**The Rise of CEO Impersonation and Passkey Phishing in Modern Cyberattacks**
Cyber adversaries are continuously evolving their tactics, recently employing massive email blasts and sophisticated social engineering to breach corporate defenses. Two distinct and alarming campaigns have emerged in the current threat landscape, targeting financial systems and cloud infrastructure through highly deceptive means.
The first operation involved the mass distribution of over a million fraudulent emails over a very short period. Threat actors impersonated chief executive officers to pressure accounts payable departments into executing Automated Clearing House (ACH) transfers. The pretext was a supposed annual subscription renewal for a widely used service management platform. To make the messages compelling, the perpetrators utilized generative artificial intelligence to craft personalized email templates and draft convincing correspondence. The targets were primarily large enterprises in the United States, operating across IT services, consumer goods, real estate, and manufacturing sectors.
The attackers registered impersonation domains and embedded fake invoices alongside fabricated email chains. By inserting the names and email addresses of actual CEOs and CFOs into the signatures, the messages appeared highly legitimate. Bogus domains were used to mimic trusted vendors and reduce recipient skepticism. The spoofed messages contained a purported approval of the fake invoice, often accompanied by a forged email thread to trick recipients into making payments to attacker-controlled accounts.
The second campaign focused on infiltrating cloud environments through identity-focused social engineering. The activity has been detected recently and revolves around suspicious sign-ins followed by the threat actors adding their own authentication methods, as well as high-volume activity through cloud application programming interfaces, SharePoint, and OneDrive.
The attack commonly begins with the threat actors calling or messaging a user’s personal phone number, posing as internal IT support staff. They urgently instructed targets to update their passkeys, multi-factor authentication (MFA), or single sign-on (SSO) configurations to prevent service outages. Unsuspecting employees are then redirected to counterfeit websites that mimic the legitimate corporate sign-in experience via SMS messages sent to their personal devices. The end goal is to use the pretext to guide them through adversary-in-the-middle authentication flows and take control of their accounts either by capturing the credentials or unknowingly granting access on the actor’s behalf.
The threat actors appear to invest heavily in pre-attack research, likely gathering information about employees and organizational structure from public sources such as social networking and professional profiling platforms. In some cases, actors take advantage of already compromised accounts to expand their reach by sending similar passkey-themed messages through internal collaboration tools.
To facilitate the phishing, the attackers registered domains built around themes such as passkeys, SSO enrollment, account activation, and identity verification. They often included the target organization’s name as a subdomain, following the pattern of [company name].[malicious domain].com. Some of the registered domains include passkeyhelpdesk[.]com, secure-passkey[.]com, setupmypasskey[.]com, add-passkey[.]com, integratedsso[.]com, oktasession[.]com, syncmykey[.]com, and portalsetuphub[.]com. This modus operandi overlaps with a loose-knit cybercrime collective known for operating multiple public extortion brands while sharing overlaps in underlying phishing infrastructure. The initial access activity has been attributed to several threat clusters, including Storm-3121 and Storm-3032, which are associated with broader extortion syndicates that share initial access playbooks and commoditized phishing panels.
Following initial access, the actor’s first objective was to transform a temporary compromise into a persistent foothold. Rather than relying solely on stolen credentials, the actor enrolled MFA methods under their control, typically by registering a new phone number or authenticator application. An advantage this actor-controlled second factor offers is that it allows the threat actor to sign in to the victim’s corporate account without their participation and maintain continued access. Once established, the threat actor conducts extensive internal reconnaissance using cloud APIs to inventory users, groups, permissions, and resources. They inspect roles and high-value accounts for privilege escalation, enumerate mailbox messages for intelligence collection, and engage in high-volume access and download activity aimed at cloud storage and collaboration platforms. The sustained data exfiltration can last from several hours to multiple days, depending on the volume of files harvested. The actors deliberately rotate infrastructure across the attack lifecycle and use separate IP addresses for authentication, reconnaissance, and exfiltration activities to subvert network-based indicators.
**FAQ Section**
**1. How did the attackers convince finance teams to send money?**
They created a false sense of legitimacy by impersonating CEOs and embedding forged email threads alongside fake invoices, making the request look like an approved internal transaction for a known service.
**2. What is adversary-in-the-middle (AitM) phishing?**
It is a technique where the attacker positions themselves between the victim and the legitimate service, capturing session tokens or credentials in real-time as the user enters them on a fake portal that mimics the official login screen.
**3. Why is enrolling a new MFA method so dangerous for the victim?**
It allows the attacker to bypass the need for the victim’s active participation during future logins. By registering a second factor under their control, the attacker can sign in without the victim ever receiving an authentication prompt.
**4. How can organizations detect these cloud-based intrusions?**
By monitoring cloud application activity holistically rather than looking at single API requests. Unusual spikes in data downloads, mass mailbox enumeration, the addition of new authentication methods, and rotating IP addresses during an active session should trigger immediate investigation.
**5. What role did AI play in these attacks?**
Generative AI was used to rapidly produce personalized email templates and draft convincing executive-level communications, significantly reducing the time and effort required to launch large-scale, targeted phishing campaigns.
**Conclusion**
These campaigns highlight a dangerous convergence of social engineering, infrastructure abuse, and cloud exploitation. As adversaries leverage AI to scale their operations and continuously adapt their phishing lures around emerging authentication technologies, organizations must adopt a defense-in-depth strategy. Vigilance in verifying financial requests, scrutinizing sign-in attempts, and monitoring cloud application activity for anomalous behavior is no longer optional—it is a critical necessity for survival in the modern threat landscape.
Thank you for reading



