The kit’s static assets share consistent last-modified timestamps indicating the Okta template base was deployed on April 18, 2026, with specific branding layers added on April 20, 2026 and the credential-relay JavaScript (client.js) deployed on April 22, 2026.
Across 110 days of observed activity, we identified 78 unique victim-targeted phishing subdomains representing 76 distinct organizations. Six organizations were targeted on two separate domain deployments, suggesting either initial blocking triggered re-deployment or deliberate parallel infrastructure saturation.
Sector breakdown:
The progressive concentration toward hedge funds, private equity and venture capital firms across the campaign window reflects a deliberate strategic choice. These organizations hold non-public portfolio company data, pending transaction intelligence and investor information. This is all material whose unauthorized disclosure creates strong extortion leverage.
The targeting of nine law firms, including several ranked among the largest in the United States by revenue, is also notable. Law firms represent a high-value credential target because compromised employee sessions provide access not only to the firm’s own data but potentially to privileged client communications, transaction documents and litigation strategy. Several of the targeted firms have active practices in Mergers and Acquisitions (M&A), capital markets and regulatory enforcement, areas where non-public information commands significant value.
The most recent infrastructure cluster (myssoapps.com, registered August 7, 2026 — the day after GTIG’s and Okta’s publications) demonstrates the actor’s operational resilience. New domains were provisioned and active phishing sessions were observed within approximately 24 hours of the cluster’s registration.
Forensically, this threat group operates similarly to other SaaS-focused data extortion groups such as Shiny Hunters. Once the threat actor has successfully authenticated to a victim’s Okta account using the victim-derived One-Time Password (OTP), they are most frequently observed pivoting to Microsoft 365, Salesforce and other SaaS infrastructure to which their OAuth Token grants them access.
Post-exploitation compromise has been observed from Private Layer INC (ASN AS51852) infrastructure, consistent with the actor’s preference in back-end infrastructure. Additionally, we have repeatedly observed the threat actor deleting concurrent security warnings delivered by email, almost certainly as an evasive action to prevent user scrutiny of the account abuse or fraudulent logins.
After eviction of successful exfiltration data, the threat actors delivered extortion emails to victims, outlining the alleged breadth of their data exfiltration and directing the victim to contact them via TOX by a pre-set deadline.
The following indicators provide high-confidence detection with negligible false positive rates:
# HTTP GET/POST requests containing kit PHP backend
# HTTP response ETag matching kit API response
# Static asset unique to kit (Okta template)
GTIG and Okta both provide detailed hardening guidance. The most impactful controls are:
Work Panel equips callers with employee contact data including direct phone numbers, job titles and organizational context sourced through commercial B2B data APIs. Employees should be trained to:
The full IOC set from GTIG contains 76 phishing domains, 11 network infrastructure IPs and associated scripting user-agent strings. Our analysis extends this with the following additional indicators:
Additional domains (not in GTIG IOC table):
Additional infrastructure IPs:
Kit fingerprints (new):
The threat actor tracked as UNC6671 / CORDIAL SPIDER / Falcon has demonstrated sustained operational capability, organizational maturity and rapid infrastructure recovery throughout a 4-month campaign targeting high-value organizations across financial services, legal and technology sectors.
The Work Panel platform first detailed by Okta represents a meaningful evolution in the industrialization of vishing-driven credential theft, packaging target reconnaissance, infrastructure automation and real-time AiTM session management into a single service platform. The separation of duties – callers who know only their next target’s phone number, managers who see the live session queue but nothing else, admins who own the infrastructure – is almost certainly a deliberate organizational design decision that solves the insider risk problem inherent in running criminal operations with hired labor. The Okta report makes this explicit: callers are treated as interchangeable commodity labor, recruited through public underground channels, paid per successful capture and deliberately prevented from accessing the product of their own work.
Despite the new format of these efforts, we observe a continuation of an underlying trend: reduced barriers to entry through increased compartmentalization of efforts. In the same manner by which Ransomware-as-a-Service was made easier through compartmented affiliates, initial access brokers and administrators, we see infrastructure maintenance, targeting and reconnaissance and social engineering execution as distinct functional areas that can be carried out by distinct individuals.
The threat actor’s targeting of MFA-enforced environments without full deployment of phishing resistant MFA is also notable, as victims are generally not technically unsophisticated. Rather, the use of AitM against Okta and M365 targets inconsistent or incomplete deployment of origin-binding cryptography.
The threat actor’s consistent registration patterns, shared infrastructure and reuse of phishing kit assets across the campaign period provide durable detection opportunities that persist despite domain rotation. Organizations in hedge fund, private equity, venture capital and legal sectors, which have featured prominently in the late-campaign targeting wave, should treat this activity as an active and ongoing threat.
[1] Google Threat Intelligence Group. “UNC6671 Rebrands: Multi-Brand Vishing Extortion Targets Financial Services and Enterprise Cloud Environments.” August 6, 2026. https://cloud.google.com/blog/topics/threat-intelligence/unc6671-targets-financial-services-and-enterprise-cloud-environments
[2] Google Threat Intelligence Group. “Welcome to BlackFile: Inside a Vishing Extortion Operation.” May 15, 2026. https://cloud.google.com/blog/topics/threat-intelligence/blackfile-vishing-extortion-operation/
[3] Okta Threat Intelligence. “Behind the Scenes of a Vishing Operation.” July 28, 2026. https://www.okta.com/blog/threat-intelligence/behind-the-scenes-of-a-vishing-operation/
This analysis represents findings as of August 10, 2026. The campaign is active and infrastructure observations may change rapidly. IOC data should be verified against current passive DNS and scan databases before operational use.