Home ยท Wiki ยท Entities & Threat Actors
type: entity ยท created: 2026-07-11 ยท updated: 2026-07-11 ยท tags: [cybercrime-group, technique] ยท confidence: medium ยท affected_sectors: [technology, healthcare, manufacturing, finance] ยท au_impact: false

O-UNC-066

O-UNC-066 is a threat actor tracked by Okta that uses voice phishing (vishing) to trick Microsoft 365 users into enrolling fake Microsoft Entra passkeys, thereby granting the attacker persistent access to victims' Microsoft 365 environments.

Attack Method

  1. Vishing call: Attacker calls the target, claims they need to register a new security passkey
  2. Fake enrollment flow: Victim is directed to a phishing kit that is identical to the legitimate Microsoft Entra passkey enrollment process (raw/digests/Cyber-Digest-2026-07-10)
  3. Credential theft: The fake passkey enrollment gives the attacker persistent access to the victim's Microsoft 365 account
  4. Bypasses MFA: The passkey-based approach circumvents traditional multi-factor authentication protections

Targets

The campaign targets a broad range of sectors, including: - Food & Beverage - Technology - Healthcare - Automotive - Construction - Aviation

Anyone with a Microsoft 365 tenant is potentially at risk. (raw/digests/Cyber-Digest-2026-07-11)

Related Pages