Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Multi-Brand Vishing Extortion Targets Financial Services and Enterprise Cloud Environments

0
Medium
Published: 08/06/2026 (08/06/2026, 22:15:43 UTC)
Source: AlienVault OTX General

Description

UNC6671 continues conducting data theft extortion operations despite the alleged retirement of the BlackFile brand in May 2026. The threat actor has diversified across multiple extortion fronts including Redact, Pink, Helix, and Falcon. They employ voice phishing tactics, posing as IT helpdesk staff to contact employees on personal mobile devices, directing them to spoofed login portals with Adversary-in-the-Middle infrastructure that intercepts credentials and multi-factor authentication tokens. Once access is established, automated scripts exfiltrate data from enterprise cloud environments including Microsoft 365 and Okta. Infrastructure analysis reveals shared phishing panels, overlapping victim targeting, and connected domains across all brands. Recent targeting has evolved toward financial services, private equity, legal, and professional services sectors. Between January and May 2026, Bitcoin wallet analysis showed approximately $10.69 million USD in ransom payments, with demands typically ranging fr...

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/07/2026, 10:28:59 UTC

Technical Analysis

The threat actor UNC6671 continues data theft extortion operations using multiple brands including Redact, Pink, Helix, and Falcon. They employ vishing tactics by calling employees on personal mobile devices, posing as IT helpdesk personnel, and directing victims to spoofed login portals that intercept credentials and MFA tokens via adversary-in-the-middle infrastructure. This access is used to automate data exfiltration from enterprise cloud environments like Microsoft 365 and Okta. Infrastructure analysis shows shared phishing infrastructure and overlapping victim targeting across brands. The campaign has evolved to focus on financial services and related sectors, with ransom payments totaling approximately $10.69 million USD between January and May 2026.

Potential Impact

Successful exploitation leads to credential and MFA token theft, enabling unauthorized access to enterprise cloud environments. This results in automated exfiltration of sensitive data from services such as Microsoft 365 and Okta. The financial impact includes significant ransom payments, with demands typically in the hundreds of thousands of dollars. The campaign affects critical sectors including financial services, private equity, legal, and professional services, potentially causing operational disruption and data breaches.

Defensive Guidance

No official patch or fix applies as this is a social engineering and credential theft campaign. Organizations should enhance employee awareness about vishing attacks, verify helpdesk requests through independent channels, and monitor for suspicious login activity. Use of phishing-resistant MFA methods is recommended to reduce risk. Since this is an ongoing extortion campaign, continuous vigilance and incident response preparedness are advised.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Author
AlienVault
Tlp
white
References
["https://cloud.google.com/blog/topics/threat-intelligence/unc6671-targets-financial-services-and-enterprise-cloud-environments"]
Adversary
UNC6671
Pulse Id
6a75078f7b8e057bc29b8769
Threat Score
null

Indicators of Compromise

Domain

ValueDescriptionCopy
domainoktaenroll.com
domainidokta.com
domainmyoktasso.com
domainmypasskeysso.com
domainsetupssopasskey.com
domainpasskeyms.com
domainkeyokta.com
domainportalpasskey.com
domainoktaportalsso.com
domainpasskeyportal.com
domainpasskeyportalsetup.com
domainaddoktapasskey.com
domaindeploypasskey.com
domainmysecurepasskey.com
domainactivatemypasskey.com
domaincreatepasskey.com
domainregisterpasskey.com
domainsetupsso.com
domainpasskeycenter.com
domainpasskeyregister.com
domainsecureauthpasskey.com
domaincreatemypasskey.com
domainpasskeyset.com
domainpasskeyokta.com
domainpasskeyadd.com
domainpasskeydeploy.com
domainsetpasskey.com
domainaddmypasskey.com
domainpasskey-portal.com
domainpasskeyregistration.com
domainportalsetuphub.com
domainmynewpasskey.com
domainmyconnectkey.com
domainenablepasskey2fa.com
domainpasskeyuser.com
domainpasskeyenroll.com
domainstartpasskey.com
domainoskeysync.com
domainassignpasskey.com
domainkeysyncos.com
domainpasskeyhelpdesk.com
domainpasskeycreate.com
domainpasskeysupport.com
domaincreatessopasskey.com
domainactivatepasskey.com
domainactivatepasskeyportal.com
domainadd-passkey.com
domainaddpasskey2fa.com
domainaddssopasskey.com
domainaddyourpasskey.com
domaincheckpasskey.com
domaincreatemfa.com
domainenablepasskey.com
domainenrollpasskey.com
domainhubpasskey.com
domainmakepasskey.com
domainmspasskey.com
domainmyaccountsecurity.com
domainmypasskeyid.com
domainmyssopasskey.com
domainnewpasskey.com
domainoskeyconnect.com
domainpasskey-check.com
domainpasskey-connect.com
domainpasskey-enable.com
domainpasskeyactivation.com
domainpasskeycreator.com
domainpasskeyenable.com
domainpasskeymfa.com
domainpasskeyrollout.com
domainpasskeystatus.com
domainsecure-passkey.com
domainsqfepjvmrd.xyz
domainssopasskey.com
domainstartpasskeysetup.com

Ip

ValueDescriptionCopy
ip107.128.45.122
ip38.42.59.171
ip47.218.103.146
ip76.103.148.180

Threat ID: 6a75af5dbf8831d539217dbd

Added to database: 08/07/2026, 10:11:41 UTC

Last enriched: 08/07/2026, 10:28:59 UTC

Last updated: 08/07/2026, 16:26:00 UTC

Views: 18

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses