UNC6671: Vishing to Adversary in the Middle SaaS Extortion - Multi Brand Operation Bypassing MFA to Steal Cloud Data from Financial Services
Source report →UNC6671 is a financially motivated criminal cluster that ran publicly as BlackFile from early 2025, announced a false shutdown in May 2026, and re-emerged operating four extortion brands in parallel: Redact, Pink, Helix, and Falcon. The same infrastructure, affiliate network, and vishing scripts sit behind all of the brands, a deliberate structure that lets one front continue while another draws law enforcement attention. Okta tracks the same activity as CORDIAL SPIDER. Through 2026 the targeting narrowed from broad opportunistic sectors toward financial services, private equity, law firms, and merger and acquisition advisors, the organizations whose confidential data commands the highest extortion leverage, and named intrusion attempts against several large hedge funds were reported in August 2026.
Initial access is voice phishing rather than malware or exploitation. Operators single out staff in identity management, helpdesk, and IT administration roles by title, register a victim branded lookalike domain themed around passkey, SSO, or MFA enrollment within hours, then call the employee on a personal mobile phone while spoofing the corporate helpdesk number. The pretext claims an urgent, mandatory passkey enrollment or MFA upgrade. The victim is steered to an adversary in the middle portal that mirrors the organization's real single sign on page and transparently proxies every entry to the legitimate Microsoft 365 or Okta endpoint. When the victim completes multi factor authentication the proxy captures the authenticated session cookie the identity provider returns, so push, SMS one time passcode, and time based one time passcode factors are all defeated and the attacker holds a live, multi factor verified session.
Once authenticated the operators work to make access durable and quiet. They register attacker controlled devices or add attacker controlled authenticators in Okta or Entra ID so access survives session expiry, and they blend follow on activity through residential proxy address space and commercial VPN exit nodes to match the victim's normal geography. Bulk collection follows: automated scripts driven by scripting and automation user agents such as python requests, Windows PowerShell, and Go http client access SharePoint document libraries and Exchange mailboxes at volumes far above human browsing, and data is staged out to attacker cloud storage. To slow discovery the operators delete the multi factor enrollment confirmations, password reset notices, and security alert emails generated during the intrusion from the compromised mailbox, and the victim commonly learns of the breach only when the extortion demand arrives.
The supporting infrastructure ties the brands together and follows a recognizable pattern. Root domains are registered through a small set of registrars and combine authentication themed keywords such as passkey, sso, and mfa with enrollment verbs like setup, activate, deploy, and enroll, with victim specific subdomains layered underneath. Adversary in the middle reverse proxies and phishing backends cluster on a handful of hosting providers including a Swiss virtual private server range, while separate nodes handle automated software as a service exfiltration. Domain provisioning ran at roughly one new phishing domain every one and a half to two days, with a surge of seven domains inside seventy two hours in late July 2026 that signalled an accelerating operation.
Beyond the domains published in the original reporting, Vega threat research pivoted on the identified infrastructure and surfaced additional related domains, including further victim branded phishing page domains and Work Panel operator console domains; these indicators appear in the indicator list below.
IOCs (126)
Scan your environment for IOCs →DOMAIN 110
addssopasskey[.]comcreatessopasskey[.]compasskeyhelpdesk[.]commyssopasskey[.]comhubpasskey[.]compasskeymfa[.]comkeysyncos[.]comoskeysync[.]compasskeyuser[.]comenrollmfamethods[.]commyaccountsecurity[.]comeditmysso[.]compasskeycreate[.]commypasskeyapp[.]commyssoapps[.]compasskey-connect[.]commypasskeyid[.]compasskeyconnect[.]comaddmypasskey[.]compasskey-setup[.]comstartpasskeysetup[.]comsetpasskey[.]compasskeysupport[.]comcreatemfa[.]comcheckpasskey[.]comnewpasskey[.]comaddpasskey2fa[.]compasskey-portal[.]comstartpasskey[.]compasskeyrollout[.]commynewpasskey[.]comenablepasskey2fa[.]compasskeycreator[.]comactivatepasskeyportal[.]compasskeyregister[.]comaddyourpasskey[.]compasskeyportalsetup[.]compasskeycenter[.]comregisterpasskey[.]comaddoktapasskey[.]comactivatemypasskey[.]comactivatepasskey[.]comadd-passkey[.]comassignpasskey[.]comcreatemypasskey[.]comcreatepasskey[.]comdeploypasskey[.]comenablepasskey[.]comenrollpasskey[.]comidokta[.]comkeyokta[.]commakepasskey[.]commspasskey[.]commyconnectkey[.]commyoktasso[.]commypasskeysso[.]commysecurepasskey[.]comoktaenroll[.]comoktaportalsso[.]comoskeyconnect[.]compasskey-check[.]compasskey-enable[.]compasskeyactivation[.]compasskeyadd[.]compasskeydeploy[.]compasskeyenable[.]compasskeyenroll[.]compasskeyms[.]compasskeyokta[.]compasskeyportal[.]compasskeyregistration[.]compasskeyset[.]compasskeystatus[.]comportalpasskey[.]comportalsetuphub[.]comsecure-passkey[.]comsecureauthpasskey[.]comsetupsso[.]comsetupssopasskey[.]comsqfepjvmrd[.]xyzssopasskey[.]comenroll-passkey[.]comnew-passkey[.]comregister-passkey[.]comdeploypasskeys[.]commypasskeyapps[.]comstartmypasskey[.]comenrollssopasskey[.]commfapasskeysetup[.]comfastpasskeys[.]comapply-passkey[.]comonboardpasskey[.]comverify-passkey[.]comconfirmpasskey[.]commymfasetup[.]commy-passkey[.]comregistersso[.]cominstallsso[.]comenlistpasskey[.]commfaregister[.]comregister-mfa[.]comsso-passkey[.]comlime.pinr3ihinrwniseas[.]comp.wpgpiwrgnivsdofdfa[.]com0dwgnbh2ur9gw[.]comcfdash[.]cfdwhatarewedoingwiththesedomainshello[.]comaws-smtp-eu[.]combixcorp[.]netnoairen[.]comIP ADDRESS 16
31.7.56[.]6131.7.56[.]52193.34.212[.]132185.178.208[.]15323.234.75[.]84195.140.213[.]114195.140.213[.]115107[.]128[.]45[.]12238[.]42[.]59[.]17147[.]218[.]103[.]14676[.]103[.]148[.]18031.7.56[.]5331.7.56[.]5531.7.56[.]5631.7.56[.]5131.7.56[.]54Detections (10)
Enable detections →Connect your environment for suggestions and queries personalized to your security telemetry.
- FastPass Authentication Attempt via AiTM Phishing Proxy
- Suspicious Use of an Okta Session Cookie
- User Denied Access due to Session Binding
- SharePoint High Volume File Access or Download
- Bulk SharePoint File Download by Single User
- Scripted Client Authenticating to Azure Device Registration Service
- Okta Suspected MFA Fatigue Attempt
- Suspected MFA Fatigue Attack in EntraID
- Okta MFA Factor Registration Coinciding With Authentication Failure