O-UNC-066 (Pink) Abuses Microsoft Entra Passkey Enrollment Feature in Active M365 Vishing Campaign
Okta Threat Intelligence has attributed a multi-sector vishing campaign active since April 2026 to O-UNC-066 (also tracked as Pink/CL-CRI-1147, affiliated with The Com), which calls employees impersonating IT support and directs them to operator-controlled phishing kits that mimic Microsoft Entra passkey enrollment — registering attacker-controlled passkeys against victim accounts in real time. The kit exploits Microsoft's May 2026 enterprise passkey registration campaign feature, weaponizing the rollout of phishing-resistant auth as a new social-engineering surface. After takeover, operators rapidly exfiltrate SharePoint and OneDrive data for extortion; Pink launched a dedicated leak site on May 31 and has claimed victims across healthcare, automotive, aviation, and technology verticals.
The kit exploits Microsoft's May 2026 enterprise passkey registration campaign feature, weaponizing the rollout of phishing-resistant auth as a new social-engineering surface.
This intelligence brief has been compiled from open-source reporting and corroborated across multiple threat intelligence sources. Defenders should treat the critical severity rating as a guide to prioritization within their environment.
For the latest indicators of compromise, formatted SIEM queries, and unredacted actor intelligence related to this brief, DMZ Operator subscribers receive automated IOC packages via email the moment new advisories are published.