OFICIAL Google Cloud Threat Intelligence

UNC6671 Rebrands: Multi-Brand Vishing Extortion Targets Financial Services and Enterprise Cloud Environments

What happened
Based on Google Cloud Threat Intelligence · Aug 06, 2026

A threat group tracked as UNC6671 has rebranded from BlackFile to multiple extortion brands while continuing vishing attacks on financial and enterprise cloud targets, using AiTM phishing and MFA token theft to steal data.

UNC6671 Rebrands: Multi-Brand Vishing Extortion Targets Financial Services and Enterprise Cloud Environments
Google Cloud Threat Intelligence — Google
Key points
·
Visibility and context on the threats that matter most.
·
Threat Intelligence Group (GTIG) continues to track UNC6671 actively conducting compromises leading to data theft extortion, despite the alleged details retirement of the BlackFile extortion brand in May 2026.
·
Telemetry and infrastructure analysis reveal that rather than disbanding, UNC6671 has diversified its operations across multiple extortion fronts including Redact, Pink, Helix, and Falcon.
·
UNC6671 continues to rely on voice phishing (vishing) to target enterprise employees, posing as IT helpdesk staff facilitating mandatory, urgent security migrations.
Key numbers
·
6 days in June–July, with a spike of seven domains in 72 hours, primarily hosted on Cloudflare and DDOS-GUARD.
·
Ransom demands initially ranged from $1 million to $3 million, with final payments averaging $750,000 in over half of tracked cases.
·
65 BTC ($10.

Google Cloud Threat Intelligence reports that UNC6671, previously associated with the BlackFile extortion brand, has rebranded into multiple operations including Redact, Pink, Helix, and Falcon while maintaining consistent tactics. The group continues to use voice phishing to impersonate IT helpdesk staff, often contacting employees on personal devices to direct them to spoofed login portals that harvest credentials and MFA tokens. Once access is gained, automated scripts exfiltrate data from enterprise cloud environments such as Microsoft 365 and Okta, with financial services, private equity, and professional services now among the targeted sectors.

The rebranding narrative claims an affiliate breakaway forced the shift from BlackFile to Redact, citing unauthorized campaigns and a hijacked data leak site. However, analysis shows overlapping infrastructure, phishing templates, and victim targeting across all brands, suggesting a single group operating multiple extortion fronts. Domains like passkeyhelpdesk[.]com and passkeyms[.]com were used simultaneously to target organizations later claimed by Falcon, Helix, and Pink, with identical credential harvesting panels deployed across these sites.

UNC6671’s targeting has evolved from broad enterprise sectors in April–May 2026 to high-value industries by July, focusing on technology, transportation, hospitality, financial services, law firms, and private equity firms. The group prioritizes organizations handling intellectual property, source code, VIP client data, or involved in mergers and litigation. Infrastructure deployment accelerated from one domain every 2.2 days in April–May to one every 1.6 days in June–July, with a spike of seven domains in 72 hours, primarily hosted on Cloudflare and DDOS-GUARD.

Ransom demands initially ranged from $1 million to $3 million, with final payments averaging $750,000 in over half of tracked cases. The group has maintained financial operations despite the rebranding, with Bitcoin transactions totaling 141.65 BTC ($10.69 million) to BlackFile wallets between January and May 2026. Google recommends implementing controls to mitigate identity-centric vishing, adversary-in-the-middle phishing, and automated SaaS data theft to counter these persistent intrusion methods.

Original source → Deals on Clipraptor.com →