Actor
high
threat
Passkey-Themed Social Engineering Targeting Microsoft Cloud Identities
3 TTPs 10 IOCsThreat actors are using passkey-themed phishing and adversary-in-the-middle attacks to compromise Microsoft cloud accounts, establish persistent access via registered MFA methods, and exfiltrate data via Microsoft Graph API.
SharePoint Online +3
UNC6671
phishing
cloud-security
credential-harvesting
mfa-bypass
data-exfiltration
3t
10i
high
threat
UNC6671 BlackFile Vishing Extortion Campaign Targeting Microsoft 365 and Okta
2 rules 8 TTPs 5 IOCsUNC6671, operating under the "BlackFile" brand, conducts a sophisticated extortion campaign targeting organizations through voice phishing (vishing) and single sign-on (SSO) compromise, using adversary-in-the-middle (AiTM) techniques to bypass MFA and exfiltrate sensitive corporate data.
Microsoft 365 +5
UNC6671
vishing
extortion
aitm
credential-theft
data-exfiltration
sso
2r
8t
5i