“IT Support” Imposters: ShinyHunters Vishing Rings Bypass MFA to Steal Data
ID: 68ccd018-e390-5163-9655-b392043904d3
STIX ID: report--68ccd018-e390-5163-9655-b392043904d3
Feed Name: securityonline.info
Mandiant and GTIG report a surge in sophisticated voice-phishing (vishing) campaigns attributed to clusters UNC6661, UNC6671, and UNC6240 that use live phone calls and victim-branded credential harvesting sites to capture SSO credentials and MFA codes. After gaining access, operators directly target cloud SaaS environments (including Okta, SharePoint, and OneDrive) to exfiltrate sensitive data and carry out extortion, with UNC6671 also observed using Tucows-registered domains, PowerShell-based data retrieval, and harassment of personnel. Recommended defenses emphasize user training to verify callers and deploying hardware-based MFA keys to resist phishing.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
