UNC6671, a prominent vishing extortion syndicate, has recently undergone a rebranding and expansion of its tactics, as reported by the Google Threat Intelligence Group (GTIG). The group has shifted its operations over recent months, maintaining a strong focus on exploiting IT helpdesk scenarios.
Evolution and Rebranding of UNC6671
Initially identified as ‘BlackFile’ in early 2026, the group targeted numerous organizations in North America, Australia, and the UK. They employed advanced vishing and single sign-on (SSO) compromise techniques to infiltrate systems. Their primary focus was on Microsoft 365 and Okta infrastructures, using adversary-in-the-middle (AiTM) attacks to circumvent multi-factor authentication (MFA) defenses.
In May, the group transitioned from the BlackFile identity, adopting new aliases such as Redact, Pink, Helix, and Falcon. These brands have since been linked to attacks on the financial, private equity, and professional services sectors. Posing as IT helpdesk staff, UNC6671 operatives contact employees to execute their phishing strategies.
Consistent Tactics and New Developments
Despite the change in branding, UNC6671’s methodologies in accessing and compromising systems have remained largely unchanged. In June, they launched a data leak site under the Redact name, signaling a strategic shift while claiming BlackFile was compromised by an affiliate. GTIG’s analysis indicates a likely connection between the various extortion brands operated by a core group of threat actors.
The group utilizes generic root domains targeting multiple victims, such as passkeyhelpdesk[.]com and portalpasskey[.]com. These domains are linked to UNC6671 through phishing templates that collect credentials, often customized with victim-specific subdomains.
Financial Gains and Tactical Shifts
Recent incidents show UNC6671 adapting its tactics, such as spoofing legitimate phone numbers and using compromised emails to reset passwords, while obstructing notifications to avoid detection. Between January and May, they accumulated over $10 million in Bitcoin through 18 wallet addresses, with ransom demands starting from $1 million to $3 million USD. Final payments were often negotiated down, averaging $750,000 in over half of the cases.
GTIG’s observation of UNC6671’s activities highlights their strategic targeting of organizations likely to possess sensitive information, underscoring the evolving nature of cyber threats in today’s digital landscape.
Related: Snowflake Hacker and Belarusian Ransom Cartel Mastermind Sentenced.
