UNC6671 / 0ktapus — origin servers behind the SSO and passkey phishing hosts
Targeted identity-provider phishing linked in public reporting to UNC6671 (the actor Google Threat Intelligence describes targeting financial services and enterprise cloud environments) and listed by public threat lists under the 0ktapus (Scattered Spider-style) SSO phishing cluster. Each lure host is a subdomain named after the targeted organisation (for example xai., simplisafe., branch., icann., marsh., vertiv., selecthealth., billcom., acorns., ciena.) under a shared, generic account or passkey themed domain: myaccountapps[.]com, my-passkeys[.]com, passkey-mfa[.]com and register-passkeys[.]com, registered between 2026-09-02 and 2026-09-18 through the same registrar (NICENIC); my-passkeys and register-passkeys have since been put on registrar hold. The passkey theme targets MFA and passkey enrolment, the step that lets an attacker register their own authenticator on a victim's account. A DNS change around 2026-09-24 exposed the servers behind the hostnames: 46.19.136[.]147 (myaccountapps) and 46.19.136[.]148 (the passkey domains), both at Private Layer.
Anchors
ip:46.19.136.147 OR ip:46.19.136.148Provenance
Sightings (7)
| Host | Scan | Script | Match | When |
|---|---|---|---|---|
| upgrade.myaccountapps.com | e5de892c… | — | query | 2026-09-25 13:15 |
| fbfs.myaccountapps.com | 7344bbf8… | — | query | 2026-09-25 13:15 |
| marsh.myaccountapps.com | 4d3c1fd3… | — | query | 2026-09-25 13:15 |
| icann.myaccountapps.com | 5989bbb1… | — | query | 2026-09-25 13:15 |
| simplisafe.myaccountapps.com | 4cb4e6a6… | — | query | 2026-09-25 13:15 |
| xai.myaccountapps.com | a658a958… | — | query | 2026-09-25 13:14 |
| branch.myaccountapps.com | 82fb86bc… | — | query | 2026-09-25 13:14 |