UNC6671 Rebrands: Multi-Brand Vishing Extortion Targets Financial Services and Enterprise Cloud Environments
A threat group tracked as UNC6671 has rebranded from BlackFile to multiple extortion brands while continuing vishing attacks on financial and enterprise cloud targets, using AiTM phishing and MFA token theft to steal data.
Google Cloud Threat Intelligence reports that UNC6671, previously associated with the BlackFile extortion brand, has rebranded into multiple operations including Redact, Pink, Helix, and Falcon while maintaining consistent tactics. The group continues to use voice phishing to impersonate IT helpdesk staff, often contacting employees on personal devices to direct them to spoofed login portals that harvest credentials and MFA tokens. Once access is gained, automated scripts exfiltrate data from enterprise cloud environments such as Microsoft 365 and Okta, with financial services, private equity, and professional services now among the targeted sectors.
The rebranding narrative claims an affiliate breakaway forced the shift from BlackFile to Redact, citing unauthorized campaigns and a hijacked data leak site. However, analysis shows overlapping infrastructure, phishing templates, and victim targeting across all brands, suggesting a single group operating multiple extortion fronts. Domains like passkeyhelpdesk[.]com and passkeyms[.]com were used simultaneously to target organizations later claimed by Falcon, Helix, and Pink, with identical credential harvesting panels deployed across these sites.
UNC6671’s targeting has evolved from broad enterprise sectors in April–May 2026 to high-value industries by July, focusing on technology, transportation, hospitality, financial services, law firms, and private equity firms. The group prioritizes organizations handling intellectual property, source code, VIP client data, or involved in mergers and litigation. Infrastructure deployment accelerated from one domain every 2.2 days in April–May to one every 1.6 days in June–July, with a spike of seven domains in 72 hours, primarily hosted on Cloudflare and DDOS-GUARD.
Ransom demands initially ranged from $1 million to $3 million, with final payments averaging $750,000 in over half of tracked cases. The group has maintained financial operations despite the rebranding, with Bitcoin transactions totaling 141.65 BTC ($10.69 million) to BlackFile wallets between January and May 2026. Google recommends implementing controls to mitigate identity-centric vishing, adversary-in-the-middle phishing, and automated SaaS data theft to counter these persistent intrusion methods.