Threat Actor Unknown origin
UNC6671
UNC6671 is involved in credential harvesting operations, utilizing vishing tactics to impersonate IT staff and directing victims to enter credentials on a victim-branded site. They have gained access to Okta customer accounts and employed PowerShell to download sensitive data from SharePoint and OneDrive. Their extortion tactics include aggressive harassment of victim personnel, and they have used unbranded extortion emails with different Tox IDs for communication. The threat actors have shown a preference for registering domains with Tucows, indicating potential operational differences from related threat groups.
Indicators of Compromise 25
Domain add-passkey[.]com Domain assignpasskey[.]com Domain domainlify[.]net Domain idokta[.]com Domain integratedsso[.]com Domain keysyncos[.]com Domain mfaregister[.]com Domain nowsso[.]com Domain oktasession[.]com Domain oskeysetup[.]com Domain oskeysync[.]com Domain oursso[.]com Domain passkey-mfa[.]com Domain passkeydeploy[.]com Domain passkeyhelpdesk[.]com Domain portalsetuphub[.]com Domain registermymfa[.]com Domain registry[.]modelcontextprotocol[.]io Domain secure-passkey[.]com Domain service-nowinc[.]com Domain setpasskey[.]com Domain setupmypasskey[.]com Domain setupsso[.]com Domain syncmykey[.]com GitHub Repo jUXTAPOSITION1/V.A.P.E
MITRE ATT&CK TTPs 41
T1003 T1020 T1027 T1059 T1059.001 T1059.003 T1071.001 T1071.004 T1078 T1078.004 T1087 T1087.003 T1090 T1090.002 T1095 T1105 T1110 T1110.001 T1114 T1133 T1190 T1213 T1480 T1482 T1486 T1495 T1496 T1529 T1530 T1531 T1538 T1538.001 T1555 T1566 T1566.002 T1567 T1567.001 T1567.002 T1568 T1568.002 T1611
OS Credential Dumping
Credential Access
Automated Exfiltration
Exfiltration
Obfuscated Files or Information
Defense Evasion
Command and Scripting Interpreter
Execution
PowerShell
Execution
Windows Command Shell
Execution
Web Protocols
Command And Control
DNS
Command And Control
Valid Accounts
Defense Evasion
Cloud Accounts
Defense Evasion
Account Discovery
Discovery
Email Account
Discovery
Proxy
Command And Control
External Proxy
Command And Control
Non-Application Layer Protocol
Command And Control
Ingress Tool Transfer
Command And Control
Brute Force
Credential Access
Password Guessing
Credential Access
Email Collection
Collection
External Remote Services
Persistence
Exploit Public-Facing Application
Initial Access
Data from Information Repositories
Collection
Execution Guardrails
Defense Evasion
Domain Trust Discovery
Discovery
Data Encrypted for Impact
Impact
Firmware Corruption
Impact
Resource Hijacking
Impact
System Shutdown/Reboot
Impact
Data from Cloud Storage
Collection
Account Access Removal
Impact
Cloud Service Dashboard
Discovery
T1538.001
Credentials from Password Stores
Credential Access
Phishing
Initial Access
Spearphishing Link
Initial Access
Exfiltration Over Web Service
Exfiltration
Exfiltration to Code Repository
Exfiltration
Exfiltration to Cloud Storage
Exfiltration
Dynamic Resolution
Command And Control
Domain Generation Algorithms
Command And Control
Escape to Host
Privilege Escalation
Source Articles
Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data
Microsoft identified two distinct attack campaigns targeting enterprise cloud environments. The first involved a large-scale phishing campaign using CEO impersonation and AI-generated content to trick finance teams into executing fraudulent ACH transfers. The second, more technically sophisticated campaign used social engineering around passkey and MFA updates to compromise Microsoft cloud identities, enabling persistent access through adversary-in-the-middle attacks and abuse of Microsoft Graph API for reconnaissance and data exfiltration. The activity is attributed to multiple threat actor groups, including Storm-3121 and Storm-3032 (UNC6671), with infrastructure linked to known cybercrime collectives.
hacker-news ·1w ago
Passkey-themed phishing attacks lead to Microsoft 365 data theft
Threat actors linked to ShinyHunters, Helix, and other extortion gangs are conducting passkey and single sign-on-themed phishing campaigns to compromise corporate Microsoft 365 accounts. The attacks begin with social engineering via phone or messaging, impersonating IT help desks to trick employees into visiting phishing sites or authorizing device-code authentication, enabling adversary-in-the-middle attacks. Attackers perform extensive reconnaissance using Microsoft Graph, persist by adding attacker-controlled MFA methods, and exfiltrate data from SharePoint, OneDrive, and Exchange over prolonged periods to evade detection.
bleeping-computer ·1w ago
Fake IT Calls Target Executives in Microsoft 365 Data Theft and Extortion Attacks
A threat cluster tracked as PREY-0058 by Arctic Wolf is conducting data theft and extortion attacks targeting Microsoft 365 users, primarily executives, through vishing (voice phishing) and adversary-in-the-middle (AitM) attacks. Attackers impersonate IT help desk personnel and direct victims to malicious authentication pages using domains that mimic legitimate services, such as 'mfaregister[.]com', to steal credentials and MFA tokens. These tokens are then replayed via residential proxy infrastructure to access Microsoft 365 services, enabling large-scale data exfiltration from SharePoint, OneDrive, Exchange, and Box without deploying malware or moving laterally within networks.
hacker-news ·1w ago
⚡ Weekly Recap: AI Goes Rogue, Metabase 0-Day, MCP Supply-Chain Attacks, and Router Backdoors
A zero-day vulnerability in Metabase, a business intelligence platform, is being exploited in the wild, allowing unauthenticated remote attackers to perform SQL injection and gain full administrator access to affected instances. This enables attackers to steal database credentials, exfiltrate data, and modify configurations. The vulnerability has a CVSS score of 10.0 but lacks a CVE identifier. One confirmed victim is Framework. Additionally, Chinese-made Zbtlink routers were found shipping with a factory-installed backdoor that phones home to Chinese C2 servers every 35 seconds, affecting at least 20 models. The backdoor enables remote command execution. Separately, the threat actor UNC6671 is conducting vishing attacks against financial firms, using voice phishing to capture credentials and MFA tokens via adversary-in-the-middle infrastructure, then deploying scripts for data exfiltration from cloud environments.
hacker-news ·1mo ago
UNC6671 Vishing Attacks Target Personal Phones to Steal SaaS Data
UNC6671, a financially motivated threat actor group, is conducting vishing attacks to steal credentials and multi-factor authentication tokens by impersonating IT help desk personnel and contacting employees on their personal mobile devices. The attackers use adversary-in-the-middle (AitM) infrastructure to capture credentials and session tokens, enabling access to SaaS platforms such as Microsoft 365 and Okta. The group operates under multiple extortion brands including Redact, Pink, Helix, and Falcon, and has exfiltrated data from organizations in North America, Australia, and the U.K., collecting over $10.6 million in Bitcoin between January and May 2026. Google and CrowdStrike assess that the group leverages social engineering rather than technical vulnerabilities, highlighting the need for phishing-resistant MFA and improved session controls.
hacker-news ·1mo ago
Hedge fund cyberattacks tied to BlackFile-linked UNC6671 extortion group
A cybercriminal group tracked as UNC6671, previously known as BlackFile, has been conducting vishing attacks against hedge funds, private-equity firms, and other financial organizations. The attackers spoof corporate helpdesks and trick employees into visiting phishing domains that steal credentials and session cookies via adversary-in-the-middle kits. After gaining access to Microsoft 365 or Okta single-sign-on accounts, they exfiltrate data from linked cloud services and suppress detection by deleting security notifications. The group has diversified its extortion operations under multiple brand names including Redact, Pink, Helix, and Falcon, though Falcon claims it is only affiliated with Redact.
bleeping-computer ·1mo ago