This post was originally published on this site

Written by: Tyler McLellan, Austin Larsen


Introduction

Google Threat Intelligence Group (GTIG) continues to track UNC6671 actively conducting compromises leading to data theft extortion, despite the alleged announced retirement of the BlackFile extortion brand in May 2026. Telemetry and infrastructure analysis reveal that rather than disbanding, UNC6671 has diversified its operations across multiple extortion fronts including Redact, Pink, Helix, and Falcon. 

UNC6671 continues to rely on voice phishing (vishing) to target enterprise employees, posing as IT helpdesk staff facilitating mandatory, urgent security migrations. Significantly, the threat actor often contacts employees via their personal mobile devices. These calls lure victims to spoofed login portals where Adversary-in-the-Middle (AiTM) infrastructure intercepts credentials and multi-factor authentication (MFA) tokens. Once session persistence is established, the actors deploy automated scripts for data exfiltration from enterprise cloud environments, including Microsoft 365 and Okta.

In this update to our May 2026 blog, we detail the infrastructure linkages connecting these extortion brands. We also examine the evolution of UNC6671’s targeting including recent activity focused on financial services, private equity, and professional services, and provide hardening guidance to help organizations protect themselves from this threat. 

UNC6671 Associated Extortion Brands 

Across UNC6671 intrusions, the initial access and post-compromise tactics, techniques, and procedures (TTPs) have remained remarkably consistent. These operations uniformly leverage tailored IT helpdesk voice phishing (vishing), AiTM credential harvesting panels, and data theft from SaaS applications. Despite this unified technical baseline, extortion messages have used different branding and victim data stolen during these intrusions has been published across distinct data leak sites (DLS) (Figure 1). While public group communications cited an affiliate breakaway as the rationale for the initial rebranding to Redact, subsequent overlaps in phishing templates, victimology, and shared infrastructure conduits suggests that associated actors have subsequently leveraged the Pink, Helix, and Falcon extortion brands to monetize their operations.

Figure 1: UNC6671 Associated DLS Listings by Site

Figure 1: UNC6671 Associated DLS Listings by Site

Figure 2: Helix and Pink DLS

Figure 2: Helix and Pink DLS

Figure 3: Falcon DLS

Figure 3: Falcon DLS

Initial REDACT Rebranding 

On June 27, 2026, the Redact operators published a blog post on their newly established Data Leak Site (DLS) addressing their alleged rebrand away from BlackFile. In the publication, the group claimed that the original BlackFile brand had been compromised and hijacked by an exiled affiliate. According to Redact, this former associate purportedly operated an unauthorized, lookalike DLS and conducted unsanctioned extortion campaigns under their name using unlinked Tox identities. The operators asserted that this rogue affiliate intentionally orchestrated the “shutdown” of the BlackFile brand in May 2026 to sow confusion among threat intelligence analysts and cyber insurance negotiators, thereby damaging the brand’s reputation. To distance themselves from BlackFile, the operators stated that they rebranded as Redact, introducing a single verified Tox ID and PGP key to authenticate all future correspondence. Additionally, the post explicitly denied that pressure from the rival groups influenced their rebranding decision.

Figure 3: REDACT statement on alleged break from BlackFile

Figure 3: REDACT statement on alleged break from BlackFile

Shared Infrastructure: Connecting the Phishing Ecosystem

UNC6671 uses credential harvesting panels hosted on generic root domains masquerading as being related to passkeys, appending victim-specific subdomains to facilitate targeted voice phishing campaigns. Monitoring this consistent digital footprint revealed overlaps in specific victim targeting associated with multiple extortion brands. These overlaps support our assessment that a common group of threat actors are affiliated with the BlackFile, Redact, Pink, Helix, and Falcon extortion brands, although other scenarios such as splintered affiliates or shared Phishing-as-a-Service infrastructure may also be plausible. 

Rather than maintaining isolated infrastructure for each target, UNC6671 reuses generic root domains across multiple target organizations, creating a traceable chain between extortion brands:

  • Falcon: The root domain passkeyhelpdesk[.]com was used to target at least one organization extorted using the Falcon brand. This same domain was simultaneously used to target an organization extorted using the Helix brand, as well as numerous other companies that we did not observe later posted on a DLS. Additionally, root domains such as portalpasskey[.]com and addssopasskey[.]com targeted organizations extorted by Falcon, while hosting intermediate targets that bridged directly into Helix infrastructure.

  • Pink: A subset of unlisted companies were concurrently targeted using additional root domains (such as passkeyms[.]com and mysecurepasskey[.]com), which acted as intermediate bridges to another infrastructure cluster focused on passkeydeploy[.]com. This final domain was simultaneously used to target at least one organization extorted by Pink.

  • Helix: The root domain passkeyhelpdesk[.]com directly overlapped targeting between Falcon and Helix. Furthermore, intermediate target organizations bridged additional infrastructure into clusters of subdomains on oskeysync[.]com and keysyncos[.]com. These clusters targeted multiple organizations later listed on the Helix DLS.

  • BlackFile: Root domains such as setupsso[.]com and idokta[.]com were used to target an organization extorted using the BlackFile brand. Intermediary target organizations on setupsso[.]com acted as bridges to passkeydeploy[.]com (Pink). Concurrently, passkeyuser[.]com was used to target another BlackFile victim, where intermediate target organizations bridged into passkeyportal[.]com (Helix) and mysecurepasskey[.]com.

Figure 4 - fixed

Figure 4: Shared infrastructure across multiple brands

Phishing templates

Analysis shows that the same phishing templates were used across all these domains, with identical code and design hosted simultaneously on different websites, including addssopasskey[.]com, createssopasskey[.]com, and passkeyhelpdesk[.]com. For instance, while addssopasskey[.]com was strictly used to target organizations later extorted by Falcon, the identically configured passkeyhelpdesk[.]com domain was simultaneously used to target two entirely separate victims—one of which was claimed by Falcon, and the other by Helix. The widespread deployment of these matching templates to harvest credentials for multiple DLS brands suggests they rely on shared underlying infrastructure.

Evolution of Targeting

UNC6671’s domain registration patterns demonstrate a regular shift in target selection, seemingly towards those that are more likely to hold sensitive information. UNC6671 leverages subdomains that incorporate prospective victim names to host tailored credential harvesting panels. Their root domains mimic enterprise authentication enrollment portals pairing terms as “passkey,” “mfa,” or “sso” paired with verbs.

Between April and May 2026, we observed domains broadly designed to target mature, large-scale enterprises across multiple industries including the manufacturing, real estate, healthcare, and insurance sectors. During this wave of activity, the threat actors appeared to prioritize high-volume credential harvesting across these established enterprise verticals.

The observed subdomains in the following months appeared to represent a progression in UNC6671’s extortion model. In June 2026, targeting transitioned toward large technology, transportation, and hospitality organizations, seemingly focusing on entities holding valuable intellectual property, software source code, or sensitive VIP client data. By July 2026, the target profile narrowed to focus on the financial and legal sectors, with observed infrastructure directed at private equity firms, law firms, and financial rating agencies. Concentrating on organizations involved in mergers, acquisitions, capital deployment, and litigation may reflect a strategy to target high-value corporate and confidential data to maximize leverage extortion demands.

Comparing these two time periods also illustrates an increase in operational tempo. The volume of newly observed infrastructure was evenly distributed between June 1 and July 31, 2026, establishing an accelerated cadence of approximately one domain every 1.6 days, primarily across Cloudflare and DDOS-GUARD. A brief spike in provisioning also occurred between July 20 and July 22, during which seven domains were operationalized within a 72-hour window. This overall June and July tempo represents a measurable increase from earlier activity observed between April 1 and May 31, 2026, where a set of 28 root domains was provisioned at a less frequent rate of one every 2.2 days.

On the date of publication of this blog, 7 of 8 still resolving phishing domains did not use wildcard DNS indicating that targets discovered through passive DNS data were likely specifically targeted by UNC6671. 

Figure 5: Root domain registrations

Figure 5: Root domain registrations

New Techniques 

Since our last blog, the tactics across UNC6671 intrusions have been largely consistent; however, we have observed several new techniques.

IT Helpdesk and Passkey Pretexts

UNC6671 callers have continued to call targeted employees on their personal mobile numbers, circumventing corporate security controls. In at least some recent cases, the threat actor has spoofed the legitimate helpdesk phone number adding an air of legitimacy. During these phone calls, operating under the false pretext of an urgent helpdesk mandate to enable FIDO2 passkeys or update multi-factor authentication enrollment, the caller directs the employee to a lookalike credential-harvesting subdomain (e.g., [company].createssopasskey[.]com or [company].addssopasskey[.]com).

EvasionTechniques

UNC6671 increasingly relies on defense evasion to maintain account-level persistence and conceal its operations. In recent intrusions, the group used compromised email accounts to initiate unauthorized password resets for non-SSO enterprise applications. To prevent end-user detection or automated security alerts, operators systematically deleted password-reset confirmations, secondary security notifications, company-wide security alerts, and any alerts generated during modifications to account security or MFA configurations.

Ransom Negotiations and Blockchain Analysis

Between January 7, 2026, and May 12, 2026, GTIG reviewed 18 BlackFile Bitcoin wallet addresses receiving a total of 141.65 BTC, representing approximately $10.69 million USD at the time of the transactions. Notably, ransom payments to these wallets continued past the publicized Blackfile data leak site shutdown notice on May 11, 2026. Multiple significant cashout events observed in late April and early May confirm that financial operations proceeded without interruption during the rebranding phase.

Initial ransom demands typically range from $1 million to upwards of $3 million USD. However, the extortion operators shifted demands during negotiations, often agreeing to reductions between 50% and 75% of the initial ransom demand. In over 53% of tracked cases in this timeframe, final payments averaged $750,000 USD (~10.2 BTC). 

Remediation and Hardening Guidance

GTIG recommends that corporate defenders implement the following controls to mitigate identity-centric vishing, AiTM phishing, and programmatic SaaS exfiltration:

  1. Enforce Phishing-Resistant Multi-factor Authentication: Mandate phishing-resistant authenticators such as FIDO2-compliant roaming security keys, passkeys, and platform authenticators (e.g., Windows Hello for Business, Okta Fastpass) across all SSO environments and enterprise identity providers (IdPs). These authenticators implement WebAuthn standard to enforce cryptographic origin binding between the authenticator and the specific domains it can authenticate to, rendering lookalike domains and AiTM proxies ineffective.

  2. Integrate SaaS Applications and Cloud Platforms with SSO: Maintaining authentication standards across multiple platforms increases the propensity for configuration drift. Different SaaS applications require or support different security features. Integrating business-critical applications with a standard SSO platform such as Entra ID or Okta allows consistent application of security controls across disparate platforms.

  3. Enforce Session Controls: Reduce session lengths to enforce re-authentication at least once per work day. Enforce idle session timeouts, especially for privileged access. These timeouts can be reduced further during active phishing campaigns. Enforce step-up authentication when accessing critical or sensitive resources. Utilize token theft mitigations within authentication platforms such as IP session binding, Device-Bound Session Credentials, or Continuous Access Evaluation.

  4. Restrict Authentication to Trusted Network Sources: Utilize defined network zones coming from known sources such as corporate networks, VPN ranges, and Secure Access Service Edge (SASE) platforms. Define and enforce these ranges within SaaS apps or cloud platforms as well as within authentication policies in Entra ID or Okta.

  5. Require Corporate-Managed Devices for Access: Enforcing that authentication comes from a corporate-managed endpoint with MDM and EDR reduces the attack surface and likelihood that an attacker can utilize an arbitrary device for access. Device checks can be configured as part of authentication policies in Entra ID or Okta.

  6. Deploy Endpoint and Browser Credential Guarding: Enable Google Workspace Password Alert to trigger automated administrative alerts or resets if corporate password hashes are entered into unauthorized domains. For Microsoft 365 environments, configure Microsoft Defender SmartScreen and Credential Protection to block credential submissions on unverified sites.

  7. Monitor IdP Logs for Abandoned Challenge Patterns: Query Okta and Microsoft Entra ID audit logs for MFA registration events (system.multifactor.factor.setup) that are immediately preceded by authentication failures (user.authentication.auth_via_mfa) or abandoned push challenges.

  8. Audit UAL Telemetry for Direct Stream Exfiltration: Configure Security Operations Center (SOC) detection pipelines to treat FileAccessed events with the same criticality as FileDownloaded when the UserAgent string identifies a scripting library (python-requests, WindowsPowerShell, Go-http-client) or when the access volume exceeds normal human browsing thresholds.

  9. Restrict and Alert on Residential Proxy Authentication: Create conditional access policies and anomaly alerts for SSO authentication attempts originating from commercial VPN providers (Mullvad, Private Layer) or unassociated residential broadband proxy pools (AT&T, Comcast, Charter) that diverge from established employee geographic baselines.

Outlook and Implications

The activity associated with UNC6671 highlights the fluidity of threat actor brands relative to persistent tactics, techniques, and procedures. While the extortion brands associated with this activity continue to multiply, the tradecraft across these operations remains anchored in helpdesk vishing, AiTM session interception, and SaaS exfiltration.

We believe that this most likely reflects a coordinated group of threat actors operating multiple public extortion brands possibly in an effort to compartmentalize operations, hide overall breach volumes, and isolate any negotiation fallout. This assessment is supported by the tight infrastructure overlaps, shared vishing panel deployments, and overlaps in victim targeting observed across BlackFile, Redact, Pink, Helix, and Falcon. However, there are several other scenarios that could explain the broader dynamics across these brands:

  • Actor Splintering: Internal rifts, financial disputes, or operational security compromises routinely lead to group fragmentation. Former affiliates or splinter cells retaining access to shared initial access playbooks, panel code, and target lists can easily establish independent extortion fronts while continuing to execute identical TTPs.

  • Shared Ecosystem and Panel use: Separate threat groups may simply be leveraging the same commoditized phishing panels, voice-phishing callers, and shared infrastructure. As these AiTM panels and VaaS services become widely available, distinct threat actors can deploy matching infrastructure and pretexts without requiring direct organizational alignment.

  • Outsourced Extortion: The intrusion operators driving initial access and cloud data exfiltration could remain the same core group of actors, while the extortion and negotiation phases are outsourced to different actors.

Regardless of whether this activity reflects a fractured threat group, outsourced extortion negotiators, or a broader affiliate network, the initial infection vector leveraged and goals of these campaigns is consistent. Organizations should prioritize phishing-resistant authenticators and behavioral SaaS auditing to disrupt these identity-centric attacks.

Indicators of Compromise (IOCs)

To assist the wider community in hunting and identifying activity outlined in this blog post, we have provided indicators of compromise (IOCs) in a free GTI Collection for registered users. At the time of publication, identified phishing domains have been added to Google Safe Browsing.

While this collection provides a comprehensive list of IOCs, defenders should note that the majority of identified IP addresses are commercial VPN nodes, and actual source IPs tend to vary as the actor continuously cycles through new infrastructure. Furthermore, the domains are often stood up and used within minutes of registration; as such, they are provided primarily as examples of past naming conventions and usage patterns rather than as a primary mechanism for real-time blocking.

 

Domain

Creation Date

Registrar

Name Servers

Targeted Industry

myoktasso[.]com

2026-04-04

TUCOWS.COM, CO.

Njalla / Pipe.ma

Financial Services, Transportation

mypasskeysso[.]com

2026-04-04

TUCOWS.COM, CO.

Cloudflare

Healthcare

setupssopasskey[.]com

2026-04-07

TUCOWS.COM, CO.

Cloudflare

Financial Services, Healthcare, Media & Entertainment

mspasskey[.]com

2026-04-08

TUCOWS.COM, CO.

Cloudflare

Real Estate, Healthcare, Technology

activatepasskey[.]com

2026-04-10

TUCOWS.COM, CO.

Cloudflare

Financial Services, Hospitality, Healthcare

enrollpasskey[.]com

2026-04-10

TUCOWS.COM, CO.

Cloudflare

Financial Services, Energy, Healthcare

keyokta[.]com

2026-04-13

TUCOWS.COM, CO.

Cloudflare

Healthcare, Financial Services

oktaenroll[.]com

2026-04-13

TUCOWS.COM, CO.

Cloudflare

Healthcare, Construction & Engineering

oktaportalsso[.]com

2026-04-16

TUCOWS.COM, CO.

Cloudflare

Retail & Consumer Goods, Healthcare, Legal

passkeyportal[.]com

2026-04-16

TUCOWS.COM, CO.

Cloudflare

N/A

portalpasskey[.]com

2026-04-16

TUCOWS.COM, CO.

Cloudflare

Transportation

passkeyportalsetup[.]com

2026-04-20

NICENIC INTERNATIONAL GROUP CO., LIMITED

Cloudflare

Financial Services, Technology

addoktapasskey[.]com

2026-04-21

NICENIC INTERNATIONAL GROUP CO., LIMITED

Private Layer (31.7.56.61)

Financial Services, Technology, Media & Entertainment

deploypasskey[.]com

2026-04-21

TUCOWS.COM, CO.

DDOS-GUARD

Retail & Consumer Goods

passkeydeploy[.]com

2026-04-23

Internet Domain Service BS Corp.

DDOS-GUARD

Healthcare, Technology

activatemypasskey[.]com

2026-04-24

TUCOWS.COM, CO.

Cloudflare

Financial Services

registerpasskey[.]com

2026-04-29

NICENIC INTERNATIONAL GROUP CO., LIMITED

MEVSPACE (193.34.212.132)

Manufacturing

createpasskey[.]com

2026-05-03

NICENIC INTERNATIONAL GROUP CO., LIMITED

Cloudflare

N/A

passkeyadd[.]com

2026-05-08

TUCOWS.COM, CO.

DDOS-GUARD

Business Services, Technology

passkeyregister[.]com

2026-05-08

NICENIC INTERNATIONAL GROUP CO., LIMITED

Cloudflare / MEVSPACE

Energy, Technology, Healthcare

passkeycenter[.]com

2026-05-11

NICENIC INTERNATIONAL GROUP CO., LIMITED

Cloudflare

Legal, Financial Services, Healthcare

secureauthpasskey[.]com

2026-05-14

NICENIC INTERNATIONAL GROUP CO., LIMITED

Cloudflare

Healthcare

passkeyrollout[.]com

2026-05-18

NICENIC INTERNATIONAL GROUP CO., LIMITED

Cloudflare / MEVSPACE

Non-Corporate, Insurance, Legal

setpasskey[.]com

2026-05-22

Internet Domain Service BS Corp.

DDOS-GUARD

Technology, Business Services, Construction & Engineering

passkeyokta[.]com

2026-05-26

NICENIC INTERNATIONAL GROUP CO., LIMITED

Cloudflare

Media & Entertainment, Transportation

passkeyset[.]com

2026-05-27

NICENIC INTERNATIONAL GROUP CO., LIMITED

Cloudflare

Transportation

createmypasskey[.]com

2026-05-27

NICENIC INTERNATIONAL GROUP CO., LIMITED

Cloudflare

Construction & Engineering

newpasskey[.]com

2026-05-28

NICENIC INTERNATIONAL GROUP CO., LIMITED

Cloudflare

Media & Entertainment

passkeysupport[.]com

2026-05-29

NICENIC INTERNATIONAL GROUP CO., LIMITED

Cloudflare

Healthcare, Technology, Legal, Retail & Consumer Goods

sqfepjvmrd[.]xyz

2026-06-01

NICENIC INTERNATIONAL GROUP CO., LIMITED

MY-NDNS

N/A

passkeyregistration[.]com

2026-06-02

PDR Ltd. d/b/a PublicDomainRegistry.com

Suspended-Domain

N/A

addmypasskey[.]com

2026-06-03

TUCOWS.COM, CO.

Private Layer (31.7.56.52)

Financial Services, Healthcare, Transportation

passkey-setup[.]com

2026-06-03

Tucows Domains Inc.

Cloudflare

Legal, Financial Services

passkey-portal[.]com

2026-06-05

NICENIC INTERNATIONAL GROUP CO., LIMITED

Cloudflare / Private Layer

Retail & Consumer Goods, Technology, Media & Entertainment

startpasskeysetup[.]com

2026-06-05

NICENIC INTERNATIONAL GROUP CO., LIMITED

Cloudflare / Private Layer

Technology, Healthcare, Retail & Consumer Goods, Construction & Engineering, Media & Entertainment, Financial Services

passkey-connect[.]com

2026-06-05

NICENIC INTERNATIONAL GROUP CO., LIMITED

Cloudflare

Technology

portalsetuphub[.]com

2026-06-10

PDR Ltd. d/b/a PublicDomainRegistry.com

Suspended-Domain

Financial Services, Healthcare, Energy, Real Estate, Technology, Construction & Engineering

activatepasskeyportal[.]com

2026-06-12

NICENIC INTERNATIONAL GROUP CO., LIMITED

Cloudflare / Private Layer

Technology, Energy

assignpasskey[.]com

2026-06-13

Internet Domain Service BS Corp.

DDOS-GUARD

Construction & Engineering, Financial Services, Energy

myconnectkey[.]com

2026-06-13

NICENIC INTERNATIONAL GROUP CO., LIMITED

Cloudflare

Transportation, Financial Services, Construction & Engineering, Real Estate, Business Services, Retail & Consumer Goods, Healthcare

mynewpasskey[.]com

2026-06-13

NICENIC INTERNATIONAL GROUP CO., LIMITED

Cloudflare

Retail & Consumer Goods, Healthcare, Financial Services, Energy

passkeycreate[.]com

2026-06-16

NICENIC INTERNATIONAL GROUP CO., LIMITED

Cloudflare

Construction & Engineering, Financial Services, Retail & Consumer Goods, Legal, Energy

oskeyconnect[.]com

2026-06-17

NICENIC INTERNATIONAL GROUP CO., LIMITED

Cloudflare

Financial Services, Real Estate, Legal, Healthcare, Transportation, Utilities, Construction & Engineering, Retail & Consumer Goods, Hospitality

passkeycreator[.]com

2026-06-19

NICENIC INTERNATIONAL GROUP CO., LIMITED

Cloudflare

Non-Corporate, Media & Entertainment, Legal, Healthcare, Energy, Technology

oskeysync[.]com

2026-06-20

NICENIC INTERNATIONAL GROUP CO., LIMITED

EZYDOMAIN

Healthcare, Financial Services, Transportation, Real Estate, Technology, Construction & Engineering, Retail & Consumer Goods, Legal, Energy, Utilities, Hospitality

enablepasskey[.]com

2026-06-22

NICENIC INTERNATIONAL GROUP CO., LIMITED

Cloudflare

Legal

enablepasskey2fa[.]com

2026-06-22

NICENIC INTERNATIONAL GROUP CO., LIMITED

Cloudflare

Healthcare, Media & Entertainment

checkpasskey[.]com

2026-06-22

NICENIC INTERNATIONAL GROUP CO., LIMITED

Cloudflare / Private Layer

Legal, Construction & Engineering, Retail & Consumer Goods, Transportation

passkeyuser[.]com

2026-06-25

NICENIC INTERNATIONAL GROUP CO., LIMITED

Cloudflare

Construction & Engineering, Legal, Aerospace & Defense, Financial Services, Technology

keysyncos[.]com

2026-06-30

NICENIC INTERNATIONAL GROUP CO., LIMITED

Cloudflare

Financial Services, Real Estate, Healthcare, Technology, Construction & Engineering, Transportation, Legal, Retail & Consumer Goods, Energy, Utilities, Hospitality

myaccountsecurity[.]com

2026-06-30

NICENIC INTERNATIONAL GROUP CO., LIMITED

Cloudflare

Construction & Engineering

addpasskey2fa[.]com

2026-07-01

NICENIC INTERNATIONAL GROUP CO., LIMITED

Cloudflare / Private Layer

Financial Services, Legal

passkeyenroll[.]com

2026-07-07

NICENIC INTERNATIONAL GROUP CO., LIMITED

Cloudflare

Financial Services

startpasskey[.]com

2026-07-07

NICENIC INTERNATIONAL GROUP CO., LIMITED

Cloudflare

Construction & Engineering, Retail & Consumer Goods

passkeyenable[.]com

2026-07-08

NICENIC INTERNATIONAL GROUP CO., LIMITED

Cloudflare

Financial Services, Legal

passkeyactivation[.]com

2026-07-09

NICENIC INTERNATIONAL GROUP CO., LIMITED

Cloudflare

Financial Services

createmfa[.]com

2026-07-09

NICENIC INTERNATIONAL GROUP CO., LIMITED

Cloudflare / Private Layer

Construction & Engineering, Energy, Financial Services, Healthcare, Transportation

passkeyhelpdesk[.]com

2026-07-10

NICENIC INTERNATIONAL GROUP CO., LIMITED

Cloudflare / Private Layer

Financial Services, Energy, Healthcare

makepasskey[.]com

2026-07-13

Internet Domain Service BS Corp.

DDOS-GUARD

N/A

add-passkey[.]com

2026-07-13

NICENIC INTERNATIONAL GROUP CO., LIMITED

Cloudflare

Healthcare, Energy

passkey-check[.]com

2026-07-13

NICENIC INTERNATIONAL GROUP CO., LIMITED

Cloudflare

Financial Services, Media & Entertainment

addyourpasskey[.]com

2026-07-20

NICENIC INTERNATIONAL GROUP CO., LIMITED

Cloudflare

Financial Services, Utilities

passkey-enable[.]com

2026-07-20

NICENIC INTERNATIONAL GROUP CO., LIMITED

Cloudflare

Aerospace & Defense, Technology

mypasskeyid[.]com

2026-07-21

NICENIC INTERNATIONAL GROUP CO., LIMITED

Cloudflare / Private Layer

Technology, Retail & Consumer Goods

passkeystatus[.]com

2026-07-21

NICENIC INTERNATIONAL GROUP CO., LIMITED

Cloudflare

Energy, Technology

secure-passkey[.]com

2026-07-21

NICENIC INTERNATIONAL GROUP CO., LIMITED

Cloudflare

Energy, Financial Services

addssopasskey[.]com

2026-07-22

NICENIC INTERNATIONAL GROUP CO., LIMITED

Cloudflare / Private Layer

Financial Services

ssopasskey[.]com

2026-07-22

NICENIC INTERNATIONAL GROUP CO., LIMITED

Cloudflare

N/A

createssopasskey[.]com

2026-07-28

NICENIC INTERNATIONAL GROUP CO., LIMITED

Cloudflare / Private Layer

Financial Services

myssopasskey[.]com

2026-07-31

NICENIC INTERNATIONAL GROUP CO., LIMITED

Cloudflare

Financial Services

hubpasskey[.]com

2026-08-03

NICENIC INTERNATIONAL GROUP CO., LIMITED

Cloudflare

Financial Services

passkeymfa[.]com

2026-08-03

NICENIC INTERNATIONAL GROUP CO., LIMITED

Cloudflare

Financial Services

 

Table 1: Indicators of compromise

Network Infrastructure and Exfiltration Observables

IP Address 

Role 

ASN

31.7.56.61

Panel AiTM Reverse Proxy

AS51852 Private Layer INC (Switzerland)

31.7.56.52

Panel AiTM Reverse Proxy

AS51852 Private Layer INC (Switzerland)

193.34.212.132

Phishing Kit Backend Proxy

AS201814 MEVSPACE (Poland)

185.178.208.153

Phishing Reverse Proxy

AS57724 DDOS-GUARD LTD (Russia)

23.234.75.84

Automated SaaS Data Exfiltration

AS11878 Tzulo, Inc. (United States)

195.140.213.114

Automated SaaS Data Exfiltration

AS25369 Hydra Communications Ltd (United Kingdom)

195.140.213.115

Automated SaaS Data Exfiltration

AS25369 Hydra Communications Ltd (United Kingdom)

107.128.45.122

M365 / Okta Residential Proxy

AS7018 AT&T Enterprises, LLC (United States)

76.103.148.180

M365 / Okta Residential Proxy

AS7922 Comcast Cable Communications (United States)

38.42.59.171

M365 / Okta Residential Proxy

AS395354 Starry, Inc. (United States)

47.218.103.146

M365 / Okta Residential Proxy

AS19108 Optimum / Suddenlink (United States)

Table 2: Network infrastructure and exfiltration observables

Scripting and SDK User-Agent Strings

python-requests/2.28.1

WindowsPowerShell/5.1

Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:146.0) Gecko/20100101 Firefox/146.0

0811A9866E.com.okta.android.auth/8.18.0 DeviceSDK/1.0.94 Android/16 Google/Pixel_9_Pro_XL

Figure 6: Scripting and SDK user-agent strings

Google Security Operations (SecOps) Detections

Google SecOps customers have access to automated detection rules under the Okta and Microsoft 365 rule packs that identify the vishing, MFA modification, and programmatic streaming activity described in this report:

  • Okta Admin Console Access Failure

  • Okta Suspicious Actions from Anonymized IP

  • Okta MFA Factor Setup Following Abandoned Challenge

  • O365 SharePoint Bulk File Access or Download via PowerShell

  • O365 SharePoint High Volume File Access Events

  • O365 SharePoint Query for Proprietary or Privileged Information

  • Okta User Authentication with Suspicious Behavioral Flags

Acknowledgements

Special thanks to researcher ZachXBT for assisting with cryptocurrency analysis.