Known malicious kithighphishing
ShinyHunters Okta PassToken — reported domains 2026-09
family: okta-passtoken
Two domains publicly reported on 2026-09-25 as likely ShinyHunters infrastructure: passkey-settings[.]com, and accounts-auth[.]com at low confidence. Public threat lists also label both under the 0ktapus SSO phishing cluster. The passkey-settings name follows the passkey and SSO enrolment theme of this group's identity-provider phishing.
Anchors
SMQL queryrun
domain:passkey-settings.com OR domain:*.passkey-settings.com OR domain:accounts-auth.com OR domain:*.accounts-auth.comProvenance
Added: 2026-09-26 10:31
Matches pages on either root domain or any subdomain of it. Exact domains only. accounts-auth[.]com sits on a shared server that also hosts unrelated parcel and banking phishing, so a match there is weaker evidence of attribution than one on passkey-settings[.]com. Confirm the page content before attributing a match.
Sightings (1)
| Host | Scan | Script | Match | When |
|---|---|---|---|---|
| accounts-auth.com | 5f1f1a56… | — | query | 2026-09-26 10:34 |