PULSE NAME
Inside a phishing panel
WHITE ShinyHunters, BlackFile, UNC6661, UNC6671, UNC6240 AlienVault 2026-05-11 Modified: 2026-05-11
21
IOCs
MEDIUM VOLUME
Security researchers gained direct access to Doko's Panel, a real-time phishing platform used in criminal campaigns by ShinyHunters and BlackFile groups. The investigation revealed four distinct infrastructure clusters operating independently customized variants of the tooling. Attacks combine voice phishing with adversary-in-the-middle techniques targeting enterprise identity providers like Okta, Microsoft, and Google, as well as cryptocurrency exchanges. Operators call victims impersonating IT helpdesk staff, directing them to combosquatted domains where credentials and MFA tokens are manually relayed in real-time. Confirmed breaches include SoundCloud (30M records), Match Group (10M records), Betterment (20M records), and Crunchbase. Over 400 domains have been identified linked to these operations. Evidence shows extensive use of AI language models in developing phishing infrastructure, with operators leveraging legitimate services to rapidly deploy and rotate attack infrastructure.
Indicators of Compromise (5 / 21 total)
All FileHash-SHA256 domain
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA256 8a01bcb70ec1c101a163c9cb8e074781c1322096f7ae01789f02252854def44c 2026-05-11
FileHash-SHA256 9c0939960e49122196e44b6779fe55dd7a13ab437ce251c8cf35f8c6daf8be21 2026-05-11
FileHash-SHA256 9d65dd34384b441505e6b67647153c02d5c367bb53da36ce36a392e70b37940a 2026-05-11
FileHash-SHA256 c0df36ccf88d5c8434b13b58f7a55a9715643a126148b9d078a93075d09cad26 2026-05-11
FileHash-SHA256 cb1d409278b2247af23e7b00ac779b232baaf4ce5f63fdf5ebc3920a38cc6102 2026-05-11