← All briefs
high August 30, 2026

UNC6671: Vishing to Adversary in the Middle SaaS Extortion - Multi Brand Operation Bypassing MFA to Steal Cloud Data from Financial Services

Source report →

UNC6671 is a financially motivated criminal cluster that ran publicly as BlackFile from early 2025, announced a false shutdown in May 2026, and re-emerged operating four extortion brands in parallel: Redact, Pink, Helix, and Falcon. The same infrastructure, affiliate network, and vishing scripts sit behind all of the brands, a deliberate structure that lets one front continue while another draws law enforcement attention. Okta tracks the same activity as CORDIAL SPIDER. Through 2026 the targeting narrowed from broad opportunistic sectors toward financial services, private equity, law firms, and merger and acquisition advisors, the organizations whose confidential data commands the highest extortion leverage, and named intrusion attempts against several large hedge funds were reported in August 2026.

Initial access is voice phishing rather than malware or exploitation. Operators single out staff in identity management, helpdesk, and IT administration roles by title, register a victim branded lookalike domain themed around passkey, SSO, or MFA enrollment within hours, then call the employee on a personal mobile phone while spoofing the corporate helpdesk number. The pretext claims an urgent, mandatory passkey enrollment or MFA upgrade. The victim is steered to an adversary in the middle portal that mirrors the organization's real single sign on page and transparently proxies every entry to the legitimate Microsoft 365 or Okta endpoint. When the victim completes multi factor authentication the proxy captures the authenticated session cookie the identity provider returns, so push, SMS one time passcode, and time based one time passcode factors are all defeated and the attacker holds a live, multi factor verified session.

Once authenticated the operators work to make access durable and quiet. They register attacker controlled devices or add attacker controlled authenticators in Okta or Entra ID so access survives session expiry, and they blend follow on activity through residential proxy address space and commercial VPN exit nodes to match the victim's normal geography. Bulk collection follows: automated scripts driven by scripting and automation user agents such as python requests, Windows PowerShell, and Go http client access SharePoint document libraries and Exchange mailboxes at volumes far above human browsing, and data is staged out to attacker cloud storage. To slow discovery the operators delete the multi factor enrollment confirmations, password reset notices, and security alert emails generated during the intrusion from the compromised mailbox, and the victim commonly learns of the breach only when the extortion demand arrives.

The supporting infrastructure ties the brands together and follows a recognizable pattern. Root domains are registered through a small set of registrars and combine authentication themed keywords such as passkey, sso, and mfa with enrollment verbs like setup, activate, deploy, and enroll, with victim specific subdomains layered underneath. Adversary in the middle reverse proxies and phishing backends cluster on a handful of hosting providers including a Swiss virtual private server range, while separate nodes handle automated software as a service exfiltration. Domain provisioning ran at roughly one new phishing domain every one and a half to two days, with a surge of seven domains inside seventy two hours in late July 2026 that signalled an accelerating operation.

Beyond the domains published in the original reporting, Vega threat research pivoted on the identified infrastructure and surfaced additional related domains, including further victim branded phishing page domains and Work Panel operator console domains; these indicators appear in the indicator list below.

DOMAIN 110
addssopasskey[.]com
createssopasskey[.]com
passkeyhelpdesk[.]com
myssopasskey[.]com
hubpasskey[.]com
passkeymfa[.]com
keysyncos[.]com
oskeysync[.]com
passkeyuser[.]com
enrollmfamethods[.]com
myaccountsecurity[.]com
editmysso[.]com
passkeycreate[.]com
mypasskeyapp[.]com
myssoapps[.]com
passkey-connect[.]com
mypasskeyid[.]com
passkeyconnect[.]com
addmypasskey[.]com
passkey-setup[.]com
startpasskeysetup[.]com
setpasskey[.]com
passkeysupport[.]com
createmfa[.]com
checkpasskey[.]com
newpasskey[.]com
addpasskey2fa[.]com
passkey-portal[.]com
startpasskey[.]com
passkeyrollout[.]com
mynewpasskey[.]com
enablepasskey2fa[.]com
passkeycreator[.]com
activatepasskeyportal[.]com
passkeyregister[.]com
addyourpasskey[.]com
passkeyportalsetup[.]com
passkeycenter[.]com
registerpasskey[.]com
addoktapasskey[.]com
activatemypasskey[.]com
activatepasskey[.]com
add-passkey[.]com
assignpasskey[.]com
createmypasskey[.]com
createpasskey[.]com
deploypasskey[.]com
enablepasskey[.]com
enrollpasskey[.]com
idokta[.]com
keyokta[.]com
makepasskey[.]com
mspasskey[.]com
myconnectkey[.]com
myoktasso[.]com
mypasskeysso[.]com
mysecurepasskey[.]com
oktaenroll[.]com
oktaportalsso[.]com
oskeyconnect[.]com
passkey-check[.]com
passkey-enable[.]com
passkeyactivation[.]com
passkeyadd[.]com
passkeydeploy[.]com
passkeyenable[.]com
passkeyenroll[.]com
passkeyms[.]com
passkeyokta[.]com
passkeyportal[.]com
passkeyregistration[.]com
passkeyset[.]com
passkeystatus[.]com
portalpasskey[.]com
portalsetuphub[.]com
secure-passkey[.]com
secureauthpasskey[.]com
setupsso[.]com
setupssopasskey[.]com
sqfepjvmrd[.]xyz
ssopasskey[.]com
enroll-passkey[.]com
new-passkey[.]com
register-passkey[.]com
deploypasskeys[.]com
mypasskeyapps[.]com
startmypasskey[.]com
enrollssopasskey[.]com
mfapasskeysetup[.]com
fastpasskeys[.]com
apply-passkey[.]com
onboardpasskey[.]com
verify-passkey[.]com
confirmpasskey[.]com
mymfasetup[.]com
my-passkey[.]com
registersso[.]com
installsso[.]com
enlistpasskey[.]com
mfaregister[.]com
register-mfa[.]com
sso-passkey[.]com
lime.pinr3ihinrwniseas[.]com
p.wpgpiwrgnivsdofdfa[.]com
0dwgnbh2ur9gw[.]com
cfdash[.]cfd
whatarewedoingwiththesedomainshello[.]com
aws-smtp-eu[.]com
bixcorp[.]net
noairen[.]com
IP ADDRESS 16
31.7.56[.]61
31.7.56[.]52
193.34.212[.]132
185.178.208[.]153
23.234.75[.]84
195.140.213[.]114
195.140.213[.]115
107[.]128[.]45[.]122
38[.]42[.]59[.]171
47[.]218[.]103[.]146
76[.]103[.]148[.]180
31.7.56[.]53
31.7.56[.]55
31.7.56[.]56
31.7.56[.]51
31.7.56[.]54

Detections (10)

Enable detections →

Connect your environment for suggestions and queries personalized to your security telemetry.

  • FastPass Authentication Attempt via AiTM Phishing Proxy
  • Suspicious Use of an Okta Session Cookie
  • User Denied Access due to Session Binding
  • SharePoint High Volume File Access or Download
  • Bulk SharePoint File Download by Single User
  • Scripted Client Authenticating to Azure Device Registration Service
  • Okta Suspected MFA Fatigue Attempt
  • Suspected MFA Fatigue Attack in EntraID
  • Okta MFA Factor Registration Coinciding With Authentication Failure