Roasting 0ktapus: The phishing campaign going after Okta identity credentials
ID: 171e3ff6-b693-59f6-929d-78e13a9cf7b0
STIX ID: report--171e3ff6-b693-59f6-929d-78e13a9cf7b0
Feed Name: Group-IB Blog
Group‑IB documents the '0ktapus' SMS phishing campaign that targeted Okta customers by sending links to convincing fake Okta login pages to capture credentials and 2FA codes; the phishing kit (Nuxt.js frontend, Django backend) delivered stolen data to a Telegram channel, enabling immediate account takeover and follow-on supply‑chain compromises (notably impacting Twilio, Mailchimp, and Klaviyo). The analysis enumerates 169 phishing domains, kit artifacts used for tracking, affected industries and geolocations, identification attempts against a suspected operator ('Subject X'), and actionable mitigations including adoption of FIDO2 hardware keys and cautious URL handling.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
