Known malicious kitcriticalphishing

ShinyHunters Okta PassToken

family: okta-passtoken

Okta-themed brand-impersonation phishing kit. Landing URL has the ?passtoken=&redirect=/ signature; backend.php polls for MFA-bypass state; pingServer heartbeat; Telegram-channel credential exfiltration. Attributed to the ShinyHunters cluster.

Provenance

Added by: analyst
Added: 2026-05-26 12:28
Seeded 2026-05-26 from PassToken pattern + js-fp3 byte-identical sweep (henryscheinsso.com, servicenowsso.com).

Sightings (2)

HostScanScriptMatchWhen
henryscheinsso.comf7d999c9https://henryscheinsso.com/client.jsbyte2026-05-22 14:55
servicenowsso.com61b53f5fhttps://servicenowsso.com/client.jsbyte2026-05-22 14:54