Multi-Brand Vishing Extortion Targets Financial Services and Enterprise Cloud Environments
UNC6671 continues conducting data theft extortion operations despite the alleged retirement of the BlackFile brand in May 2026. The threat actor has diversified across multiple extortion fronts including Redact, Pink, Helix, and Falcon. They employ voice phishing tactics, posing as IT helpdesk staff to contact employees on personal mobile devices, directing them to spoofed login portals with Adversary-in-the-Middle infrastructure that intercepts credentials and multi-factor authentication tokens. Once access is established, automated scripts exfiltrate data from enterprise cloud environments including Microsoft 365 and Okta. Infrastructure analysis reveals shared phishing panels, overlapping victim targeting, and connected domains across all brands. Recent targeting has evolved toward financial services, private equity, legal, and professional services sectors. Between January and May 2026, Bitcoin wallet analysis showed approximately $10.69 million USD in ransom payments, with demands typically ranging fr...
AI Analysis
Technical Summary
The threat actor UNC6671 continues data theft extortion operations using multiple brands including Redact, Pink, Helix, and Falcon. They employ vishing tactics by calling employees on personal mobile devices, posing as IT helpdesk personnel, and directing victims to spoofed login portals that intercept credentials and MFA tokens via adversary-in-the-middle infrastructure. This access is used to automate data exfiltration from enterprise cloud environments like Microsoft 365 and Okta. Infrastructure analysis shows shared phishing infrastructure and overlapping victim targeting across brands. The campaign has evolved to focus on financial services and related sectors, with ransom payments totaling approximately $10.69 million USD between January and May 2026.
Potential Impact
Successful exploitation leads to credential and MFA token theft, enabling unauthorized access to enterprise cloud environments. This results in automated exfiltration of sensitive data from services such as Microsoft 365 and Okta. The financial impact includes significant ransom payments, with demands typically in the hundreds of thousands of dollars. The campaign affects critical sectors including financial services, private equity, legal, and professional services, potentially causing operational disruption and data breaches.
Mitigation Recommendations
No official patch or fix applies as this is a social engineering and credential theft campaign. Organizations should enhance employee awareness about vishing attacks, verify helpdesk requests through independent channels, and monitor for suspicious login activity. Use of phishing-resistant MFA methods is recommended to reduce risk. Since this is an ongoing extortion campaign, continuous vigilance and incident response preparedness are advised.
Indicators of Compromise
- domain: oktaenroll.com
- domain: idokta.com
- domain: myoktasso.com
- domain: mypasskeysso.com
- domain: setupssopasskey.com
- domain: passkeyms.com
- domain: keyokta.com
- domain: portalpasskey.com
- domain: oktaportalsso.com
- domain: passkeyportal.com
- domain: passkeyportalsetup.com
- domain: addoktapasskey.com
- domain: deploypasskey.com
- domain: mysecurepasskey.com
- domain: activatemypasskey.com
- domain: createpasskey.com
- domain: registerpasskey.com
- domain: setupsso.com
- domain: passkeycenter.com
- domain: passkeyregister.com
- domain: secureauthpasskey.com
- domain: createmypasskey.com
- domain: passkeyset.com
- domain: passkeyokta.com
- domain: passkeyadd.com
- domain: passkeydeploy.com
- domain: setpasskey.com
- domain: addmypasskey.com
- domain: passkey-portal.com
- domain: passkeyregistration.com
- domain: portalsetuphub.com
- domain: mynewpasskey.com
- domain: myconnectkey.com
- domain: enablepasskey2fa.com
- domain: passkeyuser.com
- domain: passkeyenroll.com
- domain: startpasskey.com
- domain: oskeysync.com
- domain: assignpasskey.com
- domain: keysyncos.com
- domain: passkeyhelpdesk.com
- domain: passkeycreate.com
- domain: passkeysupport.com
- domain: createssopasskey.com
- ip: 107.128.45.122
- ip: 38.42.59.171
- ip: 47.218.103.146
- ip: 76.103.148.180
- domain: activatepasskey.com
- domain: activatepasskeyportal.com
- domain: add-passkey.com
- domain: addpasskey2fa.com
- domain: addssopasskey.com
- domain: addyourpasskey.com
- domain: checkpasskey.com
- domain: createmfa.com
- domain: enablepasskey.com
- domain: enrollpasskey.com
- domain: hubpasskey.com
- domain: makepasskey.com
- domain: mspasskey.com
- domain: myaccountsecurity.com
- domain: mypasskeyid.com
- domain: myssopasskey.com
- domain: newpasskey.com
- domain: oskeyconnect.com
- domain: passkey-check.com
- domain: passkey-connect.com
- domain: passkey-enable.com
- domain: passkeyactivation.com
- domain: passkeycreator.com
- domain: passkeyenable.com
- domain: passkeymfa.com
- domain: passkeyrollout.com
- domain: passkeystatus.com
- domain: secure-passkey.com
- domain: sqfepjvmrd.xyz
- domain: ssopasskey.com
- domain: startpasskeysetup.com
Multi-Brand Vishing Extortion Targets Financial Services and Enterprise Cloud Environments
Description
UNC6671 continues conducting data theft extortion operations despite the alleged retirement of the BlackFile brand in May 2026. The threat actor has diversified across multiple extortion fronts including Redact, Pink, Helix, and Falcon. They employ voice phishing tactics, posing as IT helpdesk staff to contact employees on personal mobile devices, directing them to spoofed login portals with Adversary-in-the-Middle infrastructure that intercepts credentials and multi-factor authentication tokens. Once access is established, automated scripts exfiltrate data from enterprise cloud environments including Microsoft 365 and Okta. Infrastructure analysis reveals shared phishing panels, overlapping victim targeting, and connected domains across all brands. Recent targeting has evolved toward financial services, private equity, legal, and professional services sectors. Between January and May 2026, Bitcoin wallet analysis showed approximately $10.69 million USD in ransom payments, with demands typically ranging fr...
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The threat actor UNC6671 continues data theft extortion operations using multiple brands including Redact, Pink, Helix, and Falcon. They employ vishing tactics by calling employees on personal mobile devices, posing as IT helpdesk personnel, and directing victims to spoofed login portals that intercept credentials and MFA tokens via adversary-in-the-middle infrastructure. This access is used to automate data exfiltration from enterprise cloud environments like Microsoft 365 and Okta. Infrastructure analysis shows shared phishing infrastructure and overlapping victim targeting across brands. The campaign has evolved to focus on financial services and related sectors, with ransom payments totaling approximately $10.69 million USD between January and May 2026.
Potential Impact
Successful exploitation leads to credential and MFA token theft, enabling unauthorized access to enterprise cloud environments. This results in automated exfiltration of sensitive data from services such as Microsoft 365 and Okta. The financial impact includes significant ransom payments, with demands typically in the hundreds of thousands of dollars. The campaign affects critical sectors including financial services, private equity, legal, and professional services, potentially causing operational disruption and data breaches.
Defensive Guidance
No official patch or fix applies as this is a social engineering and credential theft campaign. Organizations should enhance employee awareness about vishing attacks, verify helpdesk requests through independent channels, and monitor for suspicious login activity. Use of phishing-resistant MFA methods is recommended to reduce risk. Since this is an ongoing extortion campaign, continuous vigilance and incident response preparedness are advised.
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://cloud.google.com/blog/topics/threat-intelligence/unc6671-targets-financial-services-and-enterprise-cloud-environments"]
- Adversary
- UNC6671
- Pulse Id
- 6a75078f7b8e057bc29b8769
- Threat Score
- null
Indicators of Compromise
Domain
| Value | Description | Copy |
|---|---|---|
domainoktaenroll.com | — | |
domainidokta.com | — | |
domainmyoktasso.com | — | |
domainmypasskeysso.com | — | |
domainsetupssopasskey.com | — | |
domainpasskeyms.com | — | |
domainkeyokta.com | — | |
domainportalpasskey.com | — | |
domainoktaportalsso.com | — | |
domainpasskeyportal.com | — | |
domainpasskeyportalsetup.com | — | |
domainaddoktapasskey.com | — | |
domaindeploypasskey.com | — | |
domainmysecurepasskey.com | — | |
domainactivatemypasskey.com | — | |
domaincreatepasskey.com | — | |
domainregisterpasskey.com | — | |
domainsetupsso.com | — | |
domainpasskeycenter.com | — | |
domainpasskeyregister.com | — | |
domainsecureauthpasskey.com | — | |
domaincreatemypasskey.com | — | |
domainpasskeyset.com | — | |
domainpasskeyokta.com | — | |
domainpasskeyadd.com | — | |
domainpasskeydeploy.com | — | |
domainsetpasskey.com | — | |
domainaddmypasskey.com | — | |
domainpasskey-portal.com | — | |
domainpasskeyregistration.com | — | |
domainportalsetuphub.com | — | |
domainmynewpasskey.com | — | |
domainmyconnectkey.com | — | |
domainenablepasskey2fa.com | — | |
domainpasskeyuser.com | — | |
domainpasskeyenroll.com | — | |
domainstartpasskey.com | — | |
domainoskeysync.com | — | |
domainassignpasskey.com | — | |
domainkeysyncos.com | — | |
domainpasskeyhelpdesk.com | — | |
domainpasskeycreate.com | — | |
domainpasskeysupport.com | — | |
domaincreatessopasskey.com | — | |
domainactivatepasskey.com | — | |
domainactivatepasskeyportal.com | — | |
domainadd-passkey.com | — | |
domainaddpasskey2fa.com | — | |
domainaddssopasskey.com | — | |
domainaddyourpasskey.com | — | |
domaincheckpasskey.com | — | |
domaincreatemfa.com | — | |
domainenablepasskey.com | — | |
domainenrollpasskey.com | — | |
domainhubpasskey.com | — | |
domainmakepasskey.com | — | |
domainmspasskey.com | — | |
domainmyaccountsecurity.com | — | |
domainmypasskeyid.com | — | |
domainmyssopasskey.com | — | |
domainnewpasskey.com | — | |
domainoskeyconnect.com | — | |
domainpasskey-check.com | — | |
domainpasskey-connect.com | — | |
domainpasskey-enable.com | — | |
domainpasskeyactivation.com | — | |
domainpasskeycreator.com | — | |
domainpasskeyenable.com | — | |
domainpasskeymfa.com | — | |
domainpasskeyrollout.com | — | |
domainpasskeystatus.com | — | |
domainsecure-passkey.com | — | |
domainsqfepjvmrd.xyz | — | |
domainssopasskey.com | — | |
domainstartpasskeysetup.com | — |
Ip
| Value | Description | Copy |
|---|---|---|
ip107.128.45.122 | — | |
ip38.42.59.171 | — | |
ip47.218.103.146 | — | |
ip76.103.148.180 | — |
Threat ID: 6a75af5dbf8831d539217dbd
Added to database: 08/07/2026, 10:11:41 UTC
Last enriched: 08/07/2026, 10:28:59 UTC
Last updated: 08/07/2026, 16:26:00 UTC
Views: 18
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.