Known malicious kitcriticalphishing
ShinyHunters Okta PassToken — landing URL signature
family: okta-passtoken
Same Okta-themed phishing kit as the PassToken script hunt in this family, matched on its landing URL instead of its client script. Deployments open on /index.php?passtoken=&redirect=/ on look-alike domains named after the targeted company, such as <company>sso.com, <company>internal.com and my<company>.com, behind a "Verifying your connection" gate. This row catches deployments whose client script differs from the anchored build, or that did not load it during capture.
Anchors
SMQL queryrun
url:"passtoken=&redirect="Provenance
Added: 2026-09-26 10:31
Matches the passtoken=&redirect= parameter pair anywhere in the submitted or final URL. The pair is specific to this kit so far; confirm the page content before attributing a new match.
Sightings (8)
| Host | Scan | Script | Match | When |
|---|---|---|---|---|
| henryscheinsso.com | f7d999c9… | — | query | 2026-09-26 10:33 |
| myacornsinternal.com | c8e967c6… | — | query | 2026-09-26 10:33 |
| servicenowsso.com | 61b53f5f… | — | query | 2026-09-26 10:33 |
| cloverhealthsso.com | 06cfe6f5… | — | query | 2026-09-26 10:33 |
| myhioscar.com | 2702bef1… | — | query | 2026-09-26 10:33 |
| fullstoryinternal.com | 24563fe9… | — | query | 2026-09-26 10:33 |
| mymckessonsso.com | ace0d1d0… | — | query | 2026-09-26 10:33 |
| mysidley.com | 842a5b56… | — | query | 2026-09-26 10:33 |