UNC6671 Automates Microsoft 365 Data Theft After Hijacking Employee Sessions

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Spread the love

UNC6671 is carrying out data theft campaigns that begin with a phone call. The group poses as an IT helpdesk, claiming an urgent security migration is necessary. A convincing call and a fake sign-in page can turn an ordinary session into an entry point.

The calls create urgency before employees can verify the request independently. The campaign is dangerous because it does not need to crack a password.

It captures credentials and a live authentication token. That token lets an intruder act as the employee in Microsoft 365 or Okta, to access mail, files and other stored corporate data.

Analysts at Google Cloud identified the activity during ongoing data theft and extortion.

Google Cloud said in a report shared with Cyber Security News (CSN) that the group has stayed active despite the claimed retirement of its BlackFile brand, using Redact, Pink, Helix and Falcon names.

The consequences extend beyond a hijacked inbox. Stolen records can expose sensitive information and fuel extortion.

Helix and Pink DLS (Source – Google Cloud)

Recent targeting shifted toward financial services, private equity and professional services, where deal and litigation material can be especially valuable.

UNC6671 Automates Microsoft 365 Data Theft

The operation starts with voice phishing, often called vishing. Callers contact staff on personal mobile phones, sometimes spoofing a helpdesk number, claiming a passkey or multi-factor authentication update is mandatory.

They direct employees to tailored imitation enrolment portals, a technique also seen in Microsoft Graph reconnaissance attacks against workplace accounts.

The fraudulent site sits between the victim and the real login service. This adversary-in-the-middle setup relays the sign-in process while collecting the password and multi-factor authentication token.

Falcon DLS (Source – Google Cloud)

UNC6671 can then reuse the authenticated session, an approach similar to the session hijacking payroll attacks against Microsoft 365 users.

Once inside, operators use automated scripts to take data from cloud services. The report notes direct-stream access patterns associated with scripting tools, enabling large-scale reading without conventional downloads.

The group also uses residential proxy connections to make access look closer to ordinary user traffic and complicate incident response.

The operators have added steps to stay hidden. They used compromised mailboxes to reset passwords for applications that do not use single sign-on, then deleted reset confirmations, security notices and alerts tied to account or multi-factor authentication changes. That can leave a victim unaware while access and data collection continue.

Google Cloud linked the activity through recurring phishing templates, overlapping victim targeting and reused domain infrastructure.

The same generic passkey-themed domains supported campaigns used by several extortion brands, although researchers said this could reflect a coordinated group, splintered affiliates or shared phishing services.

Brand changes should not distract defenders from the method behind them.

The pace also increased. From June through July, researchers observed about one new root domain every 1.6 days, with seven domains activated over a 72-hour period in late July.

Names frequently combine passkey, MFA or SSO, reinforcing the false impression that a routine security task is underway.

Defenders should make it easy for employees to verify unexpected helpdesk requests through a known company channel.

Security teams should enforce phishing-resistant sign-in methods, shorten session lifetimes, require stronger checks for sensitive resources and restrict authentication to managed devices and trusted networks.

REDACT statement on alleged break from BlackFile (Source – Google Cloud)

These measures reduce the value of a stolen session. This matters because AiTM phishing campaigns targeting Microsoft 365 aim to exploit a valid session, not merely a stolen password.

Teams should review identity-provider and Microsoft 365 audit data for abandoned authentication challenges, unusual multi-factor enrolment, high-volume file access and scripting-related user-agent strings.

Treating FileAccessed events with the same urgency as downloads can expose direct-stream collection.

Shared infrastructure across multiple brands (Source – Google Cloud)

Monitoring for anonymised or residential-proxy logins adds another warning when activity is unusual or comes from an unfamiliar device.

UNC6671 shows how a phone call can breach cloud security. Organisations that combine staff verification procedures with resistant authentication, session controls and behavioural monitoring can stop theft before stolen data becomes an extortion tool.

Indicators of Compromise (IoCs):-

Type Indicator Description
Domain myoktasso[.]com Phishing domain, created 2026-04-04
Domain mypasskeysso[.]com Phishing domain, created 2026-04-04
Domain setupssopasskey[.]com Phishing domain, created 2026-04-07
Domain mspasskey[.]com Phishing domain, created 2026-04-08
Domain activatepasskey[.]com Phishing domain, created 2026-04-10
Domain enrollpasskey[.]com Phishing domain, created 2026-04-10
Domain keyokta[.]com Phishing domain, created 2026-04-13
Domain oktaenroll[.]com Phishing domain, created 2026-04-13
Domain oktaportalsso[.]com Phishing domain, created 2026-04-16
Domain passkeyportal[.]com Phishing domain, created 2026-04-16
Domain portalpasskey[.]com Phishing domain, created 2026-04-16
Domain passkeyportalsetup[.]com Phishing domain, created 2026-04-20
Domain addoktapasskey[.]com Phishing domain, created 2026-04-21
Domain deploypasskey[.]com Phishing domain, created 2026-04-21
Domain passkeydeploy[.]com Phishing domain, created 2026-04-23
Domain activatemypasskey[.]com Phishing domain, created 2026-04-24
Domain registerpasskey[.]com Phishing domain, created 2026-04-29
Domain createpasskey[.]com Phishing domain, created 2026-05-03
Domain passkeyadd[.]com Phishing domain, created 2026-05-08
Domain passkeyregister[.]com Phishing domain, created 2026-05-08
Domain passkeycenter[.]com Phishing domain, created 2026-05-11
Domain secureauthpasskey[.]com Phishing domain, created 2026-05-14
Domain passkeyrollout[.]com Phishing domain, created 2026-05-18
Domain setpasskey[.]com Phishing domain, created 2026-05-22
Domain passkeyokta[.]com Phishing domain, created 2026-05-26
Domain passkeyset[.]com Phishing domain, created 2026-05-27
Domain createmypasskey[.]com Phishing domain, created 2026-05-27
Domain newpasskey[.]com Phishing domain, created 2026-05-28
Domain passkeysupport[.]com Phishing domain, created 2026-05-29
Domain sqfepjvmrd[.]xyz Phishing domain, created 2026-06-01
Domain passkeyregistration[.]com Phishing domain, created 2026-06-02
Domain addmypasskey[.]com Phishing domain, created 2026-06-03
Domain passkey-setup[.]com Phishing domain, created 2026-06-03
Domain passkey-portal[.]com Phishing domain, created 2026-06-05
Domain startpasskeysetup[.]com Phishing domain, created 2026-06-05
Domain passkey-connect[.]com Phishing domain, created 2026-06-05
Domain portalsetuphub[.]com Phishing domain, created 2026-06-10
Domain activatepasskeyportal[.]com Phishing domain, created 2026-06-12
Domain assignpasskey[.]com Phishing domain, created 2026-06-13
Domain myconnectkey[.]com Phishing domain, created 2026-06-13
Domain mynewpasskey[.]com Phishing domain, created 2026-06-13
Domain passkeycreate[.]com Phishing domain, created 2026-06-16
Domain oskeyconnect[.]com Phishing domain, created 2026-06-17
Domain passkeycreator[.]com Phishing domain, created 2026-06-19
Domain oskeysync[.]com Phishing domain, created 2026-06-20
Domain enablepasskey[.]com Phishing domain, created 2026-06-22
Domain enablepasskey2fa[.]com Phishing domain, created 2026-06-22
Domain checkpasskey[.]com Phishing domain, created 2026-06-22
Domain passkeyuser[.]com Phishing domain, created 2026-06-25
Domain keysyncos[.]com Phishing domain, created 2026-06-30
Domain myaccountsecurity[.]com Phishing domain, created 2026-06-30
Domain addpasskey2fa[.]com Phishing domain, created 2026-07-01
Domain passkeyenroll[.]com Phishing domain, created 2026-07-07
Domain startpasskey[.]com Phishing domain, created 2026-07-07
Domain passkeyenable[.]com Phishing domain, created 2026-07-08
Domain passkeyactivation[.]com Phishing domain, created 2026-07-09
Domain createmfa[.]com Phishing domain, created 2026-07-09
Domain passkeyhelpdesk[.]com Phishing domain, created 2026-07-10
Domain makepasskey[.]com Phishing domain, created 2026-07-13
Domain add-passkey[.]com Phishing domain, created 2026-07-13
Domain passkey-check[.]com Phishing domain, created 2026-07-13
Domain addyourpasskey[.]com Phishing domain, created 2026-07-20
Domain passkey-enable[.]com Phishing domain, created 2026-07-20
Domain mypasskeyid[.]com Phishing domain, created 2026-07-21
Domain passkeystatus[.]com Phishing domain, created 2026-07-21
Domain secure-passkey[.]com Phishing domain, created 2026-07-21
Domain addssopasskey[.]com Phishing domain, created 2026-07-22
Domain ssopasskey[.]com Phishing domain, created 2026-07-22
Domain createssopasskey[.]com Phishing domain, created 2026-07-28
Domain myssopasskey[.]com Phishing domain, created 2026-07-31
Domain hubpasskey[.]com Phishing domain, created 2026-08-03
Domain passkeymfa[.]com Phishing domain, created 2026-08-03
IP address 31.7.56.61 AiTM panel reverse proxy
IP address 31.7.56.52 AiTM panel reverse proxy
IP address 193.34.212.132 Phishing kit backend proxy
IP address 185.178.208.153 Phishing reverse proxy
IP address 23.234.75.84 Automated SaaS data exfiltration
IP address 195.140.213.114 Automated SaaS data exfiltration
IP address 195.140.213.115 Automated SaaS data exfiltration
IP address 107.128.45.122 Microsoft 365 or Okta residential proxy
IP address 76.103.148.180 Microsoft 365 or Okta residential proxy
IP address 38.42.59.171 Microsoft 365 or Okta residential proxy
IP address 47.218.103.146 Microsoft 365 or Okta residential proxy
User-Agent python-requests/2.28.1 Scripting-related user-agent
User-Agent WindowsPowerShell/5.1 Scripting-related user-agent
User-Agent Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:146.0) Gecko/20100101 Firefox/146.0 Observed browser user-agent
User-Agent 0811A9866E.com.okta.android.auth/8.18.0 DeviceSDK/1.0.94 Android/16 Google/Pixel_9_Pro_XL Observed Okta Android SDK user-agent

tionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Stop new phishing & malware before they compromise your business. Integrate live intel from 15K SOCs around the world