
Fake Install Guides and Helpdesk Calls Drive Attacks
This bulletin describes multiple real-world social engineering campaigns where attackers trick people into trusting a familiar screen, like a search result…
The “Pink” data extortion group is running a real-world voice phishing campaign targeting employees in Microsoft 365 / Entra ID environments. Callers impersonate the internal IT helpdesk and direct staff to realistic lookalike login sites timed to Microsoft’s passkey-enrollment prompts, enabling attackers to register their own passkey and gain persistent access. A notable tell is a fake “recovery” page showing crypto-style BIP-39 seed phrases, which do not belong in Microsoft Entra flows.
The group known as Pink (also tracked as O-UNC-066 or CL-CRI-1147) runs a voice phishing campaign against Microsoft 365 and Entra ID users, active since April 2026 and surging through July 2026. Callers pose as internal IT helpdesk staff, telling employees they need to complete a Microsoft Entra passkey enrollment step. Victims are directed to a realistic, employer-branded lookalike subdomain to sign in, timed to coincide with Microsoft's own passkey enrollment nudges so the request feels expected.
Once on the fake site, victims are shown a Microsoft-branded page presenting a list of BIP-39 seed phrases and told to write them down as an identity backup. This step has no legitimate place in Entra ID login flows. While the victim is occupied copying down the words, the attacker quietly registers their own persistent, phishing-resistant passkey on the victim's real Entra profile, gaining long-term access without needing further credentials or MFA prompts.
The campaign blends several elements that make it hard to spot:
This combination lets the attacker register a passkey that grants ongoing access, described as a definitive indicator of compromise once identified, without immediately alarming the victim.
Employees and security teams should treat the following as red flags:
Because BIP-39 seed phrases have no technical function within Microsoft Entra ID, seeing them during a corporate login should be treated as an active compromise signal.
Organizations can reduce exposure to this pattern with a mix of process and technical controls:
These steps target the specific mechanics of this campaign, from the initial vishing call to the final passkey registration that gives attackers persistent access to systems like SharePoint and OneDrive.
Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.
It is a voice phishing operation in which callers impersonate internal IT helpdesk staff and direct employees to employer-branded lookalike login pages to hijack their Microsoft Entra ID accounts.
The seed phrase screen is a distraction that keeps the victim occupied while the attacker registers their own phishing-resistant passkey on the victim's real Entra profile, since seed phrases have no legitimate role in Entra ID.
Recommended mitigations include restricting passkey registration to known corporate IP ranges, monitoring logs for newly bound passkeys with benign names, and enforcing out-of-band verification for unsolicited IT calls.
They should hang up and verify the request through a known internal number rather than following any link or instructions given during the call.
You get a call: “Hi, this is IT Helpdesk. We need to finish your Microsoft Entra passkey registration right now.” This is the Pink vishing crew. They walk you to a company-branded lookalike login site, then a fake Microsoft recovery page that shows a list of crypto-style BIP-39 seed words and tells you to write them down. Here’s the trick: while you’re busy copying those seed words, they’re on your real Entra profile in the background, quietly registering their own passkey so they can live in your SharePoint and OneDrive. Aha moment: Microsoft never shows crypto seed phrases. If an IT caller sends you to a login page and you see BIP-39 words, hang up and call the real helpdesk number yourself.

This bulletin describes multiple real-world social engineering campaigns where attackers trick people into trusting a familiar screen, like a search result…

Okta says it gained an inside look at “Work Panel,” a polished SaaS-style dashboard that helps voice-phishing (vishing) crews rapidly set up fake login sites…

This roundup describes several real-world social-engineering and human-abuse techniques, including trojanized “installer” lures (ClickFix), large-scale…

The article describes real-world ways attackers get around multifactor authentication (MFA), including “push bombing” (MFA fatigue), phishing pages that relay…

Amazon says North Korea-linked actors compromised widely used npm packages (including debug and chalk) by tricking a trusted maintainer into signing in through…

Check Point reports that scammers are now impersonating ChatGPT/OpenAI in phishing campaigns, reflecting how mainstream the service has become. One documented…