CyberSecurityNews

UNC6671 Automates Microsoft 365 Data Theft After Hijacking Employee Sessions


UNC6671 is carrying out data theft campaigns that begin with a phone call. The group poses as an IT helpdesk, claiming an urgent security migration is necessary. A convincing call and a fake sign-in page can turn an ordinary session into an entry point.

The calls create urgency before employees can verify the request independently. The campaign is dangerous because it does not need to crack a password.

It captures credentials and a live authentication token. That token lets an intruder act as the employee in Microsoft 365 or Okta, to access mail, files and other stored corporate data.

Analysts at Google Cloud identified the activity during ongoing data theft and extortion.

Google Cloud said in a report shared with Cyber Security News (CSN) that the group has stayed active despite the claimed retirement of its BlackFile brand, using Redact, Pink, Helix and Falcon names.

The consequences extend beyond a hijacked inbox. Stolen records can expose sensitive information and fuel extortion.

Helix and Pink DLS (Source – Google Cloud)

Recent targeting shifted toward financial services, private equity and professional services, where deal and litigation material can be especially valuable.

UNC6671 Automates Microsoft 365 Data Theft

The operation starts with voice phishing, often called vishing. Callers contact staff on personal mobile phones, sometimes spoofing a helpdesk number, claiming a passkey or multi-factor authentication update is mandatory.

They direct employees to tailored imitation enrolment portals, a technique also seen in Microsoft Graph reconnaissance attacks against workplace accounts.

The fraudulent site sits between the victim and the real login service. This adversary-in-the-middle setup relays the sign-in process while collecting the password and multi-factor authentication token.

Falcon DLS (Source - Google Cloud)
Falcon DLS (Source – Google Cloud)

UNC6671 can then reuse the authenticated session, an approach similar to the session hijacking payroll attacks against Microsoft 365 users.

Once inside, operators use automated scripts to take data from cloud services. The report notes direct-stream access patterns associated with scripting tools, enabling large-scale reading without conventional downloads.

The group also uses residential proxy connections to make access look closer to ordinary user traffic and complicate incident response.

The operators have added steps to stay hidden. They used compromised mailboxes to reset passwords for applications that do not use single sign-on, then deleted reset confirmations, security notices and alerts tied to account or multi-factor authentication changes. That can leave a victim unaware while access and data collection continue.

Shared Infrastructure Raises Extortion Risk

Google Cloud linked the activity through recurring phishing templates, overlapping victim targeting and reused domain infrastructure.

The same generic passkey-themed domains supported campaigns used by several extortion brands, although researchers said this could reflect a coordinated group, splintered affiliates or shared phishing services.

Brand changes should not distract defenders from the method behind them.

The pace also increased. From June through July, researchers observed about one new root domain every 1.6 days, with seven domains activated over a 72-hour period in late July.

Names frequently combine passkey, MFA or SSO, reinforcing the false impression that a routine security task is underway.

Defenders should make it easy for employees to verify unexpected helpdesk requests through a known company channel.

Security teams should enforce phishing-resistant sign-in methods, shorten session lifetimes, require stronger checks for sensitive resources and restrict authentication to managed devices and trusted networks.

REDACT statement on alleged break from BlackFile (Source - Google Cloud)
REDACT statement on alleged break from BlackFile (Source – Google Cloud)

These measures reduce the value of a stolen session. This matters because AiTM phishing campaigns targeting Microsoft 365 aim to exploit a valid session, not merely a stolen password.

Teams should review identity-provider and Microsoft 365 audit data for abandoned authentication challenges, unusual multi-factor enrolment, high-volume file access and scripting-related user-agent strings.

Treating FileAccessed events with the same urgency as downloads can expose direct-stream collection.

Shared infrastructure across multiple brands (Source - Google Cloud)
Shared infrastructure across multiple brands (Source – Google Cloud)

Monitoring for anonymised or residential-proxy logins adds another warning when activity is unusual or comes from an unfamiliar device.

UNC6671 shows how a phone call can breach cloud security. Organisations that combine staff verification procedures with resistant authentication, session controls and behavioural monitoring can stop theft before stolen data becomes an extortion tool.

Indicators of Compromise (IoCs):-

TypeIndicatorDescription
Domainmyoktasso[.]comPhishing domain, created 2026-04-04
Domainmypasskeysso[.]comPhishing domain, created 2026-04-04
Domainsetupssopasskey[.]comPhishing domain, created 2026-04-07
Domainmspasskey[.]comPhishing domain, created 2026-04-08
Domainactivatepasskey[.]comPhishing domain, created 2026-04-10
Domainenrollpasskey[.]comPhishing domain, created 2026-04-10
Domainkeyokta[.]comPhishing domain, created 2026-04-13
Domainoktaenroll[.]comPhishing domain, created 2026-04-13
Domainoktaportalsso[.]comPhishing domain, created 2026-04-16
Domainpasskeyportal[.]comPhishing domain, created 2026-04-16
Domainportalpasskey[.]comPhishing domain, created 2026-04-16
Domainpasskeyportalsetup[.]comPhishing domain, created 2026-04-20
Domainaddoktapasskey[.]comPhishing domain, created 2026-04-21
Domaindeploypasskey[.]comPhishing domain, created 2026-04-21
Domainpasskeydeploy[.]comPhishing domain, created 2026-04-23
Domainactivatemypasskey[.]comPhishing domain, created 2026-04-24
Domainregisterpasskey[.]comPhishing domain, created 2026-04-29
Domaincreatepasskey[.]comPhishing domain, created 2026-05-03
Domainpasskeyadd[.]comPhishing domain, created 2026-05-08
Domainpasskeyregister[.]comPhishing domain, created 2026-05-08
Domainpasskeycenter[.]comPhishing domain, created 2026-05-11
Domainsecureauthpasskey[.]comPhishing domain, created 2026-05-14
Domainpasskeyrollout[.]comPhishing domain, created 2026-05-18
Domainsetpasskey[.]comPhishing domain, created 2026-05-22
Domainpasskeyokta[.]comPhishing domain, created 2026-05-26
Domainpasskeyset[.]comPhishing domain, created 2026-05-27
Domaincreatemypasskey[.]comPhishing domain, created 2026-05-27
Domainnewpasskey[.]comPhishing domain, created 2026-05-28
Domainpasskeysupport[.]comPhishing domain, created 2026-05-29
Domainsqfepjvmrd[.]xyzPhishing domain, created 2026-06-01
Domainpasskeyregistration[.]comPhishing domain, created 2026-06-02
Domainaddmypasskey[.]comPhishing domain, created 2026-06-03
Domainpasskey-setup[.]comPhishing domain, created 2026-06-03
Domainpasskey-portal[.]comPhishing domain, created 2026-06-05
Domainstartpasskeysetup[.]comPhishing domain, created 2026-06-05
Domainpasskey-connect[.]comPhishing domain, created 2026-06-05
Domainportalsetuphub[.]comPhishing domain, created 2026-06-10
Domainactivatepasskeyportal[.]comPhishing domain, created 2026-06-12
Domainassignpasskey[.]comPhishing domain, created 2026-06-13
Domainmyconnectkey[.]comPhishing domain, created 2026-06-13
Domainmynewpasskey[.]comPhishing domain, created 2026-06-13
Domainpasskeycreate[.]comPhishing domain, created 2026-06-16
Domainoskeyconnect[.]comPhishing domain, created 2026-06-17
Domainpasskeycreator[.]comPhishing domain, created 2026-06-19
Domainoskeysync[.]comPhishing domain, created 2026-06-20
Domainenablepasskey[.]comPhishing domain, created 2026-06-22
Domainenablepasskey2fa[.]comPhishing domain, created 2026-06-22
Domaincheckpasskey[.]comPhishing domain, created 2026-06-22
Domainpasskeyuser[.]comPhishing domain, created 2026-06-25
Domainkeysyncos[.]comPhishing domain, created 2026-06-30
Domainmyaccountsecurity[.]comPhishing domain, created 2026-06-30
Domainaddpasskey2fa[.]comPhishing domain, created 2026-07-01
Domainpasskeyenroll[.]comPhishing domain, created 2026-07-07
Domainstartpasskey[.]comPhishing domain, created 2026-07-07
Domainpasskeyenable[.]comPhishing domain, created 2026-07-08
Domainpasskeyactivation[.]comPhishing domain, created 2026-07-09
Domaincreatemfa[.]comPhishing domain, created 2026-07-09
Domainpasskeyhelpdesk[.]comPhishing domain, created 2026-07-10
Domainmakepasskey[.]comPhishing domain, created 2026-07-13
Domainadd-passkey[.]comPhishing domain, created 2026-07-13
Domainpasskey-check[.]comPhishing domain, created 2026-07-13
Domainaddyourpasskey[.]comPhishing domain, created 2026-07-20
Domainpasskey-enable[.]comPhishing domain, created 2026-07-20
Domainmypasskeyid[.]comPhishing domain, created 2026-07-21
Domainpasskeystatus[.]comPhishing domain, created 2026-07-21
Domainsecure-passkey[.]comPhishing domain, created 2026-07-21
Domainaddssopasskey[.]comPhishing domain, created 2026-07-22
Domainssopasskey[.]comPhishing domain, created 2026-07-22
Domaincreatessopasskey[.]comPhishing domain, created 2026-07-28
Domainmyssopasskey[.]comPhishing domain, created 2026-07-31
Domainhubpasskey[.]comPhishing domain, created 2026-08-03
Domainpasskeymfa[.]comPhishing domain, created 2026-08-03
IP address31.7.56.61AiTM panel reverse proxy
IP address31.7.56.52AiTM panel reverse proxy
IP address193.34.212.132Phishing kit backend proxy
IP address185.178.208.153Phishing reverse proxy
IP address23.234.75.84Automated SaaS data exfiltration
IP address195.140.213.114Automated SaaS data exfiltration
IP address195.140.213.115Automated SaaS data exfiltration
IP address107.128.45.122Microsoft 365 or Okta residential proxy
IP address76.103.148.180Microsoft 365 or Okta residential proxy
IP address38.42.59.171Microsoft 365 or Okta residential proxy
IP address47.218.103.146Microsoft 365 or Okta residential proxy
User-Agentpython-requests/2.28.1Scripting-related user-agent
User-AgentWindowsPowerShell/5.1Scripting-related user-agent
User-AgentMozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:146.0) Gecko/20100101 Firefox/146.0Observed browser user-agent
User-Agent0811A9866E.com.okta.android.auth/8.18.0 DeviceSDK/1.0.94 Android/16 Google/Pixel_9_Pro_XLObserved Okta Android SDK user-agent

tionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Stop new phishing & malware before they compromise your business. Integrate live intel from 15K SOCs around the world



Source link