UNC6671 Automates Microsoft 365 Data Theft via Session Hijacking
Key Takeaways The threat group UNC6671 is conducting sophisticated data theft operations against Microsoft 365 and Okta users. The attacks begin with “vishing” (voice phishing) calls,...
Key Takeaways
- The threat group UNC6671 is conducting sophisticated data theft operations against Microsoft 365 and Okta users.
- The attacks begin with “vishing” (voice phishing) calls, where attackers impersonate IT helpdesk personnel to trick employees.
- Instead of merely stealing passwords, UNC6671 employs adversary-in-the-middle (AiTM) techniques to capture live authentication tokens.
- This allows the group to hijack active sessions, bypass multi-factor authentication (MFA), and automate data exfiltration from cloud services.
- Targeted sectors include financial services, private equity, and professional services, indicating a focus on high-value corporate data.
Overview of UNC6671’s Automated Data Theft
A new wave of data theft campaigns, attributed to the threat group UNC6671, is leveraging sophisticated social engineering and technical exploits to compromise Microsoft 365 and Okta environments. These campaigns initiate with a convincing phone call, where attackers masquerade as IT helpdesk staff, urging employees to perform an “urgent security migration.” This initial contact, combined with a fabricated sign-in page, transforms a routine employee interaction into a critical entry point for corporate data exfiltration.
Table Of Content
The core danger of this method lies in its ability to bypass traditional password security. By creating a false sense of urgency, UNC6671 prevents employees from independently verifying the request. The campaign doesn’t merely aim to crack a password; it captures both user credentials and a live authentication token. This token then grants the intruder the ability to operate as the legitimate employee within Microsoft 365 or Okta, providing unfettered access to email, files, and other sensitive corporate data.
Analysts at Google Cloud said in a report that they identified this activity during ongoing investigations into data theft and extortion. The report highlights that UNC6671 has remained active despite the purported retirement of its “BlackFile” brand, now operating under various aliases such as Redact, Pink, Helix, and Falcon.
The ramifications of these attacks extend far beyond a compromised inbox. Stolen records can expose highly sensitive information, which UNC6671 then leverages for extortion. Recently, the group has shifted its focus towards the financial services, private equity, and professional services sectors, where access to deal-related and litigation materials holds significant value.
Automated Microsoft 365 Data Theft via Vishing and Session Hijacking
UNC6671’s modus operandi begins with voice phishing (vishing). Attackers contact employees on their personal mobile phones, often spoofing legitimate helpdesk numbers. They typically claim that a mandatory passkey or multi-factor authentication (MFA) update is required. Employees are then directed to meticulously crafted, fraudulent enrollment portals, a tactic also observed in Microsoft Graph reconnaissance attacks targeting workplace accounts.
These deceptive websites employ an adversary-in-the-middle (AiTM) setup. The fake site acts as a proxy, relaying the login process between the victim and the actual service. During this relay, the attacker harvests both the user’s password and the live MFA token. This enables UNC6671 to reuse the authenticated session, a technique reminiscent of session hijacking payroll attacks that have previously targeted Microsoft 365 users.
Once inside the compromised environment, the attackers deploy automated scripts to extract data from cloud services. The Google Cloud report details direct-stream access patterns associated with these scripting tools, allowing for large-scale data exfiltration without conventional downloads. To further complicate detection and incident response, UNC6671 utilizes residential proxy connections, making malicious access appear as ordinary user traffic.
The threat actors have also implemented measures to maintain stealth. They exploit compromised mailboxes to reset passwords for applications not integrated with single sign-on (SSO). Subsequently, they delete any password reset confirmations, security notices, and alerts related to account or MFA changes. This strategic deletion often leaves victims unaware of the compromise while data access and collection persist.
Shared Infrastructure and Escalating Risk
Google Cloud researchers established connections between these activities through consistent phishing templates, overlapping victim profiles, and shared domain infrastructure. The same generic passkey-themed domains have been observed supporting campaigns linked to multiple extortion brands. While this could indicate a coordinated group, it might also suggest fragmented affiliates or shared phishing-as-a-service operations. Defenders are advised to focus on the underlying attack methodology rather than being distracted by shifting brand names.
The pace of these attacks has accelerated significantly. Between June and July, researchers noted the creation of approximately one new root domain every 1.6 days, with a surge of seven domains activated within a 72-hour period in late July. The domain names frequently incorporate terms like “passkey,” “MFA,” or “SSO,” reinforcing the deceptive impression that a legitimate security update is underway.
What You Should Do
- Strengthen Employee Verification Protocols: Implement and enforce clear procedures for employees to verify unexpected IT helpdesk requests through established, known company channels, never through links or numbers provided in the suspicious contact.
- Deploy Phishing-Resistant Authentication: Mandate and enforce phishing-resistant sign-in methods, such as FIDO2 security keys, which are inherently more resilient against AiTM attacks than traditional MFA.
- Shorten Session Lifetimes: Configure shorter session timeouts for cloud applications, particularly for sensitive resources. This reduces the window of opportunity for attackers to exploit stolen session tokens.
- Enforce Conditional Access Policies: Implement robust conditional access policies that require stronger authentication checks for sensitive resources and restrict access to managed devices and trusted network locations.
- Enhance Audit Log Monitoring: Regularly review identity provider and Microsoft 365 audit logs for suspicious activities, including abandoned authentication challenges, unusual MFA enrollments, high-volume file access, and scripting-related user-agent strings. Treat “FileAccessed” events with the same urgency as actual downloads.
- Monitor for Anomalous Logins: Implement monitoring for logins originating from anonymized services, residential proxies, or unfamiliar devices, especially if they coincide with unusual user behavior.
- Educate Users on Vishing: Conduct ongoing security awareness training specifically addressing vishing attacks, emphasizing the importance of verifying unexpected requests and reporting suspicious calls.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.