Newly-observed vishing/phishing campaign targeting retail/finance/fintech/more

On the threat intelligence side as well as the Very Concerned Customer side, seeing rising talk of an emergent campaign consistent with previous Com-related voice phishing. Domains include terms like “passkey” and “mfa”, with subdomains targeting specific enterprises. Initial compromise is achieved through social engineering on phone calls to employees, pretending to be the enterprise helpdesk rolling out new passkey authentication. Post-compromise is mostly data exfiltration and ransom.

Largely they’re targeting Okta or M365 credentials, using a modified Doko php panel. Possibly yet another Blackfile/Cordial Spider rebrand/offshoot calling itself Falcon, with some overlap into Snarky Spider as well. Connections with “Pink” group. (Academic note: this is mostly going to show that our threat actor classification schemas are failing lately around activity clusters coming out of the Com and similar.)

Indicative pattern:

specific content indicators include: api_FyekIDWY.php

first_seen greater_than_or_equal “2026-04-11”
AND
nameserver_domain matches “cloudflare.com
AND
registrar begins_with “nicenic”
AND
domain contains “pass”
domain contains “mfa”
domain contains “sso”
domain contains “tickets-”
domain contains “helpdesk-”
domain contains “dmca”

had to clear out a bunch of radisson spam and a few other terms. CSV below (133 suspect domains) may include a small handful of false positives. Data exported from DomainTools Iris Investigate.

Highly recommend that Defenders/IT desks do proactive outreach to their users in order to buoy awareness of this type of campaign.

You can see previous examples that align with this activity in posts from several months ago: Inside a phishing panel used by ShinyHunters and BlackFile (in particular, Cluster C).

Okta, July 28: Behind the scenes of a vishing operation | Okta Threat Intelligence

iris-pe-export-2026-07-31T10_28_15-04_00.csv (243.8 KB)

2 Likes