Bird Watching: Characterizing the Infrastructure and Behavior of Falcon-branded Extortion Operations
The kit’s static assets share consistent last-modified timestamps indicating the Okta temp 2026-8-11 19:23:6 Author: www.guidepointsecurity.com(查看原文) 阅读量:6 收藏

The kit’s static assets share consistent last-modified timestamps indicating the Okta template base was deployed on April 18, 2026, with specific branding layers added on April 20, 2026 and the credential-relay JavaScript (client.js) deployed on April 22, 2026.

Targeting Analysis

Across 110 days of observed activity, we identified 78 unique victim-targeted phishing subdomains representing 76 distinct organizations. Six organizations were targeted on two separate domain deployments, suggesting either initial blocking triggered re-deployment or deliberate parallel infrastructure saturation.

Sector breakdown:

The progressive concentration toward hedge funds, private equity and venture capital firms across the campaign window reflects a deliberate strategic choice. These organizations hold non-public portfolio company data, pending transaction intelligence and investor information. This is all material whose unauthorized disclosure creates strong extortion leverage.

The targeting of nine law firms, including several ranked among the largest in the United States by revenue, is also notable. Law firms represent a high-value credential target because compromised employee sessions provide access not only to the firm’s own data but potentially to privileged client communications, transaction documents and litigation strategy. Several of the targeted firms have active practices in Mergers and Acquisitions (M&A), capital markets and regulatory enforcement, areas where non-public information commands significant value.

The most recent infrastructure cluster (myssoapps.com, registered August 7, 2026 — the day after GTIG’s and Okta’s publications) demonstrates the actor’s operational resilience. New domains were provisioned and active phishing sessions were observed within approximately 24 hours of the cluster’s registration.

Forensic Observations

Forensically, this threat group operates similarly to other SaaS-focused data extortion groups such as Shiny Hunters. Once the threat actor has successfully authenticated to a victim’s Okta account using the victim-derived One-Time Password (OTP), they are most frequently observed pivoting to Microsoft 365, Salesforce and other SaaS infrastructure to which their OAuth Token grants them access.

Post-exploitation compromise has been observed from Private Layer INC (ASN AS51852) infrastructure, consistent with the actor’s preference in back-end infrastructure. Additionally, we have repeatedly observed the threat actor deleting concurrent security warnings delivered by email, almost certainly as an evasive action to prevent user scrutiny of the account abuse or fraudulent logins.

After eviction of successful exfiltration data, the threat actors delivered extortion emails to victims, outlining the alleged breadth of their data exfiltration and directing the victim to contact them via TOX by a pre-set deadline.

Detection and Hardening Guidance

Network Detection

The following indicators provide high-confidence detection with negligible false positive rates:

# HTTP GET/POST requests containing kit PHP backend

  • uri contains “api_FyekIDWY.php”

# HTTP response ETag matching kit API response

  • http.response.headers[“etag”] == “W/\”1c-xHTlhvqhxGIJKu5AJR5p+il839Y\””

# Static asset unique to kit (Okta template)

  • uri contains “d15faff9a15a05e605bc9cfadacdfb4f16ff2c9d.svg”
  • uri contains “okta-logo-end-user-dashboard.svg”

DNS / Web Proxy Blocking

  • Block all domains matching the pattern *.passkey*.com, *.mfa*.com, *.sso*.com registered through NICENIC International after April 2026. The full IOC domain list from GTIG provides a comprehensive starting point; this should be treated as a living list given the actor’s demonstrated cadence of new domain registration.
  • Consider implementing blocks against newly registered domains. Threat actors often operationalize domains shortly after registration to minimize detection windows and this form of block would prevent the domains’ usage against internal employees on-network. A window of <30 days would be sufficient for this control. 

Identity and Authentication Controls

GTIG and Okta both provide detailed hardening guidance. The most impactful controls are:

  1. Enforce phishing-resistant MFA (FIDO2/WebAuthn passkeys or hardware security keys). These cryptographically bind authentication to the legitimate origin domain, making AiTM relay ineffective regardless of how convincing the phishing page appears
  2. Restrict authentication to trusted network sources using Okta Network Zones or Microsoft Entra ID Conditional Access
  3. Require managed device enrollment for access to sensitive applications
  4. Reduce session token lifetimes and enforce re-authentication, particularly for privileged access
  5. Alert on MFA registration events preceded by authentication failures or abandoned push challenges, a reliable behavioral indicator of active AiTM session interception

How to Increase Vishing Awareness

Work Panel equips callers with employee contact data including direct phone numbers, job titles and organizational context sourced through commercial B2B data APIs. Employees should be trained to:

  • Treat any unsolicited call requesting authentication, MFA enrollment or credential entry with suspicion regardless of caller ID
  • Verify helpdesk identity through a known, independently sourced callback number before taking any action
  • Understand that legitimate helpdesk staff will never ask them to approve MFA prompts they did not initiate

IOC Summary and Additional Indicators

The full IOC set from GTIG contains 76 phishing domains, 11 network infrastructure IPs and associated scripting user-agent strings. Our analysis extends this with the following additional indicators:

Additional domains (not in GTIG IOC table):

  • myssoapps.com and subdomains (registered 2026-08-07; active at time of publication)
  • sqfepjvmrd.xyz (C2 panel backend; NICENIC; now on serverHold)
  • ncuqld.com (operator Nextcloud server)
  • aws-us-smtp.com (SMTP sender domain)
  • betterdays2828199.com (earliest Work Panel instance; NameSilo)
  • whatarewedoingwiththesedomainshello.com (secondary Work Panel domain; Tucows/Njalla)

Additional infrastructure IPs:

  • 31.7.56.229 — Private Layer operator server (Nextcloud + eturnal VoIP)
  • 179.43.171.18 — Private Layer operator workstation (Windows 11 RDP)

Kit fingerprints (new):

  • Filename: api_FyekIDWY.php
  • Filename: d15faff9a15a05e605bc9cfadacdfb4f16ff2c9d.svg
  • Response hash: c51eb785e771af1ebb7afdfdca05deaa808680c89e51b8c12f1e319482a997fb
  • Response hash: 275a824ce0ca43d0b48c4e3e11e0c5a47dd09062a0f99cbbf801e20bea01c5bd
  • ETag: W/”1c-xHTlhvqhxGIJKu5AJR5p+il839Y”

Conclusion

The threat actor tracked as UNC6671 / CORDIAL SPIDER / Falcon has demonstrated sustained operational capability, organizational maturity and rapid infrastructure recovery throughout a 4-month campaign targeting high-value organizations across financial services, legal and technology sectors. 

The Work Panel platform first detailed by Okta represents a meaningful evolution in the industrialization of vishing-driven credential theft, packaging target reconnaissance, infrastructure automation and real-time AiTM session management into a single service platform. The separation of duties – callers who know only their next target’s phone number, managers who see the live session queue but nothing else, admins who own the infrastructure – is almost certainly a deliberate organizational design decision that solves the insider risk problem inherent in running criminal operations with hired labor. The Okta report makes this explicit: callers are treated as interchangeable commodity labor, recruited through public underground channels, paid per successful capture and deliberately prevented from accessing the product of their own work.

Despite the new format of these efforts, we observe a continuation of an underlying trend: reduced barriers to entry through increased compartmentalization of efforts. In the same manner by which Ransomware-as-a-Service was made easier through compartmented affiliates, initial access brokers and administrators, we see infrastructure maintenance, targeting and reconnaissance and social engineering execution as distinct functional areas that can be carried out by distinct individuals.

The threat actor’s targeting of MFA-enforced environments without full deployment of phishing resistant MFA is also notable, as victims are generally not technically unsophisticated. Rather, the use of AitM against Okta and M365 targets inconsistent or incomplete deployment of origin-binding cryptography. 

The threat actor’s consistent registration patterns, shared infrastructure and reuse of phishing kit assets across the campaign period provide durable detection opportunities that persist despite domain rotation. Organizations in hedge fund, private equity, venture capital and legal sectors, which have featured prominently in the late-campaign targeting wave, should treat this activity as an active and ongoing threat.

References

[1] Google Threat Intelligence Group. “UNC6671 Rebrands: Multi-Brand Vishing Extortion Targets Financial Services and Enterprise Cloud Environments.” August 6, 2026. https://cloud.google.com/blog/topics/threat-intelligence/unc6671-targets-financial-services-and-enterprise-cloud-environments

[2] Google Threat Intelligence Group. “Welcome to BlackFile: Inside a Vishing Extortion Operation.” May 15, 2026. https://cloud.google.com/blog/topics/threat-intelligence/blackfile-vishing-extortion-operation/ 

[3] Okta Threat Intelligence. “Behind the Scenes of a Vishing Operation.” July 28, 2026. https://www.okta.com/blog/threat-intelligence/behind-the-scenes-of-a-vishing-operation/

This analysis represents findings as of August 10, 2026. The campaign is active and infrastructure observations may change rapidly. IOC data should be verified against current passive DNS and scan databases before operational use.


文章来源: https://www.guidepointsecurity.com/blog/characterizing-infrastructure-behavior-falcon-branded-extortion/
如有侵权请联系:admin#unsafe.sh