Cybercriminals are now using highly sophisticated off-the-shelf phishing kits, complete with easy-to-use dashboards, to enable highly effective vishing attacks, initially targeting key staff members via phone calls. US identity and access management company Okta has observed a threat actor deploying a phishing kit that targets the passkey enrollment process for Microsoft 365 users, in which the actor calls targeted users in a voice-enabled phishing scheme, or "vishing."
Okta reports that the primary motivation for the campaign is data extortion, targeting organizations spanning in the technology, healthcare, construction and aviation industries. These attacks are coming at a very strategic time – as of May 2026, Microsoft administrators are able to configure campaigns to "nudge" users to register passkeys during sign-in, to help organizations "drive passkey adoption at scale." Ironically, threat actors are now using these reminders to their advantage, mimicking passkey enrolment pages to advance their campaign.
Panel-controlled phishing kits
Until recently, the most common phishing methods involved impersonating IT support to trick victims into signing in with their credentials and OTPs on malicious phishing websites. However, these methods have been rendered less successful now that phishing-resistant authenticators have become commonplace, forcing threat actors to innovate.
This phishing kit is not a simple Adversary-in-The-Middle (AiTM) attack, which is the more frequently used method for hackers to harvest credentials and MFA tokens. It is a panel-controlled phishing kit, including a web-based administration panel for managing phishing campaigns. More than just a fake log-in page, it provides hackers with a dashboard to control, monitor, and collect stolen information.
The scam starts with the threat actor calling a targeted user on the phone, trying to convince them to register a new passkey. Users are then directed to the phishing kit, which closely replicates Microsoft Entra ID login pages and is customized with each victim's organization's logo and branding. The first few pages request the user's username and password, which get sent to the hacker's administration panel. Next is a "processing" page, in which the user is presented with a loading screen – presumably to buy the threat actor time to log into the user's legitimate Microsoft account using the harvested credentials and see what multi-factor authentication (MFA) challenges are presented. The threat actor can then, in real time, adjust the phishing pages that the user sees.
The user is then tricked into entering a one-time password (OTP), giving the threat actor access to their Microsoft account. The final stages of the campaign include a false passkey enrollment page, in which the user is duped into thinking they are registering a passkey in Microsoft, when in reality the threat actor is registering their own passkey into the user's account.
After successfully completing the phishing kit, the threat actor now has access to the user's Microsoft account without requiring any input from the real account holder.
This campaign preys on users who are unfamiliar with the passkey authentication process. Okta recommends that organizations strengthen account management policies by requiring phishing-resistant MFA's and stricter verification for account enrollment in order to subdue these attacks.
