Storm-3121 Fakes Passkey Portals to Steal M365 Data
Microsoft links Storm-3121 (ShinyHunters) and Storm-3032 (Helix) to AiTM and device-code phishing against corporate M365 accounts since May 2026.

Three Microsoft-tracked threat clusters have been registering passkey and single sign-on-themed domains since May 2026, using them as staging infrastructure for adversary-in-the-middle phishing and device-code authentication abuse against corporate Microsoft 365 tenants. Microsoft disclosed the campaign this week, attributing it to Storm-3121 (overlapping ShinyHunters and Falcon extortion) and Storm-3032 (now operating as Helix, formerly BlackFile). Google Threat Intelligence tracks the same activity as UNC6671, connected to BlackFile, Helix, Falcon, Pink, and Redact groups.
How the infrastructure works
Attackers register domains combining a target company’s name with passkey or SSO terminology. Examples documented by Microsoft include passkeyhelpdesk[.]com, setupmypasskey[.]com, secure-passkey[.]com, and integratedsso[.]com. Subdomains incorporate the victim organization’s name to make the lure credible before the victim loads the page.
Initial contact comes by phone or SMS. Callers impersonate corporate IT help desks, drawing on LinkedIn and other public sources to match the caller’s claimed role and knowledge of internal team structure to the target. Victims who proceed are directed to phishing infrastructure through one of two methods.
The first is adversary-in-the-middle (AiTM): the page proxies a genuine Microsoft login in real time, capturing credentials and session tokens before forwarding the victim to a benign landing page. The second is device-code flow abuse: victims are walked through entering an attacker-supplied code on a legitimate Microsoft authentication page, which issues a valid OAuth token to an attacker-controlled application. Both paths bypass MFA because the token is what the attacker captures, not just the password.
What gets taken
After authentication, attackers use Microsoft Graph to enumerate the environment: users, groups, privileged directory roles, authentication methods, OAuth application permissions, and SharePoint site inventories. Exfiltration targets SharePoint Online documents, OneDrive for Business files, and Exchange Online mailboxes via REST API access.
In one documented intrusion, the attacker completed the MFA step, remained active for approximately one hour, and systematically listed sensitive files and applications before exiting. Persistence is established by registering new phone numbers, authenticator applications, or software-based TOTP tokens on the compromised account. Microsoft notes this persistence does not survive a complete credential and session reset, so full remediation requires resetting credentials, revoking active sessions, and removing attacker-added authentication methods, in that order.
Reducing exposure
Phishing-resistant MFA, specifically hardware security keys or certificate-based authentication, prevents token capture at the AiTM step by binding the authentication assertion to the origin. Microsoft recommends disabling device-code authentication flows where no legitimate workflow requires them, restricting access to sensitive cloud resources to managed devices only, and monitoring for unusual sign-ins followed immediately by new MFA method registrations.
The infrastructure and social-engineering model used here overlaps with the vishing-to-Entra-passkey campaign covered in July by Microsoft and Unit 42. That earlier wave focused on passkey registration takeover; the current campaign extends to broad SharePoint and Exchange exfiltration. Storm-3032’s prior use of OAuth abuse against Microsoft and Salesforce environments is detailed in reporting from the same period.
A parallel Helix campaign using helpdesk impersonation for similar M365 access objectives is covered in September’s fake-IT-call reporting.
Source: BleepingComputer, citing Microsoft Threat Intelligence disclosure, September 11, 2026.
Found this useful? Share it.


