkey, /passkey/check), before showing a false success page (/done). The victim believes they personally completed a routine security upgrade, and legitimate Microsoft notification emails about the new passkey are frequently dismissed as expected. Because passkeys are device-bound credentials independent of the password, the attacker-registered passkey survives a subsequent password reset, giving durable persistent access.
Post-compromise, Pink actors move quickly to collect and exfiltrate data from the victim's SharePoint and OneDrive services, then use the data-leak site to pressure victims into paying extortion demands rather than deploying ransomware. Observed targeting spans food and beverage, technology, healthcare, automotive, construction, and aviation organizations. The kit does not redirect through third-party identity providers, so organizations that route Microsoft 365 authentication through external IdP federation have not shown signs of direct compromise via this specific kit. There is no associated CVE — this is an identity/social-engineering abuse of a legitimate product feature (Entra passkey self-service enrollment), not a software vulnerability.
MITRE ATT&CK techniques used in TL-2026-1186
Defense Evasion
Persistence
T1078.004 Cloud Accounts; T1098.005 Device Registration
Credential Access
T1111 Multi-Factor Authentication Interception; T1552 Unsecured Credentials; T1621 Multi-Factor Authentication Request Generation
Collection
T1213.002 Sharepoint; T1530 Data from Cloud Storage
Discovery
Initial Access
Exfiltration
T1567 Exfiltration Over Web Service
Resource Development
T1583.001 Domains; T1583.004 Server; T1608.005 Link Target
Reconnaissance
T1589 Gather Victim Identity Information; T1591 Gather Victim Org Information
Impact
stealth
Affected products and versions in O-UNC-066 ("Pink") Abuses Microsoft Entra Passkey Enrollment
- Microsoft — Microsoft Entra ID passkey self-service enrollment
Vulnerable versions: Entra ID tenants with default/unmanaged passkey enrollment nudges enabled - Microsoft — Microsoft 365 (SharePoint Online, OneDrive)
Vulnerable versions: Any tenant accounts lacking phishing-resistant MFA/Conditional Access enforcement
Remediation for O-UNC-066 ("Pink") Abuses Microsoft Entra Passkey Enrollment
Immediate actions
- Block/deny inbound and DNS access to known Pink phishing domains: assignpasskey.com, deploypasskey.com, passkeydeploy.com, passkeyadd.com, setpasskey.com and their subdomains
- Configure network/identity zone policies to deny access from AS57724 (DDoS-Guard) and AS59692 (IQWeb FZ-LLC) where the organization has no legitimate business presence
- Audit Microsoft Entra ID for recently registered passkeys/authenticators that the account owner cannot confirm enrolling, and revoke unrecognized passkeys immediately
- Alert on and review any accounts that registered a new passkey shortly after a helpdesk/IT-support phone contact
Workarounds
- Disable or tightly restrict self-service passkey "nudge" enrollment prompts in Entra ID tenant settings until phishing-resistant, admin-verified enrollment workflows are in place
- Require number-matching push MFA plus out-of-band verification for any newly initiated authenticator/passkey registration
Longer-term hardening
- Enroll users in phishing-resistant authenticators (FIDO2 hardware security keys, platform passkeys bound via managed device attestation) rather than self-service, unmanaged passkey enrollment
- Configure alerts for all authenticator lifecycle events (registration, removal, recovery-method changes) and route them to security operations, not just the end user
- Restrict passkey/authenticator enrollment and sensitive app access based on device compliance status, geolocation, and network context (Conditional Access / network zones)
- Establish and train staff on an official, unspoofable identity-verification procedure for any inbound phone call claiming to be IT/helpdesk support before acting on enrollment requests
- Consider routing Microsoft 365 authentication through an external identity provider with federation, which this specific kit does not support redirecting through
Weaknesses (CWE) in O-UNC-066 ("Pink") Abuses Microsoft Entra Passkey Enrollment
CWE-287, CWE-1390
Timeline of O-UNC-066 ("Pink") Abuses Microsoft Entra Passkey Enrollment
- O-UNC-066 ("Pink") begins live-operator vishing campaign abusing Microsoft Entra passkey enrollment against enterprise employees, per Okta Threat Intelligence.
- Domain deploypasskey.com registered via Tucows, hosted behind DDoS-Guard — earliest observed Pink phishing infrastructure.
- Domain passkeydeploy.com registered, mirroring deploypasskey.com naming pattern.
- Domain passkeyadd.com registered via Tucows behind DDoS-Guard.
- Domain setpasskey.com registered, hosted via IQWeb FZ-LLC (AS59692).
- Pink data-leak site goes live to publicly pressure compromised victims into paying extortion demands.
- The Register publishes early public reporting on Pink's fake-helpdesk vishing campaign.
- Domain assignpasskey.com registered — latest observed base domain in the campaign's infrastructure.
- Widespread security-media coverage (Cyber Security News, BleepingComputer, The Hacker News, GBHackers, CyberPress, TechNadu) amplifies the Okta report.
- Okta Threat Intelligence publishes full technical writeup attributing the campaign to O-UNC-066, cross-referencing Palo Alto Networks Unit 42's CL-CRI-1147 tracking and detailing the operator-controlled phishing kit.
Sources cited for O-UNC-066 ("Pink") Abuses Microsoft Entra Passkey Enrollment
- Hackers Abuse Microsoft Entra Passkey Enrollment to Hijack Enterprise Accounts
- Vishing actors target Microsoft Entra passkey enrollment
- Hackers Use Fake Microsoft Entra Passkey Enrollment to Gain Microsoft 365 Access
- Entra passkey enrollment vishing targets Microsoft 365 users
- Pink is the latest goon squad to use fake helpdesk calls to steal creds
- O-UNC-066 Vishing Targets Microsoft Entra Passkey Enrollment
- Microsoft Entra Passkey Enrollment Abused in Operator-Controlled Vishing Campaign
- Fake Microsoft Passkey Flow Uses BIP-39 Seed Phrase Distraction During Account Takeover
Threats related to O-UNC-066 ("Pink") Abuses Microsoft Entra Passkey Enrollment
- UNC6671 Automates Microsoft 365 Data Theft via Vishing-Driven AiTM Phishing and Session Hijacking
- UNC6671 Rebrands BlackFile into Redact, Pink, Helix, Falcon: Vishing + AiTM Campaign Steals M365/Okta Data for Extortion
- ShinyHunters Extortion Group Claims 284M-Record McKesson Corporation Data Breach via Vishing and Salesforce/Snowflake Compromise
- Kali365 (K365) PhaaS Expansion — OAuth Device-Code Token Theft Beyond M365 to Okta SSO, AWS, Xerox DocuShare & MAX Messenger (126-Host Cluster, Live C2 Panel)
- Misconfigured Server Exposes Three Evilginx-Based Microsoft 365 Phishing Operations (codemado, mail-argenta, saroula01)
- AI Voice-Cloning Vishing Wave Hits Point72, Citadel, Two Sigma, Millennium Management — Tied to UNC6671 (BlackFile/Redact) Extortion Group
Detection coverage for TL-2026-1186
As of 2026-07-10, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1186 across Splunk SPL, Microsoft KQL and Sigma, covering 22 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.