Executive Summary
Since May 2026, Microsoft has tracked sophisticated cloud intrusions attributed to a range of actors including Storm-3121 (linked to ShinyHunters and Falcon extortion) and Storm-3032 (a splinter of BlackFile operating under the Helix brand). The campaign leverages high-fidelity social engineering, including vishing and SMS, to lure victims into completing Adversary-in-the-Middle (AiTM) or device-code authentication flows under the guise of mandatory passkey or SSO updates.
Technically, the actors follow a structured lifecycle: identity compromise, MFA persistence through unauthorized device registration, extensive tenant reconnaissance via Microsoft Graph, and automated data collection from SharePoint, OneDrive, and Exchange. The actors often rotate infrastructure and use separate IP addresses for different attack stages to evade traditional network-based detection, preferring a measured pace of exfiltration to blend with legitimate enterprise traffic.
The business impact is severe, involving the potential exfiltration of sensitive organizational data, email correspondence, and internal documentation. Affected sectors include IT services, consumer goods, real estate, and discrete manufacturing, primarily in the U.S. Organizations are urged to move toward phishing-resistant MFA and monitor for specific behavioral sequences in cloud audit logs.
Key Details
Threat Name
Storm-3121 and Storm-3032 Passkey Phishing
Affects
—
Adversary
Storm-3121 Other Adversaries and Aliases: Storm-3032; BlackFile group; UNC6671; ShinyHunters; Falcon; BlackFile; Helix
MITRE Techniques
Malware/Tools
python-httpx, Helix, Falcon
