Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Vishing Group UNC6671 Restructures After Millions in Extortion

Vishing Group UNC6671 Restructures After Millions in Extortion

Posted on August 7, 2026 By CWS

UNC6671, a prominent vishing extortion syndicate, has recently undergone a rebranding and expansion of its tactics, as reported by the Google Threat Intelligence Group (GTIG). The group has shifted its operations over recent months, maintaining a strong focus on exploiting IT helpdesk scenarios.

Evolution and Rebranding of UNC6671

Initially identified as ‘BlackFile’ in early 2026, the group targeted numerous organizations in North America, Australia, and the UK. They employed advanced vishing and single sign-on (SSO) compromise techniques to infiltrate systems. Their primary focus was on Microsoft 365 and Okta infrastructures, using adversary-in-the-middle (AiTM) attacks to circumvent multi-factor authentication (MFA) defenses.

In May, the group transitioned from the BlackFile identity, adopting new aliases such as Redact, Pink, Helix, and Falcon. These brands have since been linked to attacks on the financial, private equity, and professional services sectors. Posing as IT helpdesk staff, UNC6671 operatives contact employees to execute their phishing strategies.

Consistent Tactics and New Developments

Despite the change in branding, UNC6671’s methodologies in accessing and compromising systems have remained largely unchanged. In June, they launched a data leak site under the Redact name, signaling a strategic shift while claiming BlackFile was compromised by an affiliate. GTIG’s analysis indicates a likely connection between the various extortion brands operated by a core group of threat actors.

The group utilizes generic root domains targeting multiple victims, such as passkeyhelpdesk[.]com and portalpasskey[.]com. These domains are linked to UNC6671 through phishing templates that collect credentials, often customized with victim-specific subdomains.

Financial Gains and Tactical Shifts

Recent incidents show UNC6671 adapting its tactics, such as spoofing legitimate phone numbers and using compromised emails to reset passwords, while obstructing notifications to avoid detection. Between January and May, they accumulated over $10 million in Bitcoin through 18 wallet addresses, with ransom demands starting from $1 million to $3 million USD. Final payments were often negotiated down, averaging $750,000 in over half of the cases.

GTIG’s observation of UNC6671’s activities highlights their strategic targeting of organizations likely to possess sensitive information, underscoring the evolving nature of cyber threats in today’s digital landscape.

Related: Snowflake Hacker and Belarusian Ransom Cartel Mastermind Sentenced.

Security Week News Tags:Bitcoin, cloud security, Cybercrime, Cybersecurity, data breach, Extortion, GTIG, IT helpdesk, MFA, Microsoft 365, Okta, Phishing, Threat Actors, UNC6671, Vishing

Post navigation

Previous Post: AitM Phishing Targets Microsoft 365 for Payroll Data

Related Posts

Critical Flaw in Everest Forms Plugin Threatens WordPress Sites Critical Flaw in Everest Forms Plugin Threatens WordPress Sites Security Week News
Hackers Agree to Erase Data Stolen From Canvas Platform Hackers Agree to Erase Data Stolen From Canvas Platform Security Week News
Surge in Cyberattacks Targeting Journalists: Cloudflare Surge in Cyberattacks Targeting Journalists: Cloudflare Security Week News
Malanta Emerges from Stealth With  Million Seed Funding Malanta Emerges from Stealth With $10 Million Seed Funding Security Week News
Virtual Event Today: Attack Surface Management Summit Virtual Event Today: Attack Surface Management Summit Security Week News
Critical Apache Tika Vulnerability Leads to XXE Injection Critical Apache Tika Vulnerability Leads to XXE Injection Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Vishing Group UNC6671 Restructures After Millions in Extortion
  • AitM Phishing Targets Microsoft 365 for Payroll Data
  • CHAINDROP Malware Targets Over 400 npm Packages
  • Bendix Brake Controller Recall Exposes Hidden Security Risks
  • NatJack Exploits NAT Vulnerabilities to Hijack TCP and DNS

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Vishing Group UNC6671 Restructures After Millions in Extortion
  • AitM Phishing Targets Microsoft 365 for Payroll Data
  • CHAINDROP Malware Targets Over 400 npm Packages
  • Bendix Brake Controller Recall Exposes Hidden Security Risks
  • NatJack Exploits NAT Vulnerabilities to Hijack TCP and DNS

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark