UNC6671 Rebrands: Multi-Brand ... Note

UNC6671 Rebrands: Multi-Brand Vishing Extortion Targets Financial Services and Enterprise Cloud Environments

The Google Threat Intelligence Group is tracking UNC6671, a threat actor group that continues to conduct data theft and extortion operations despite the alleged retirement of the BlackFile brand. UNC6671 has diversified its activities across multiple extortion fronts, including Redact, Pink, Helix, and Falcon. They employ voice phishing (vishing) to impersonate IT helpdesk staff, targeting employees via personal mobile devices. These calls direct victims to spoofed login portals where Adversary-in-the-Middle (AiTM) infrastructure intercepts credentials and multi-factor authentication tokens. Once access is gained, automated scripts are used to exfiltrate data from cloud environments like Microsoft 365 and Okta. Analysis reveals overlapping infrastructure and phishing templates connecting these various extortion brands, suggesting a common operational thread. UNC6671's targeting has evolved, with recent focus on financial services, private equity, and professional services firms. New techniques include using passkey pretexts for phishing and employing defense evasion tactics to maintain persistence and delete evidence. Ransom payments continue to be observed, with significant amounts transacted even after the supposed BlackFile shutdown. Organizations are advised to enforce phishing-resistant multi-factor authentication to mitigate these threats.
CdXz5zHNQW_oek9BOyxep.png