Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Vishing Group UNC6671 Restructures After Millions in Extortion

Vishing Group UNC6671 Restructures After Millions in Extortion

Posted on August 7, 2026 By CWS

UNC6671, a prominent vishing extortion syndicate, has recently undergone a rebranding and expansion of its tactics, as reported by the Google Threat Intelligence Group (GTIG). The group has shifted its operations over recent months, maintaining a strong focus on exploiting IT helpdesk scenarios.

Evolution and Rebranding of UNC6671

Initially identified as ‘BlackFile’ in early 2026, the group targeted numerous organizations in North America, Australia, and the UK. They employed advanced vishing and single sign-on (SSO) compromise techniques to infiltrate systems. Their primary focus was on Microsoft 365 and Okta infrastructures, using adversary-in-the-middle (AiTM) attacks to circumvent multi-factor authentication (MFA) defenses.

In May, the group transitioned from the BlackFile identity, adopting new aliases such as Redact, Pink, Helix, and Falcon. These brands have since been linked to attacks on the financial, private equity, and professional services sectors. Posing as IT helpdesk staff, UNC6671 operatives contact employees to execute their phishing strategies.

Consistent Tactics and New Developments

Despite the change in branding, UNC6671’s methodologies in accessing and compromising systems have remained largely unchanged. In June, they launched a data leak site under the Redact name, signaling a strategic shift while claiming BlackFile was compromised by an affiliate. GTIG’s analysis indicates a likely connection between the various extortion brands operated by a core group of threat actors.

The group utilizes generic root domains targeting multiple victims, such as passkeyhelpdesk[.]com and portalpasskey[.]com. These domains are linked to UNC6671 through phishing templates that collect credentials, often customized with victim-specific subdomains.

Financial Gains and Tactical Shifts

Recent incidents show UNC6671 adapting its tactics, such as spoofing legitimate phone numbers and using compromised emails to reset passwords, while obstructing notifications to avoid detection. Between January and May, they accumulated over $10 million in Bitcoin through 18 wallet addresses, with ransom demands starting from $1 million to $3 million USD. Final payments were often negotiated down, averaging $750,000 in over half of the cases.

GTIG’s observation of UNC6671’s activities highlights their strategic targeting of organizations likely to possess sensitive information, underscoring the evolving nature of cyber threats in today’s digital landscape.

Related: Snowflake Hacker and Belarusian Ransom Cartel Mastermind Sentenced.

Security Week News Tags:Bitcoin, cloud security, Cybercrime, Cybersecurity, data breach, Extortion, GTIG, IT helpdesk, MFA, Microsoft 365, Okta, Phishing, Threat Actors, UNC6671, Vishing

Post navigation

Previous Post: AitM Phishing Targets Microsoft 365 for Payroll Data
Next Post: UNC6671 Exploits Microsoft 365 Through Phishing Attacks

Related Posts

Companies Warned of Commvault Vulnerability Exploitation Companies Warned of Commvault Vulnerability Exploitation Security Week News
Chinese Hackers Exploiting React2Shell Vulnerability Chinese Hackers Exploiting React2Shell Vulnerability Security Week News
Red Hat NPM Packages Targeted in Supply Chain Breach Red Hat NPM Packages Targeted in Supply Chain Breach Security Week News
Citrix Addresses NetScaler Vulnerabilities in Security Update Citrix Addresses NetScaler Vulnerabilities in Security Update Security Week News
Rise in Supply Chain Attacks Highlights SBOM Challenges Rise in Supply Chain Attacks Highlights SBOM Challenges Security Week News
Vibe Coding: When Everyone’s a Developer, Who Secures the Code? Vibe Coding: When Everyone’s a Developer, Who Secures the Code? Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • ChatGPT Ad Tracking Cookie Raises Privacy Concerns
  • Noopur Davis: From Developer to Comcast’s Global CISO
  • Weekly Security Recap: Cisco ISE Flaw & AI Vulnerabilities
  • Windows Updates Disrupt File History Backups in September 2026
  • Dragos Expands with NetRise and runZero Acquisitions

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • ChatGPT Ad Tracking Cookie Raises Privacy Concerns
  • Noopur Davis: From Developer to Comcast’s Global CISO
  • Weekly Security Recap: Cisco ISE Flaw & AI Vulnerabilities
  • Windows Updates Disrupt File History Backups in September 2026
  • Dragos Expands with NetRise and runZero Acquisitions

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark