Known malicious kithighphishing

ShinyHunters Okta PassToken — reported domains 2026-09

family: okta-passtoken

Two domains publicly reported on 2026-09-25 as likely ShinyHunters infrastructure: passkey-settings[.]com, and accounts-auth[.]com at low confidence. Public threat lists also label both under the 0ktapus SSO phishing cluster. The passkey-settings name follows the passkey and SSO enrolment theme of this group's identity-provider phishing.

Anchors

SMQL queryrun
domain:passkey-settings.com OR domain:*.passkey-settings.com OR domain:accounts-auth.com OR domain:*.accounts-auth.com

Provenance

Added: 2026-09-26 10:31
Matches pages on either root domain or any subdomain of it. Exact domains only. accounts-auth[.]com sits on a shared server that also hosts unrelated parcel and banking phishing, so a match there is weaker evidence of attribution than one on passkey-settings[.]com. Confirm the page content before attributing a match.

Sightings (1)

HostScanScriptMatchWhen
accounts-auth.com5f1f1a56…—query2026-09-26 10:34