SophiaX
🔍
LIVE
· New victim: Portable Intelligence Inc www.portable-intelligence.com serviced by an IT company Computer... — blacknevas· New victim: Riker Danzig Scherer Hyland & Perretti — SilentRansomGroup· New victim: Hightech Signs — kairos· New victim: Riker Danzig LLP — SilentRansomGroup· New victim: gamaus.com — incransom· New KEV: CVE-2026-72898 · Metabase· New KEV: CVE-2026-20349 · Cisco· New KEV: CVE-2026-68820 · Microsoft· New KEV: CVE-2026-8037 · Progress· New KEV: CVE-2026-63077 · JetBrains· New victim: 3,979 new IOCs ingested in last 24h Portable Intelligence Inc www.portable-intelligence.com serviced by an IT company Computer... — blacknevas· New victim: Riker Danzig Scherer Hyland & Perretti — SilentRansomGroup· New victim: Hightech Signs — kairos· New victim: Riker Danzig LLP — SilentRansomGroup· New victim: gamaus.com — incransom· New KEV: CVE-2026-72898 · Metabase· New KEV: CVE-2026-20349 · Cisco· New KEV: CVE-2026-68820 · Microsoft· New KEV: CVE-2026-8037 · Progress· New KEV: CVE-2026-63077 · JetBrains· 3,979 new IOCs ingested in last 24h

UNC6671

❔ UnknownLast active: 2026-08-10First seen: 2026-08-06
0
linked CVEs
Targeted industries
FinanceTechnologyTransportationHospitalityHealthcareLegalManufacturingReal EstateInsuranceEnergyRetailConstructionMediaAerospaceDefenseTelecommunications
UNC6671 is involved in credential harvesting operations, utilizing vishing tactics to impersonate IT staff and directing victims to enter credentials on a victim-branded site. They have gained access to Okta customer accounts and employed PowerShell to download sensitive data from SharePoint and OneDrive. Their extortion tactics include aggressive harassment of victim personnel, and they have used unbranded extortion emails with different Tox IDs for communication. The threat actors have shown a preference for registering domains with Tucows, indicating potential operational differences from related threat groups.
Source: misp_galaxy · Collected: 2026-08-11
⚡ Vulnerabilities & Exploits0 CVEs
threat_actor_cve → cves / exploits.cve_ids
No CVE correlation on record for this actor yet.
🔍 Detection Coverage0 Sigma
Derived from linked CVEs — not a direct actor match
No Sigma rules mapped via this actor's CVEs yet.
🧬 YaraComing soon
🛰️ Infrastructure & IOCs83
domainstartpasskeysetup.com2026-08-10
domainpasskeystatus.com2026-08-10
domainsecure-passkey.com2026-08-10
domainsqfepjvmrd.xyz2026-08-10
domainssopasskey.com2026-08-10
domainoktaenroll.com2026-08-10
domainidokta.com2026-08-10
domainmyoktasso.com2026-08-10
domainmypasskeysso.com2026-08-10
domainsetupssopasskey.com2026-08-10
domainpasskeyms.com2026-08-10
domainkeyokta.com2026-08-10
domainportalpasskey.com2026-08-10
domainoktaportalsso.com2026-08-10
domainpasskeyportal.com2026-08-10
domainpasskeyportalsetup.com2026-08-10
domainaddoktapasskey.com2026-08-10
domaindeploypasskey.com2026-08-10
domainmysecurepasskey.com2026-08-10
domainactivatemypasskey.com2026-08-10
domaincreatepasskey.com2026-08-10
domainregisterpasskey.com2026-08-10
domainsetupsso.com2026-08-10
domainpasskeycenter.com2026-08-10
domainpasskeyregister.com2026-08-10
domainsecureauthpasskey.com2026-08-10
domaincreatemypasskey.com2026-08-10
domainpasskeyset.com2026-08-10
domainpasskeyokta.com2026-08-10
domainpasskeyadd.com2026-08-10
domainpasskeydeploy.com2026-08-10
domainsetpasskey.com2026-08-10
domainaddmypasskey.com2026-08-10
domainpasskey-portal.com2026-08-10
domainpasskeyregistration.com2026-08-10
domainportalsetuphub.com2026-08-10
domainmynewpasskey.com2026-08-10
domainmyconnectkey.com2026-08-10
domainenablepasskey2fa.com2026-08-10
domainpasskeyuser.com2026-08-10
domainpasskeyenroll.com2026-08-10
domainstartpasskey.com2026-08-10
domainoskeysync.com2026-08-10
domainassignpasskey.com2026-08-10
domainkeysyncos.com2026-08-10
domainpasskeyhelpdesk.com2026-08-10
domainpasskeycreate.com2026-08-10
domainpasskeysupport.com2026-08-10
domaincreatessopasskey.com2026-08-10
ip107.128.45.1222026-08-10
ip38.42.59.1712026-08-10
ip47.218.103.1462026-08-10
ip76.103.148.1802026-08-10
domainactivatepasskey.com2026-08-10
domainactivatepasskeyportal.com2026-08-10
domainadd-passkey.com2026-08-10
domainaddpasskey2fa.com2026-08-10
domainaddssopasskey.com2026-08-10
domainaddyourpasskey.com2026-08-10
domaincheckpasskey.com2026-08-10
domaincreatemfa.com2026-08-10
domainenablepasskey.com2026-08-10
domainenrollpasskey.com2026-08-10
domainhubpasskey.com2026-08-10
domainmakepasskey.com2026-08-10
domainmspasskey.com2026-08-10
domainmyaccountsecurity.com2026-08-10
domainmypasskeyid.com2026-08-10
domainmyssopasskey.com2026-08-10
domainnewpasskey.com2026-08-10
domainoskeyconnect.com2026-08-10
domainpasskey-check.com2026-08-10
domainpasskey-connect.com2026-08-10
domainpasskey-enable.com2026-08-10
domainpasskeyactivation.com2026-08-10
domainpasskeycreator.com2026-08-10
domainpasskeyenable.com2026-08-10
domainpasskeymfa.com2026-08-10
domainpasskeyrollout.com2026-08-10
domainpasskeyms.com2026-05-15
domainsetupsso.com2026-05-15
ip179.43.185.2262026-05-15
domainenrollms.com2026-05-15
📰 Threat Intel Coverage1
Digest reports mentioning this actor (incl. aliases)
Welcome to BlackFile: Inside a Vishing Extortion Operation | Google Cloud Blogmatched as UNC66712026-05-15