Security News

Cybersecurity news aggregator

⚔️
HIGH Attacks SecurityWeek

Vishing Extortion Group UNC6671 Rebrands After Making Millions

UNC6671 is a threat actor conducting sophisticated vishing attacks by impersonating IT helpdesk staff to lure employees to spoofed login portals, using adversary-in-the-middle (AiTM) techniques to bypass MFA and compromise Microsoft 365 and Okta credentials. The group has rebranded from BlackFile to multiple extortion brands (Redact, Pink, Helix, Falcon) and primarily targets financial services, private equity, and professional services sectors. Defenders should educate users on vishing tactics and monitor for suspicious domains incorporating victim names or generic terms like "passkey."
Read Full Article →

Malware & Threats Vishing Extortion Group UNC6671 Rebrands After Making Millions Initially calling itself BlackFile, the group has expanded operations to the Redact, Pink, Helix, and Falcon brands. By Ionut Arghire | August 7, 2026 (7:06 AM ET) Flipboard Reddit Whatsapp Whatsapp Email UNC6671, an extortion group engaging in tailored IT helpdesk voice phishing (vishing), has rebranded and diversified its operations over the past several months, Google Threat Intelligence Group (GTIG) reports. The threat actor emerged in early 2026, operating under the ‘BlackFile’ name. In May, GTIG warned it had targeted dozens of organizations across North America, Australia, and the UK in sophisticated vishing and single sign-on (SSO) compromise attacks. Mainly focusing on Microsoft 365 and Okta infrastructure, it was leveraging adversary-in-the-middle (AiTM) techniques to bypass defenses and multi-factor authentication (MFA) and gain access to cloud environments. In May, GTIG now says , the group retired the BlackFile extortion name, but has continued its activities under multiple brands: Redact, Pink, Helix, and Falcon. The latest attacks have focused on the financial services, private equity, and professional services sectors. Posing as IT helpdesk employees, UNC6671 threat actors have been calling employees at the victim organizations, often on personal mobile phones, under the pretext of mandatory, urgent security migrations, luring them to spoofed login portals to intercept their credentials and MFA tokens. Despite different branding in extortion messages, UNC6671’s initial access and post-compromise tactics, techniques, and procedures (TTPs) have remained consistent, GTIG says. Advertisement. Scroll to continue reading. In June, the group established a new data leak site under the Redact brand, announcing the departure from BlackFile, claiming the operation had been hijacked by an affiliate. GTIG’s monitoring of UNC6671’s digital footprint showed overlaps with the operations of other extortion brands. “These overlaps support our assessment that a common group of threat actors are affiliated with the BlackFile, Redact, Pink, Helix, and Falcon extortion brands, although other scenarios such as splintered affiliates or shared Phishing-as-a-Service infrastructure may also be plausible,” GTIG says. The group has been using generic root domains across multiple victims, such as passkeyhelpdesk[.]com, portalpasskey[.]com, addssopasskey[.]com, passkeydeploy[.]com, mysecurepasskey[.]com, and passkeyuser[.]com. While some domains were exclusively used by specific extortion brands, they could be linked to UNC6671 activity through the phishing templates deployed to harvest credentials. “UNC6671’s domain registration patterns demonstrate a regular shift in target selection, seemingly towards those that are more likely to hold sensitive information. UNC6671 leverages subdomains that incorporate prospective victim names to host tailored credential harvesting panels,” GTIG notes. Recent attacks have demonstrated an evolution in tactics, with the threat actor spoofing legitimate helpdesk phone numbers and using compromised email addresses to reset the passwords for non-SSO enterprise applications, while deleting confirmation messages, alerts, and notifications to prevent detection. Between January and May, the group received over $10 million in Bitcoin across 18 wallet addresses, representing ransom payments. Some of the payments were made after the BlackFile shutdown announcement. “Initial ransom demands typically range from $1 million to upwards of $3 million USD. However, the extortion operators shifted demands during negotiations, often agreeing to reductions between 50% and 75% of the initial ransom demand. In over 53% of tracked cases in this timeframe, final payments averaged $750,000,” GTIG notes. Related: Snowflake Hacker Pleads Guilty in US Court Related: Belarusian Ransom Cartel Mastermind Gets 16 Years in Prison Related: Weaponized Email AI Assistants Could Help Attackers Hijack Accounts Related: The Fourth Battlefield: The Growing Role of Cyber Operations in Global Conflict Written By Ionut Arghire Ionut Arghire is an international correspondent for SecurityWeek. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Ionut Arghire Critical Paperclip Flaw Allowed Admin Access, Code Execution Belarusian Ransom Cartel Mastermind Gets 16 Years in Prison Cisco Patches Critical SD-WAN, IOS XE, FMC Vulnerabilities Hackers Start Exploiting Recent JetBrains TeamCity Vulnerability 311,000 Impacted by Brown Health Medical Group-MA Data Breach AI Agents Targeted Real People and Projects During Cybersecurity Tests CISA Warns of Exploited Langflow, N-central, and Tomcat Vulnerabilities Over 400 NPM Packages Infected in ChainDrop Supply Chain Attack Latest News Truck Brake Controller’s Safety Recall Doubled as Hidden Security Fix Black Hat USA 2026 – Summary of Vendor Announcements (Part 4) Microsoft, Apple Release Fresh Security Updates 3.8 Million Impacted by Unlimited Technology Systems Data Breach Critical Vulnerabilities Patched With Chrome 151 Update Snowflake Hacker Pleads Guilty in US Court Zero-Click AI Browser Hacking: Claude and ChatGPT Atlas Hijacked via Emails, X Posts Podcast: Compliance Won’t Save You: The Future of Cyber Risk with Edna Conway Trending Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Webinar: Rethinking Cyber Defense for AI-Speed Attacks August 18, 2026 Join this live webinar as we explore if detection-first security operations can keep pace with AI, or if it’s time to rethink prevention as the strongest default. Register Virtual Event: CodeSecCon 2026 August 19, 2026 CodeSecCon bridges the gap between dev and security. Discover best practices for secure coding, innovative risk-reduction tools, and safe AI integration to cultivate a true DevSecOps culture. Safely secure your apps! Register People on the Move 1Kosmos has named Frank Cohen Chief Revenue Officer. ServiceNow has appointed Simon Mouyal as Chief Marketing Officer. James Wilkinson has been named Chief Information Security Officer for the City of Dallas. More People On The Move Expert Insights Rethinking AI Security: Why CASB and DLP Need an Interaction-Aware Layer Build your strategy around answering these questions to ensure employees use AI productively while keeping sensitive data, IP, and agent behavior within the boundaries set for safe AI use. (Etay Maor) Timeless Compliance: Why Better Questions Beat Bigger Frameworks The best compliance programs aren't the biggest ones. They're the ones built on a short list of questions that can actually be answered, and that still hold true when the models change. (Matt Honea) Is Patching Dead? Vulnerability Management in the Post-Mythos Era You cannot out-patch a machine that writes a working exploit from a vulnerability description in twenty hours. Stop trying to optimize a game you cannot win. (Danelle Au) When Identity Verification Fails: Lessons from a Real-World SIM Swap and Near Account Takeover Identity confidence changes throughout every interaction and should be reassessed continuously as new risk signals emerge. (Torsten George) Legacy Systems, Real-World Impacts: The Reality of OT Security Legacy systems, safety concerns, and critical infrastructure risks make OT vulnerability disclosure one of cybersecurity's most challenging balancing acts. (Tod Beardsley) Flipboard Reddit Whatsapp Whatsapp Email

Share this article