Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Indicators Multi-Brand Vishing Extortion Targets Financial Services and Enterprise Cloud Environments

passkey-connect.com

TLP:CLEAR
Active

Domain

Description

UNC6671 continues conducting data theft extortion operations despite the alleged retirement of the BlackFile brand in May 2026. The threat actor has diversified across multiple extortion fronts including Redact, Pink, Helix, and Falcon. They employ voice phishing tactics, posing as IT helpdesk staff to contact employees on personal mobile devices, directing them to spoofed login portals with Adversary-in-the-Middle infrastructure that intercepts credentials and multi-factor authentication tokens. Once access is established, automated scripts exfiltrate data from enterprise cloud environments including Microsoft 365 and Okta. Infrastructure analysis reveals shared phishing panels, overlapping victim targeting, and connected domains across all brands. Recent targeting has evolved toward financial services, private equity, legal, and professional services sectors. Between January and May 2026, Bitcoin wallet analysis showed approximately $10.69 million USD in ransom payments, with demands...

Sightings (0)

No sightings recorded yet

Details

Name / Label
Multi-Brand Vishing Extortion Targets Financial Services and Enterprise Cloud Environments
Pattern Type
STIX
Confidence
75%
Valid From
Aug 7, 2026 12:01
Total Sightings
0
Added
Aug 7, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.

Record Sighting

Record an observation of passkey-connect.com

Sighting Type
Source
Comment
Leaving Threaticon

This link opens an external site that isn't part of the platform.