Known malicious kitcriticalphishing

ShinyHunters Okta PassToken — landing URL signature

family: okta-passtoken

Same Okta-themed phishing kit as the PassToken script hunt in this family, matched on its landing URL instead of its client script. Deployments open on /index.php?passtoken=&redirect=/ on look-alike domains named after the targeted company, such as <company>sso.com, <company>internal.com and my<company>.com, behind a "Verifying your connection" gate. This row catches deployments whose client script differs from the anchored build, or that did not load it during capture.

Anchors

SMQL queryrun
url:"passtoken=&redirect="

Provenance

Added: 2026-09-26 10:31
Matches the passtoken=&redirect= parameter pair anywhere in the submitted or final URL. The pair is specific to this kit so far; confirm the page content before attributing a new match.

Sightings (8)

HostScanScriptMatchWhen
henryscheinsso.comf7d999c9…—query2026-09-26 10:33
myacornsinternal.comc8e967c6…—query2026-09-26 10:33
servicenowsso.com61b53f5f…—query2026-09-26 10:33
cloverhealthsso.com06cfe6f5…—query2026-09-26 10:33
myhioscar.com2702bef1…—query2026-09-26 10:33
fullstoryinternal.com24563fe9…—query2026-09-26 10:33
mymckessonsso.comace0d1d0…—query2026-09-26 10:33
mysidley.com842a5b56…—query2026-09-26 10:33