Written by: Tyler McLellan, Austin Larsen
Introduction
Google Threat Intelligence Group (GTIG) continues to track UNC6671 actively conducting compromises leading to data theft extortion, despite the alleged announced retirement of the BlackFile extortion brand in May 2026. Telemetry and infrastructure analysis reveal that rather than disbanding, UNC6671 has diversified its operations across multiple extortion fronts including Redact, Pink, Helix, and Falcon.
UNC6671 continues to rely on voice phishing (vishing) to target enterprise employees, posing as IT helpdesk staff facilitating mandatory, urgent security migrations. Significantly, the threat actor often contacts employees via their personal mobile devices. These calls lure victims to spoofed login portals where Adversary-in-the-Middle (AiTM) infrastructure intercepts credentials and multi-factor authentication (MFA) tokens. Once session persistence is established, the actors deploy automated scripts for data exfiltration from enterprise cloud environments, including Microsoft 365 and Okta.
In this update to our May 2026 blog, we detail the infrastructure linkages connecting these extortion brands. We also examine the evolution of UNC6671’s targeting including recent activity focused on financial services, private equity, and professional services, and provide hardening guidance to help organizations protect themselves from this threat.
UNC6671 Associated Extortion Brands
Across UNC6671 intrusions, the initial access and post-compromise tactics, techniques, and procedures (TTPs) have remained remarkably consistent. These operations uniformly leverage tailored IT helpdesk voice phishing (vishing), AiTM credential harvesting panels, and data theft from SaaS applications. Despite this unified technical baseline, extortion messages have used different branding and victim data stolen during these intrusions has been published across distinct data leak sites (DLS) (Figure 1). While public group communications cited an affiliate breakaway as the rationale for the initial rebranding to Redact, subsequent overlaps in phishing templates, victimology, and shared infrastructure conduits suggests that associated actors have subsequently leveraged the Pink, Helix, and Falcon extortion brands to monetize their operations.
Figure 1: UNC6671 Associated DLS Listings by Site
Figure 2: Helix and Pink DLS
Figure 3: Falcon DLS
Initial REDACT Rebranding
On June 27, 2026, the Redact operators published a blog post on their newly established Data Leak Site (DLS) addressing their alleged rebrand away from BlackFile. In the publication, the group claimed that the original BlackFile brand had been compromised and hijacked by an exiled affiliate. According to Redact, this former associate purportedly operated an unauthorized, lookalike DLS and conducted unsanctioned extortion campaigns under their name using unlinked Tox identities. The operators asserted that this rogue affiliate intentionally orchestrated the “shutdown” of the BlackFile brand in May 2026 to sow confusion among threat intelligence analysts and cyber insurance negotiators, thereby damaging the brand’s reputation. To distance themselves from BlackFile, the operators stated that they rebranded as Redact, introducing a single verified Tox ID and PGP key to authenticate all future correspondence. Additionally, the post explicitly denied that pressure from the rival groups influenced their rebranding decision.
Figure 3: REDACT statement on alleged break from BlackFile
Shared Infrastructure: Connecting the Phishing Ecosystem
UNC6671 uses credential harvesting panels hosted on generic root domains masquerading as being related to passkeys, appending victim-specific subdomains to facilitate targeted voice phishing campaigns. Monitoring this consistent digital footprint revealed overlaps in specific victim targeting associated with multiple extortion brands. These overlaps support our assessment that a common group of threat actors are affiliated with the BlackFile, Redact, Pink, Helix, and Falcon extortion brands, although other scenarios such as splintered affiliates or shared Phishing-as-a-Service infrastructure may also be plausible.
Rather than maintaining isolated infrastructure for each target, UNC6671 reuses generic root domains across multiple target organizations, creating a traceable chain between extortion brands:
-
Falcon: The root domain
passkeyhelpdesk[.]comwas used to target at least one organization extorted using the Falcon brand. This same domain was simultaneously used to target an organization extorted using the Helix brand, as well as numerous other companies that we did not observe later posted on a DLS. Additionally, root domains such asportalpasskey[.]comandaddssopasskey[.]comtargeted organizations extorted by Falcon, while hosting intermediate targets that bridged directly into Helix infrastructure. -
Pink: A subset of unlisted companies were concurrently targeted using additional root domains (such as
passkeyms[.]comandmysecurepasskey[.]com), which acted as intermediate bridges to another infrastructure cluster focused onpasskeydeploy[.]com. This final domain was simultaneously used to target at least one organization extorted by Pink. -
Helix: The root domain
passkeyhelpdesk[.]comdirectly overlapped targeting between Falcon and Helix. Furthermore, intermediate target organizations bridged additional infrastructure into clusters of subdomains onoskeysync[.]comandkeysyncos[.]com. These clusters targeted multiple organizations later listed on the Helix DLS. -
BlackFile: Root domains such as
setupsso[.]comandidokta[.]comwere used to target an organization extorted using the BlackFile brand. Intermediary target organizations onsetupsso[.]comacted as bridges topasskeydeploy[.]com(Pink). Concurrently,passkeyuser[.]comwas used to target another BlackFile victim, where intermediate target organizations bridged intopasskeyportal[.]com(Helix) andmysecurepasskey[.]com.
Figure 4: Shared infrastructure across multiple brands
Phishing templates
Analysis shows that the same phishing templates were used across all these domains, with identical code and design hosted simultaneously on different websites, including addssopasskey[.]com, createssopasskey[.]com, and passkeyhelpdesk[.]com. For instance, while addssopasskey[.]com was strictly used to target organizations later extorted by Falcon, the identically configured passkeyhelpdesk[.]com domain was simultaneously used to target two entirely separate victims—one of which was claimed by Falcon, and the other by Helix. The widespread deployment of these matching templates to harvest credentials for multiple DLS brands suggests they rely on shared underlying infrastructure.
Evolution of Targeting
UNC6671’s domain registration patterns demonstrate a regular shift in target selection, seemingly towards those that are more likely to hold sensitive information. UNC6671 leverages subdomains that incorporate prospective victim names to host tailored credential harvesting panels. Their root domains mimic enterprise authentication enrollment portals pairing terms as “passkey,” “mfa,” or “sso” paired with verbs.
Between April and May 2026, we observed domains broadly designed to target mature, large-scale enterprises across multiple industries including the manufacturing, real estate, healthcare, and insurance sectors. During this wave of activity, the threat actors appeared to prioritize high-volume credential harvesting across these established enterprise verticals.
The observed subdomains in the following months appeared to represent a progression in UNC6671’s extortion model. In June 2026, targeting transitioned toward large technology, transportation, and hospitality organizations, seemingly focusing on entities holding valuable intellectual property, software source code, or sensitive VIP client data. By July 2026, the target profile narrowed to focus on the financial and legal sectors, with observed infrastructure directed at private equity firms, law firms, and financial rating agencies. Concentrating on organizations involved in mergers, acquisitions, capital deployment, and litigation may reflect a strategy to target high-value corporate and confidential data to maximize leverage extortion demands.
Comparing these two time periods also illustrates an increase in operational tempo. The volume of newly observed infrastructure was evenly distributed between June 1 and July 31, 2026, establishing an accelerated cadence of approximately one domain every 1.6 days, primarily across Cloudflare and DDOS-GUARD. A brief spike in provisioning also occurred between July 20 and July 22, during which seven domains were operationalized within a 72-hour window. This overall June and July tempo represents a measurable increase from earlier activity observed between April 1 and May 31, 2026, where a set of 28 root domains was provisioned at a less frequent rate of one every 2.2 days.
On the date of publication of this blog, 7 of 8 still resolving phishing domains did not use wildcard DNS indicating that targets discovered through passive DNS data were likely specifically targeted by UNC6671.
Figure 5: Root domain registrations
New Techniques
Since our last blog, the tactics across UNC6671 intrusions have been largely consistent; however, we have observed several new techniques.
IT Helpdesk and Passkey Pretexts
UNC6671 callers have continued to call targeted employees on their personal mobile numbers, circumventing corporate security controls. In at least some recent cases, the threat actor has spoofed the legitimate helpdesk phone number adding an air of legitimacy. During these phone calls, operating under the false pretext of an urgent helpdesk mandate to enable FIDO2 passkeys or update multi-factor authentication enrollment, the caller directs the employee to a lookalike credential-harvesting subdomain (e.g., [company].createssopasskey[.]com or [company].addssopasskey[.]com).
EvasionTechniques
UNC6671 increasingly relies on defense evasion to maintain account-level persistence and conceal its operations. In recent intrusions, the group used compromised email accounts to initiate unauthorized password resets for non-SSO enterprise applications. To prevent end-user detection or automated security alerts, operators systematically deleted password-reset confirmations, secondary security notifications, company-wide security alerts, and any alerts generated during modifications to account security or MFA configurations.
Ransom Negotiations and Blockchain Analysis
Between January 7, 2026, and May 12, 2026, GTIG reviewed 18 BlackFile Bitcoin wallet addresses receiving a total of 141.65 BTC, representing approximately $10.69 million USD at the time of the transactions. Notably, ransom payments to these wallets continued past the publicized Blackfile data leak site shutdown notice on May 11, 2026. Multiple significant cashout events observed in late April and early May confirm that financial operations proceeded without interruption during the rebranding phase.
Initial ransom demands typically range from $1 million to upwards of $3 million USD. However, the extortion operators shifted demands during negotiations, often agreeing to reductions between 50% and 75% of the initial ransom demand. In over 53% of tracked cases in this timeframe, final payments averaged $750,000 USD (~10.2 BTC).
Remediation and Hardening Guidance
GTIG recommends that corporate defenders implement the following controls to mitigate identity-centric vishing, AiTM phishing, and programmatic SaaS exfiltration:
-
Enforce Phishing-Resistant Multi-factor Authentication: Mandate phishing-resistant authenticators such as FIDO2-compliant roaming security keys, passkeys, and platform authenticators (e.g., Windows Hello for Business, Okta Fastpass) across all SSO environments and enterprise identity providers (IdPs). These authenticators implement WebAuthn standard to enforce cryptographic origin binding between the authenticator and the specific domains it can authenticate to, rendering lookalike domains and AiTM proxies ineffective.
-
Integrate SaaS Applications and Cloud Platforms with SSO: Maintaining authentication standards across multiple platforms increases the propensity for configuration drift. Different SaaS applications require or support different security features. Integrating business-critical applications with a standard SSO platform such as Entra ID or Okta allows consistent application of security controls across disparate platforms.
-
Enforce Session Controls: Reduce session lengths to enforce re-authentication at least once per work day. Enforce idle session timeouts, especially for privileged access. These timeouts can be reduced further during active phishing campaigns. Enforce step-up authentication when accessing critical or sensitive resources. Utilize token theft mitigations within authentication platforms such as IP session binding, Device-Bound Session Credentials, or Continuous Access Evaluation.
-
Restrict Authentication to Trusted Network Sources: Utilize defined network zones coming from known sources such as corporate networks, VPN ranges, and Secure Access Service Edge (SASE) platforms. Define and enforce these ranges within SaaS apps or cloud platforms as well as within authentication policies in Entra ID or Okta.
-
Require Corporate-Managed Devices for Access: Enforcing that authentication comes from a corporate-managed endpoint with MDM and EDR reduces the attack surface and likelihood that an attacker can utilize an arbitrary device for access. Device checks can be configured as part of authentication policies in Entra ID or Okta.
-
Deploy Endpoint and Browser Credential Guarding: Enable Google Workspace Password Alert to trigger automated administrative alerts or resets if corporate password hashes are entered into unauthorized domains. For Microsoft 365 environments, configure Microsoft Defender SmartScreen and Credential Protection to block credential submissions on unverified sites.
-
Monitor IdP Logs for Abandoned Challenge Patterns: Query Okta and Microsoft Entra ID audit logs for MFA registration events (
system.multifactor.factor.setup) that are immediately preceded by authentication failures (user.authentication.auth_via_mfa) or abandoned push challenges. -
Audit UAL Telemetry for Direct Stream Exfiltration: Configure Security Operations Center (SOC) detection pipelines to treat
FileAccessedevents with the same criticality asFileDownloadedwhen theUserAgentstring identifies a scripting library (python-requests,WindowsPowerShell,Go-http-client) or when the access volume exceeds normal human browsing thresholds. -
Restrict and Alert on Residential Proxy Authentication: Create conditional access policies and anomaly alerts for SSO authentication attempts originating from commercial VPN providers (Mullvad, Private Layer) or unassociated residential broadband proxy pools (AT&T, Comcast, Charter) that diverge from established employee geographic baselines.
Outlook and Implications
The activity associated with UNC6671 highlights the fluidity of threat actor brands relative to persistent tactics, techniques, and procedures. While the extortion brands associated with this activity continue to multiply, the tradecraft across these operations remains anchored in helpdesk vishing, AiTM session interception, and SaaS exfiltration.
We believe that this most likely reflects a coordinated group of threat actors operating multiple public extortion brands possibly in an effort to compartmentalize operations, hide overall breach volumes, and isolate any negotiation fallout. This assessment is supported by the tight infrastructure overlaps, shared vishing panel deployments, and overlaps in victim targeting observed across BlackFile, Redact, Pink, Helix, and Falcon. However, there are several other scenarios that could explain the broader dynamics across these brands:
-
Actor Splintering: Internal rifts, financial disputes, or operational security compromises routinely lead to group fragmentation. Former affiliates or splinter cells retaining access to shared initial access playbooks, panel code, and target lists can easily establish independent extortion fronts while continuing to execute identical TTPs.
-
Shared Ecosystem and Panel use: Separate threat groups may simply be leveraging the same commoditized phishing panels, voice-phishing callers, and shared infrastructure. As these AiTM panels and VaaS services become widely available, distinct threat actors can deploy matching infrastructure and pretexts without requiring direct organizational alignment.
-
Outsourced Extortion: The intrusion operators driving initial access and cloud data exfiltration could remain the same core group of actors, while the extortion and negotiation phases are outsourced to different actors.
Regardless of whether this activity reflects a fractured threat group, outsourced extortion negotiators, or a broader affiliate network, the initial infection vector leveraged and goals of these campaigns is consistent. Organizations should prioritize phishing-resistant authenticators and behavioral SaaS auditing to disrupt these identity-centric attacks.
Indicators of Compromise (IOCs)
To assist the wider community in hunting and identifying activity outlined in this blog post, we have provided indicators of compromise (IOCs) in a free GTI Collection for registered users. At the time of publication, identified phishing domains have been added to Google Safe Browsing.
While this collection provides a comprehensive list of IOCs, defenders should note that the majority of identified IP addresses are commercial VPN nodes, and actual source IPs tend to vary as the actor continuously cycles through new infrastructure. Furthermore, the domains are often stood up and used within minutes of registration; as such, they are provided primarily as examples of past naming conventions and usage patterns rather than as a primary mechanism for real-time blocking.
|
Domain |
Creation Date |
Registrar |
Name Servers |
Targeted Industry |
|
|
2026-04-04 |
TUCOWS.COM, CO. |
Njalla / Pipe.ma |
Financial Services, Transportation |
|
|
2026-04-04 |
TUCOWS.COM, CO. |
Cloudflare |
Healthcare |
|
|
2026-04-07 |
TUCOWS.COM, CO. |
Cloudflare |
Financial Services, Healthcare, Media & Entertainment |
|
|
2026-04-08 |
TUCOWS.COM, CO. |
Cloudflare |
Real Estate, Healthcare, Technology |
|
|
2026-04-10 |
TUCOWS.COM, CO. |
Cloudflare |
Financial Services, Hospitality, Healthcare |
|
|
2026-04-10 |
TUCOWS.COM, CO. |
Cloudflare |
Financial Services, Energy, Healthcare |
|
|
2026-04-13 |
TUCOWS.COM, CO. |
Cloudflare |
Healthcare, Financial Services |
|
|
2026-04-13 |
TUCOWS.COM, CO. |
Cloudflare |
Healthcare, Construction & Engineering |
|
|
2026-04-16 |
TUCOWS.COM, CO. |
Cloudflare |
Retail & Consumer Goods, Healthcare, Legal |
|
|
2026-04-16 |
TUCOWS.COM, CO. |
Cloudflare |
N/A |
|
|
2026-04-16 |
TUCOWS.COM, CO. |
Cloudflare |
Transportation |
|
|
2026-04-20 |
NICENIC INTERNATIONAL GROUP CO., LIMITED |
Cloudflare |
Financial Services, Technology |
|
|
2026-04-21 |
NICENIC INTERNATIONAL GROUP CO., LIMITED |
Private Layer (31.7.56.61) |
Financial Services, Technology, Media & Entertainment |
|
|
2026-04-21 |
TUCOWS.COM, CO. |
DDOS-GUARD |
Retail & Consumer Goods |
|
|
2026-04-23 |
Internet Domain Service BS Corp. |
DDOS-GUARD |
Healthcare, Technology |
|
|
2026-04-24 |
TUCOWS.COM, CO. |
Cloudflare |
Financial Services |
|
|
2026-04-29 |
NICENIC INTERNATIONAL GROUP CO., LIMITED |
MEVSPACE (193.34.212.132) |
Manufacturing |
|
|
2026-05-03 |
NICENIC INTERNATIONAL GROUP CO., LIMITED |
Cloudflare |
N/A |
|
|
2026-05-08 |
TUCOWS.COM, CO. |
DDOS-GUARD |
Business Services, Technology |
|
|
2026-05-08 |
NICENIC INTERNATIONAL GROUP CO., LIMITED |
Cloudflare / MEVSPACE |
Energy, Technology, Healthcare |
|
|
2026-05-11 |
NICENIC INTERNATIONAL GROUP CO., LIMITED |
Cloudflare |
Legal, Financial Services, Healthcare |
|
|
2026-05-14 |
NICENIC INTERNATIONAL GROUP CO., LIMITED |
Cloudflare |
Healthcare |
|
|
2026-05-18 |
NICENIC INTERNATIONAL GROUP CO., LIMITED |
Cloudflare / MEVSPACE |
Non-Corporate, Insurance, Legal |
|
|
2026-05-22 |
Internet Domain Service BS Corp. |
DDOS-GUARD |
Technology, Business Services, Construction & Engineering |
|
|
2026-05-26 |
NICENIC INTERNATIONAL GROUP CO., LIMITED |
Cloudflare |
Media & Entertainment, Transportation |
|
|
2026-05-27 |
NICENIC INTERNATIONAL GROUP CO., LIMITED |
Cloudflare |
Transportation |
|
|
2026-05-27 |
NICENIC INTERNATIONAL GROUP CO., LIMITED |
Cloudflare |
Construction & Engineering |
|
|
2026-05-28 |
NICENIC INTERNATIONAL GROUP CO., LIMITED |
Cloudflare |
Media & Entertainment |
|
|
2026-05-29 |
NICENIC INTERNATIONAL GROUP CO., LIMITED |
Cloudflare |
Healthcare, Technology, Legal, Retail & Consumer Goods |
|
|
2026-06-01 |
NICENIC INTERNATIONAL GROUP CO., LIMITED |
MY-NDNS |
N/A |
|
|
2026-06-02 |
PDR Ltd. d/b/a PublicDomainRegistry.com |
Suspended-Domain |
N/A |
|
|
2026-06-03 |
TUCOWS.COM, CO. |
Private Layer (31.7.56.52) |
Financial Services, Healthcare, Transportation |
|
|
2026-06-03 |
Tucows Domains Inc. |
Cloudflare |
Legal, Financial Services |
|
|
2026-06-05 |
NICENIC INTERNATIONAL GROUP CO., LIMITED |
Cloudflare / Private Layer |
Retail & Consumer Goods, Technology, Media & Entertainment |
|
|
2026-06-05 |
NICENIC INTERNATIONAL GROUP CO., LIMITED |
Cloudflare / Private Layer |
Technology, Healthcare, Retail & Consumer Goods, Construction & Engineering, Media & Entertainment, Financial Services |
|
|
2026-06-05 |
NICENIC INTERNATIONAL GROUP CO., LIMITED |
Cloudflare |
Technology |
|
|
2026-06-10 |
PDR Ltd. d/b/a PublicDomainRegistry.com |
Suspended-Domain |
Financial Services, Healthcare, Energy, Real Estate, Technology, Construction & Engineering |
|
|
2026-06-12 |
NICENIC INTERNATIONAL GROUP CO., LIMITED |
Cloudflare / Private Layer |
Technology, Energy |
|
|
2026-06-13 |
Internet Domain Service BS Corp. |
DDOS-GUARD |
Construction & Engineering, Financial Services, Energy |
|
|
2026-06-13 |
NICENIC INTERNATIONAL GROUP CO., LIMITED |
Cloudflare |
Transportation, Financial Services, Construction & Engineering, Real Estate, Business Services, Retail & Consumer Goods, Healthcare |
|
|
2026-06-13 |
NICENIC INTERNATIONAL GROUP CO., LIMITED |
Cloudflare |
Retail & Consumer Goods, Healthcare, Financial Services, Energy |
|
|
2026-06-16 |
NICENIC INTERNATIONAL GROUP CO., LIMITED |
Cloudflare |
Construction & Engineering, Financial Services, Retail & Consumer Goods, Legal, Energy |
|
|
2026-06-17 |
NICENIC INTERNATIONAL GROUP CO., LIMITED |
Cloudflare |
Financial Services, Real Estate, Legal, Healthcare, Transportation, Utilities, Construction & Engineering, Retail & Consumer Goods, Hospitality |
|
|
2026-06-19 |
NICENIC INTERNATIONAL GROUP CO., LIMITED |
Cloudflare |
Non-Corporate, Media & Entertainment, Legal, Healthcare, Energy, Technology |
|
|
2026-06-20 |
NICENIC INTERNATIONAL GROUP CO., LIMITED |
EZYDOMAIN |
Healthcare, Financial Services, Transportation, Real Estate, Technology, Construction & Engineering, Retail & Consumer Goods, Legal, Energy, Utilities, Hospitality |
|
|
2026-06-22 |
NICENIC INTERNATIONAL GROUP CO., LIMITED |
Cloudflare |
Legal |
|
|
2026-06-22 |
NICENIC INTERNATIONAL GROUP CO., LIMITED |
Cloudflare |
Healthcare, Media & Entertainment |
|
|
2026-06-22 |
NICENIC INTERNATIONAL GROUP CO., LIMITED |
Cloudflare / Private Layer |
Legal, Construction & Engineering, Retail & Consumer Goods, Transportation |
|
|
2026-06-25 |
NICENIC INTERNATIONAL GROUP CO., LIMITED |
Cloudflare |
Construction & Engineering, Legal, Aerospace & Defense, Financial Services, Technology |
|
|
2026-06-30 |
NICENIC INTERNATIONAL GROUP CO., LIMITED |
Cloudflare |
Financial Services, Real Estate, Healthcare, Technology, Construction & Engineering, Transportation, Legal, Retail & Consumer Goods, Energy, Utilities, Hospitality |
|
|
2026-06-30 |
NICENIC INTERNATIONAL GROUP CO., LIMITED |
Cloudflare |
Construction & Engineering |
|
|
2026-07-01 |
NICENIC INTERNATIONAL GROUP CO., LIMITED |
Cloudflare / Private Layer |
Financial Services, Legal |
|
|
2026-07-07 |
NICENIC INTERNATIONAL GROUP CO., LIMITED |
Cloudflare |
Financial Services |
|
|
2026-07-07 |
NICENIC INTERNATIONAL GROUP CO., LIMITED |
Cloudflare |
Construction & Engineering, Retail & Consumer Goods |
|
|
2026-07-08 |
NICENIC INTERNATIONAL GROUP CO., LIMITED |
Cloudflare |
Financial Services, Legal |
|
|
2026-07-09 |
NICENIC INTERNATIONAL GROUP CO., LIMITED |
Cloudflare |
Financial Services |
|
|
2026-07-09 |
NICENIC INTERNATIONAL GROUP CO., LIMITED |
Cloudflare / Private Layer |
Construction & Engineering, Energy, Financial Services, Healthcare, Transportation |
|
|
2026-07-10 |
NICENIC INTERNATIONAL GROUP CO., LIMITED |
Cloudflare / Private Layer |
Financial Services, Energy, Healthcare |
|
|
2026-07-13 |
Internet Domain Service BS Corp. |
DDOS-GUARD |
N/A |
|
|
2026-07-13 |
NICENIC INTERNATIONAL GROUP CO., LIMITED |
Cloudflare |
Healthcare, Energy |
|
|
2026-07-13 |
NICENIC INTERNATIONAL GROUP CO., LIMITED |
Cloudflare |
Financial Services, Media & Entertainment |
|
|
2026-07-20 |
NICENIC INTERNATIONAL GROUP CO., LIMITED |
Cloudflare |
Financial Services, Utilities |
|
|
2026-07-20 |
NICENIC INTERNATIONAL GROUP CO., LIMITED |
Cloudflare |
Aerospace & Defense, Technology |
|
|
2026-07-21 |
NICENIC INTERNATIONAL GROUP CO., LIMITED |
Cloudflare / Private Layer |
Technology, Retail & Consumer Goods |
|
|
2026-07-21 |
NICENIC INTERNATIONAL GROUP CO., LIMITED |
Cloudflare |
Energy, Technology |
|
|
2026-07-21 |
NICENIC INTERNATIONAL GROUP CO., LIMITED |
Cloudflare |
Energy, Financial Services |
|
|
2026-07-22 |
NICENIC INTERNATIONAL GROUP CO., LIMITED |
Cloudflare / Private Layer |
Financial Services |
|
|
2026-07-22 |
NICENIC INTERNATIONAL GROUP CO., LIMITED |
Cloudflare |
N/A |
|
|
2026-07-28 |
NICENIC INTERNATIONAL GROUP CO., LIMITED |
Cloudflare / Private Layer |
Financial Services |
|
|
2026-07-31 |
NICENIC INTERNATIONAL GROUP CO., LIMITED |
Cloudflare |
Financial Services |
|
|
2026-08-03 |
NICENIC INTERNATIONAL GROUP CO., LIMITED |
Cloudflare |
Financial Services |
|
|
2026-08-03 |
NICENIC INTERNATIONAL GROUP CO., LIMITED |
Cloudflare |
Financial Services |
Table 1: Indicators of compromise
Network Infrastructure and Exfiltration Observables
|
IP Address |
Role |
ASN |
|---|---|---|
|
|
Panel AiTM Reverse Proxy |
AS51852 Private Layer INC (Switzerland) |
|
|
Panel AiTM Reverse Proxy |
AS51852 Private Layer INC (Switzerland) |
|
|
Phishing Kit Backend Proxy |
AS201814 MEVSPACE (Poland) |
|
|
Phishing Reverse Proxy |
AS57724 DDOS-GUARD LTD (Russia) |
|
|
Automated SaaS Data Exfiltration |
AS11878 Tzulo, Inc. (United States) |
|
|
Automated SaaS Data Exfiltration |
AS25369 Hydra Communications Ltd (United Kingdom) |
|
|
Automated SaaS Data Exfiltration |
AS25369 Hydra Communications Ltd (United Kingdom) |
|
|
M365 / Okta Residential Proxy |
AS7018 AT&T Enterprises, LLC (United States) |
|
|
M365 / Okta Residential Proxy |
AS7922 Comcast Cable Communications (United States) |
|
|
M365 / Okta Residential Proxy |
AS395354 Starry, Inc. (United States) |
|
|
M365 / Okta Residential Proxy |
AS19108 Optimum / Suddenlink (United States) |
Table 2: Network infrastructure and exfiltration observables
Scripting and SDK User-Agent Strings
python-requests/2.28.1
WindowsPowerShell/5.1
Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:146.0) Gecko/20100101 Firefox/146.0
0811A9866E.com.okta.android.auth/8.18.0 DeviceSDK/1.0.94 Android/16 Google/Pixel_9_Pro_XL
Figure 6: Scripting and SDK user-agent strings
Google Security Operations (SecOps) Detections
Google SecOps customers have access to automated detection rules under the Okta and Microsoft 365 rule packs that identify the vishing, MFA modification, and programmatic streaming activity described in this report:
-
Okta Admin Console Access Failure
-
Okta Suspicious Actions from Anonymized IP
-
Okta MFA Factor Setup Following Abandoned Challenge
-
O365 SharePoint Bulk File Access or Download via PowerShell
-
O365 SharePoint High Volume File Access Events
-
O365 SharePoint Query for Proprietary or Privileged Information
-
Okta User Authentication with Suspicious Behavioral Flags
Acknowledgements
Special thanks to researcher ZachXBT for assisting with cryptocurrency analysis.