UNC6671 is carrying out data theft campaigns that begin with a phone call. The group poses as an IT helpdesk, claiming an urgent security migration is necessary. A convincing call and a fake sign-in page can turn an ordinary session into an entry point.
The calls create urgency before employees can verify the request independently. The campaign is dangerous because it does not need to crack a password.
It captures credentials and a live authentication token. That token lets an intruder act as the employee in Microsoft 365 or Okta, to access mail, files and other stored corporate data.
Analysts at Google Cloud identified the activity during ongoing data theft and extortion.
Google Cloud said in a report shared with Cyber Security News (CSN) that the group has stayed active despite the claimed retirement of its BlackFile brand, using Redact, Pink, Helix and Falcon names.
The consequences extend beyond a hijacked inbox. Stolen records can expose sensitive information and fuel extortion.
Recent targeting shifted toward financial services, private equity and professional services, where deal and litigation material can be especially valuable.
UNC6671 Automates Microsoft 365 Data Theft
The operation starts with voice phishing, often called vishing. Callers contact staff on personal mobile phones, sometimes spoofing a helpdesk number, claiming a passkey or multi-factor authentication update is mandatory.
They direct employees to tailored imitation enrolment portals, a technique also seen in Microsoft Graph reconnaissance attacks against workplace accounts.
The fraudulent site sits between the victim and the real login service. This adversary-in-the-middle setup relays the sign-in process while collecting the password and multi-factor authentication token.
.webp)
UNC6671 can then reuse the authenticated session, an approach similar to the session hijacking payroll attacks against Microsoft 365 users.
Once inside, operators use automated scripts to take data from cloud services. The report notes direct-stream access patterns associated with scripting tools, enabling large-scale reading without conventional downloads.
The group also uses residential proxy connections to make access look closer to ordinary user traffic and complicate incident response.
The operators have added steps to stay hidden. They used compromised mailboxes to reset passwords for applications that do not use single sign-on, then deleted reset confirmations, security notices and alerts tied to account or multi-factor authentication changes. That can leave a victim unaware while access and data collection continue.
Shared Infrastructure Raises Extortion Risk
Google Cloud linked the activity through recurring phishing templates, overlapping victim targeting and reused domain infrastructure.
The same generic passkey-themed domains supported campaigns used by several extortion brands, although researchers said this could reflect a coordinated group, splintered affiliates or shared phishing services.
Brand changes should not distract defenders from the method behind them.
The pace also increased. From June through July, researchers observed about one new root domain every 1.6 days, with seven domains activated over a 72-hour period in late July.
Names frequently combine passkey, MFA or SSO, reinforcing the false impression that a routine security task is underway.
Defenders should make it easy for employees to verify unexpected helpdesk requests through a known company channel.
Security teams should enforce phishing-resistant sign-in methods, shorten session lifetimes, require stronger checks for sensitive resources and restrict authentication to managed devices and trusted networks.
.webp)
These measures reduce the value of a stolen session. This matters because AiTM phishing campaigns targeting Microsoft 365 aim to exploit a valid session, not merely a stolen password.
Teams should review identity-provider and Microsoft 365 audit data for abandoned authentication challenges, unusual multi-factor enrolment, high-volume file access and scripting-related user-agent strings.
Treating FileAccessed events with the same urgency as downloads can expose direct-stream collection.
.webp)
Monitoring for anonymised or residential-proxy logins adds another warning when activity is unusual or comes from an unfamiliar device.
UNC6671 shows how a phone call can breach cloud security. Organisations that combine staff verification procedures with resistant authentication, session controls and behavioural monitoring can stop theft before stolen data becomes an extortion tool.
Indicators of Compromise (IoCs):-
| Type | Indicator | Description |
|---|---|---|
| Domain | myoktasso[.]com | Phishing domain, created 2026-04-04 |
| Domain | mypasskeysso[.]com | Phishing domain, created 2026-04-04 |
| Domain | setupssopasskey[.]com | Phishing domain, created 2026-04-07 |
| Domain | mspasskey[.]com | Phishing domain, created 2026-04-08 |
| Domain | activatepasskey[.]com | Phishing domain, created 2026-04-10 |
| Domain | enrollpasskey[.]com | Phishing domain, created 2026-04-10 |
| Domain | keyokta[.]com | Phishing domain, created 2026-04-13 |
| Domain | oktaenroll[.]com | Phishing domain, created 2026-04-13 |
| Domain | oktaportalsso[.]com | Phishing domain, created 2026-04-16 |
| Domain | passkeyportal[.]com | Phishing domain, created 2026-04-16 |
| Domain | portalpasskey[.]com | Phishing domain, created 2026-04-16 |
| Domain | passkeyportalsetup[.]com | Phishing domain, created 2026-04-20 |
| Domain | addoktapasskey[.]com | Phishing domain, created 2026-04-21 |
| Domain | deploypasskey[.]com | Phishing domain, created 2026-04-21 |
| Domain | passkeydeploy[.]com | Phishing domain, created 2026-04-23 |
| Domain | activatemypasskey[.]com | Phishing domain, created 2026-04-24 |
| Domain | registerpasskey[.]com | Phishing domain, created 2026-04-29 |
| Domain | createpasskey[.]com | Phishing domain, created 2026-05-03 |
| Domain | passkeyadd[.]com | Phishing domain, created 2026-05-08 |
| Domain | passkeyregister[.]com | Phishing domain, created 2026-05-08 |
| Domain | passkeycenter[.]com | Phishing domain, created 2026-05-11 |
| Domain | secureauthpasskey[.]com | Phishing domain, created 2026-05-14 |
| Domain | passkeyrollout[.]com | Phishing domain, created 2026-05-18 |
| Domain | setpasskey[.]com | Phishing domain, created 2026-05-22 |
| Domain | passkeyokta[.]com | Phishing domain, created 2026-05-26 |
| Domain | passkeyset[.]com | Phishing domain, created 2026-05-27 |
| Domain | createmypasskey[.]com | Phishing domain, created 2026-05-27 |
| Domain | newpasskey[.]com | Phishing domain, created 2026-05-28 |
| Domain | passkeysupport[.]com | Phishing domain, created 2026-05-29 |
| Domain | sqfepjvmrd[.]xyz | Phishing domain, created 2026-06-01 |
| Domain | passkeyregistration[.]com | Phishing domain, created 2026-06-02 |
| Domain | addmypasskey[.]com | Phishing domain, created 2026-06-03 |
| Domain | passkey-setup[.]com | Phishing domain, created 2026-06-03 |
| Domain | passkey-portal[.]com | Phishing domain, created 2026-06-05 |
| Domain | startpasskeysetup[.]com | Phishing domain, created 2026-06-05 |
| Domain | passkey-connect[.]com | Phishing domain, created 2026-06-05 |
| Domain | portalsetuphub[.]com | Phishing domain, created 2026-06-10 |
| Domain | activatepasskeyportal[.]com | Phishing domain, created 2026-06-12 |
| Domain | assignpasskey[.]com | Phishing domain, created 2026-06-13 |
| Domain | myconnectkey[.]com | Phishing domain, created 2026-06-13 |
| Domain | mynewpasskey[.]com | Phishing domain, created 2026-06-13 |
| Domain | passkeycreate[.]com | Phishing domain, created 2026-06-16 |
| Domain | oskeyconnect[.]com | Phishing domain, created 2026-06-17 |
| Domain | passkeycreator[.]com | Phishing domain, created 2026-06-19 |
| Domain | oskeysync[.]com | Phishing domain, created 2026-06-20 |
| Domain | enablepasskey[.]com | Phishing domain, created 2026-06-22 |
| Domain | enablepasskey2fa[.]com | Phishing domain, created 2026-06-22 |
| Domain | checkpasskey[.]com | Phishing domain, created 2026-06-22 |
| Domain | passkeyuser[.]com | Phishing domain, created 2026-06-25 |
| Domain | keysyncos[.]com | Phishing domain, created 2026-06-30 |
| Domain | myaccountsecurity[.]com | Phishing domain, created 2026-06-30 |
| Domain | addpasskey2fa[.]com | Phishing domain, created 2026-07-01 |
| Domain | passkeyenroll[.]com | Phishing domain, created 2026-07-07 |
| Domain | startpasskey[.]com | Phishing domain, created 2026-07-07 |
| Domain | passkeyenable[.]com | Phishing domain, created 2026-07-08 |
| Domain | passkeyactivation[.]com | Phishing domain, created 2026-07-09 |
| Domain | createmfa[.]com | Phishing domain, created 2026-07-09 |
| Domain | passkeyhelpdesk[.]com | Phishing domain, created 2026-07-10 |
| Domain | makepasskey[.]com | Phishing domain, created 2026-07-13 |
| Domain | add-passkey[.]com | Phishing domain, created 2026-07-13 |
| Domain | passkey-check[.]com | Phishing domain, created 2026-07-13 |
| Domain | addyourpasskey[.]com | Phishing domain, created 2026-07-20 |
| Domain | passkey-enable[.]com | Phishing domain, created 2026-07-20 |
| Domain | mypasskeyid[.]com | Phishing domain, created 2026-07-21 |
| Domain | passkeystatus[.]com | Phishing domain, created 2026-07-21 |
| Domain | secure-passkey[.]com | Phishing domain, created 2026-07-21 |
| Domain | addssopasskey[.]com | Phishing domain, created 2026-07-22 |
| Domain | ssopasskey[.]com | Phishing domain, created 2026-07-22 |
| Domain | createssopasskey[.]com | Phishing domain, created 2026-07-28 |
| Domain | myssopasskey[.]com | Phishing domain, created 2026-07-31 |
| Domain | hubpasskey[.]com | Phishing domain, created 2026-08-03 |
| Domain | passkeymfa[.]com | Phishing domain, created 2026-08-03 |
| IP address | 31.7.56.61 | AiTM panel reverse proxy |
| IP address | 31.7.56.52 | AiTM panel reverse proxy |
| IP address | 193.34.212.132 | Phishing kit backend proxy |
| IP address | 185.178.208.153 | Phishing reverse proxy |
| IP address | 23.234.75.84 | Automated SaaS data exfiltration |
| IP address | 195.140.213.114 | Automated SaaS data exfiltration |
| IP address | 195.140.213.115 | Automated SaaS data exfiltration |
| IP address | 107.128.45.122 | Microsoft 365 or Okta residential proxy |
| IP address | 76.103.148.180 | Microsoft 365 or Okta residential proxy |
| IP address | 38.42.59.171 | Microsoft 365 or Okta residential proxy |
| IP address | 47.218.103.146 | Microsoft 365 or Okta residential proxy |
| User-Agent | python-requests/2.28.1 | Scripting-related user-agent |
| User-Agent | WindowsPowerShell/5.1 | Scripting-related user-agent |
| User-Agent | Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:146.0) Gecko/20100101 Firefox/146.0 | Observed browser user-agent |
| User-Agent | 0811A9866E.com.okta.android.auth/8.18.0 DeviceSDK/1.0.94 Android/16 Google/Pixel_9_Pro_XL | Observed Okta Android SDK user-agent |
tionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Stop new phishing & malware before they compromise your business. Integrate live intel from 15K SOCs around the world

