Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
UNC6671 Automates Microsoft 365 Data Theft via Session Hijacking
August 7, 2026
Papyrus Ad Fraud Abuses Hidden WebViews to Fake User Engagement
August 7, 2026
Critical Flaws in Enterprise Java Platforms Let Attackers Execute Remote Code
August 7, 2026
Home/Threats/UNC6671 Automates Microsoft 365 Data Theft via Session Hijacking
Threats

UNC6671 Automates Microsoft 365 Data Theft via Session Hijacking

Key Takeaways The threat group UNC6671 is conducting sophisticated data theft operations against Microsoft 365 and Okta users. The attacks begin with “vishing” (voice phishing) calls,...

David kimber
David kimber
August 7, 2026 4 Min Read
2 0

Key Takeaways

  • The threat group UNC6671 is conducting sophisticated data theft operations against Microsoft 365 and Okta users.
  • The attacks begin with “vishing” (voice phishing) calls, where attackers impersonate IT helpdesk personnel to trick employees.
  • Instead of merely stealing passwords, UNC6671 employs adversary-in-the-middle (AiTM) techniques to capture live authentication tokens.
  • This allows the group to hijack active sessions, bypass multi-factor authentication (MFA), and automate data exfiltration from cloud services.
  • Targeted sectors include financial services, private equity, and professional services, indicating a focus on high-value corporate data.

Overview of UNC6671’s Automated Data Theft

A new wave of data theft campaigns, attributed to the threat group UNC6671, is leveraging sophisticated social engineering and technical exploits to compromise Microsoft 365 and Okta environments. These campaigns initiate with a convincing phone call, where attackers masquerade as IT helpdesk staff, urging employees to perform an “urgent security migration.” This initial contact, combined with a fabricated sign-in page, transforms a routine employee interaction into a critical entry point for corporate data exfiltration.

Table Of Content

  • Key Takeaways
  • Overview of UNC6671’s Automated Data Theft
  • Automated Microsoft 365 Data Theft via Vishing and Session Hijacking
  • Shared Infrastructure and Escalating Risk
  • What You Should Do

The core danger of this method lies in its ability to bypass traditional password security. By creating a false sense of urgency, UNC6671 prevents employees from independently verifying the request. The campaign doesn’t merely aim to crack a password; it captures both user credentials and a live authentication token. This token then grants the intruder the ability to operate as the legitimate employee within Microsoft 365 or Okta, providing unfettered access to email, files, and other sensitive corporate data.

Analysts at Google Cloud said in a report that they identified this activity during ongoing investigations into data theft and extortion. The report highlights that UNC6671 has remained active despite the purported retirement of its “BlackFile” brand, now operating under various aliases such as Redact, Pink, Helix, and Falcon.

The ramifications of these attacks extend far beyond a compromised inbox. Stolen records can expose highly sensitive information, which UNC6671 then leverages for extortion. Recently, the group has shifted its focus towards the financial services, private equity, and professional services sectors, where access to deal-related and litigation materials holds significant value.

Automated Microsoft 365 Data Theft via Vishing and Session Hijacking

UNC6671’s modus operandi begins with voice phishing (vishing). Attackers contact employees on their personal mobile phones, often spoofing legitimate helpdesk numbers. They typically claim that a mandatory passkey or multi-factor authentication (MFA) update is required. Employees are then directed to meticulously crafted, fraudulent enrollment portals, a tactic also observed in Microsoft Graph reconnaissance attacks targeting workplace accounts.

These deceptive websites employ an adversary-in-the-middle (AiTM) setup. The fake site acts as a proxy, relaying the login process between the victim and the actual service. During this relay, the attacker harvests both the user’s password and the live MFA token. This enables UNC6671 to reuse the authenticated session, a technique reminiscent of session hijacking payroll attacks that have previously targeted Microsoft 365 users.

Once inside the compromised environment, the attackers deploy automated scripts to extract data from cloud services. The Google Cloud report details direct-stream access patterns associated with these scripting tools, allowing for large-scale data exfiltration without conventional downloads. To further complicate detection and incident response, UNC6671 utilizes residential proxy connections, making malicious access appear as ordinary user traffic.

The threat actors have also implemented measures to maintain stealth. They exploit compromised mailboxes to reset passwords for applications not integrated with single sign-on (SSO). Subsequently, they delete any password reset confirmations, security notices, and alerts related to account or MFA changes. This strategic deletion often leaves victims unaware of the compromise while data access and collection persist.

Shared Infrastructure and Escalating Risk

Google Cloud researchers established connections between these activities through consistent phishing templates, overlapping victim profiles, and shared domain infrastructure. The same generic passkey-themed domains have been observed supporting campaigns linked to multiple extortion brands. While this could indicate a coordinated group, it might also suggest fragmented affiliates or shared phishing-as-a-service operations. Defenders are advised to focus on the underlying attack methodology rather than being distracted by shifting brand names.

The pace of these attacks has accelerated significantly. Between June and July, researchers noted the creation of approximately one new root domain every 1.6 days, with a surge of seven domains activated within a 72-hour period in late July. The domain names frequently incorporate terms like “passkey,” “MFA,” or “SSO,” reinforcing the deceptive impression that a legitimate security update is underway.

What You Should Do

  • Strengthen Employee Verification Protocols: Implement and enforce clear procedures for employees to verify unexpected IT helpdesk requests through established, known company channels, never through links or numbers provided in the suspicious contact.
  • Deploy Phishing-Resistant Authentication: Mandate and enforce phishing-resistant sign-in methods, such as FIDO2 security keys, which are inherently more resilient against AiTM attacks than traditional MFA.
  • Shorten Session Lifetimes: Configure shorter session timeouts for cloud applications, particularly for sensitive resources. This reduces the window of opportunity for attackers to exploit stolen session tokens.
  • Enforce Conditional Access Policies: Implement robust conditional access policies that require stronger authentication checks for sensitive resources and restrict access to managed devices and trusted network locations.
  • Enhance Audit Log Monitoring: Regularly review identity provider and Microsoft 365 audit logs for suspicious activities, including abandoned authentication challenges, unusual MFA enrollments, high-volume file access, and scripting-related user-agent strings. Treat “FileAccessed” events with the same urgency as actual downloads.
  • Monitor for Anomalous Logins: Implement monitoring for logins originating from anonymized services, residential proxies, or unfamiliar devices, especially if they coincide with unusual user behavior.
  • Educate Users on Vishing: Conduct ongoing security awareness training specifically addressing vishing attacks, emphasizing the importance of verifying unexpected requests and reporting suspicious calls.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackBreachExploitphishingSecurityThreat

Share Article

David kimber

David kimber

David is a penetration tester turned security journalist with expertise in mobile security, IoT vulnerabilities, and exploit development. As an OSCP-certified security professional, David brings hands-on technical experience to his reporting on vulnerabilities and security research. His articles often feature detailed technical analysis of exploits and provide actionable defense recommendations. David maintains an active presence in the security research community and has contributed to multiple open-source security tools.

Previous Post

Papyrus Ad Fraud Abuses Hidden WebViews to Fake User Engagement

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Critical Zbtlink Router Backdoor Affects 20+ Models
August 7, 2026
OpenAI Expands GPT-3.5 Access With Unlimited Chats for All Users
August 7, 2026
SilverFox Hijacks Drivers to Disable Security Tools
August 7, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Emy Elsamnoudy
Emy Elsamnoudy
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us